|
|
| |
|
| |
rubygem-actionpack: strip_tags function weakness
| Package(s): | rubygem-actionpack |
CVE #(s): | CVE-2009-4214
|
| Created: | December 10, 2009 |
Updated: | September 5, 2011 |
| Description: |
From the Fedora bug report:
There is a weakness in the strip_tags function in ruby on rails. Due to
a bug in the parsing code inside HTML::Tokenizer regarding non-printable
ascii characters, an attacker can include values which certain browsers
will then evaluate. |
| Alerts: |
|
( Log in to post comments)
|
|
|