Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 4

Количество 4

ubuntu логотип

CVE-2011-2197

около 15 лет назад

The cross-site scripting (XSS) prevention feature in Ruby on Rails 2.x before 2.3.12, 3.0.x before 3.0.8, and 3.1.x before 3.1.0.rc2 does not properly handle mutation of safe buffers, which makes it easier for remote attackers to conduct XSS attacks via crafted strings to an application that uses a problematic string method, as demonstrated by the sub method.

CVSS2: 4.3
EPSS: Низкий
nvd логотип

CVE-2011-2197

около 15 лет назад

The cross-site scripting (XSS) prevention feature in Ruby on Rails 2.x before 2.3.12, 3.0.x before 3.0.8, and 3.1.x before 3.1.0.rc2 does not properly handle mutation of safe buffers, which makes it easier for remote attackers to conduct XSS attacks via crafted strings to an application that uses a problematic string method, as demonstrated by the sub method.

CVSS2: 4.3
EPSS: Низкий
debian логотип

CVE-2011-2197

около 15 лет назад

The cross-site scripting (XSS) prevention feature in Ruby on Rails 2.x ...

CVSS2: 4.3
EPSS: Низкий
github логотип

GHSA-v9v4-7jp6-8c73

почти 9 лет назад

rails Cross-site Scripting vulnerability

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
ubuntu логотип
CVE-2011-2197

The cross-site scripting (XSS) prevention feature in Ruby on Rails 2.x before 2.3.12, 3.0.x before 3.0.8, and 3.1.x before 3.1.0.rc2 does not properly handle mutation of safe buffers, which makes it easier for remote attackers to conduct XSS attacks via crafted strings to an application that uses a problematic string method, as demonstrated by the sub method.

CVSS2: 4.3
2%
Низкий
около 15 лет назад
nvd логотип
CVE-2011-2197

The cross-site scripting (XSS) prevention feature in Ruby on Rails 2.x before 2.3.12, 3.0.x before 3.0.8, and 3.1.x before 3.1.0.rc2 does not properly handle mutation of safe buffers, which makes it easier for remote attackers to conduct XSS attacks via crafted strings to an application that uses a problematic string method, as demonstrated by the sub method.

CVSS2: 4.3
2%
Низкий
около 15 лет назад
debian логотип
CVE-2011-2197

The cross-site scripting (XSS) prevention feature in Ruby on Rails 2.x ...

CVSS2: 4.3
2%
Низкий
около 15 лет назад
github логотип
GHSA-v9v4-7jp6-8c73

rails Cross-site Scripting vulnerability

2%
Низкий
почти 9 лет назад

Уязвимостей на страницу