|
|
| |
|
| |
rubygem-activerecord: sql injection
| Package(s): | rubygem-activerecord |
CVE #(s): | CVE-2012-6496
|
| Created: | January 15, 2013 |
Updated: | January 21, 2013 |
| Description: |
From the CVE entry:
SQL injection vulnerability in the Active Record component in Ruby on Rails before 3.0.18, 3.1.x before 3.1.9, and 3.2.x before 3.2.10 allows remote attackers to execute arbitrary SQL commands via a crafted request that leverages incorrect behavior of dynamic finders in applications that can use unexpected data types in certain find_by_ method calls. |
| Alerts: |
|
( Log in to post comments)
|
|
|