|
|
| |
|
| |
rails: input validation error
| Package(s): | rails |
CVE #(s): | CVE-2012-5664
|
| Created: | January 7, 2013 |
Updated: | January 9, 2013 |
| Description: |
From the Debian advisory:
joernchen of Phenoelit discovered that rails, an MVC ruby based framework
geared for web application development, is not properly treating
user-supplied input to "find_by_*" methods. Depending on how the ruby
on rails application is using these methods, this allows an attacker
to perform SQL injection attacks, e.g., to bypass authentication if
Authlogic is used and the session secret token is known.
See this advisory for more information, patches, and workarounds. |
| Alerts: |
|
( Log in to post comments)
|
|
|