|
|
| |
|
| |
rubygem-actionpack: cross-site scripting
| Package(s): | rubygem-actionpack |
CVE #(s): | CVE-2011-4319
|
| Created: | January 26, 2012 |
Updated: | March 19, 2012 |
| Description: |
From the Red Hat bugzilla entry:
A cross-site scripting (XSS) flaw was found in the way the 'translate' helper
method of the Ruby on Rails performed HTML escaping of interpolated user input,
when interpolation in combination with HTML-safe translations were used. A
remote attacker could use this flaw to execute arbitrary HTML or web script by
providing a specially-crafted input to Ruby on Rails application, using the
ActionPack module and its 'translate' helper method without explicit
(application specific) sanitization of user provided input. |
| Alerts: |
|
( Log in to post comments)
|
|
|