[Forgot Password]
Login  Register Subscribe

30480

 
 

423868

 
 

254202

 
 

909

 
 

198060

 
 

282

Paid content will be excluded from the download.


Download | Alert*


oval:org.secpod.oval:def:505115
Ruby on Rails is a model-view-controller framework for web application development. Action Pack implements the controller and the view components. Security Fix: * It was discovered that Action View tag helpers did not escape quotes when using strings declared as HTML safe as attribute values. A rem ...

oval:org.secpod.oval:def:505059
Ruby on Rails is a model-view-controller framework for web application development. Action View implements the view component. Security Fix: * It was discovered that Action View tag helpers did not escape quotes when using strings declared as HTML safe as attribute values. A remote attacker could u ...

oval:org.secpod.oval:def:504870
Ruby on Rails is a model-view-controller framework for web application development. Action View implements the view component, and Active Record implements the model component. Security Fix in rubygem-actionview: * It was discovered that Action View tag helpers did not escape quotes when using stri ...

oval:org.secpod.oval:def:504898
Ruby on Rails is a model-view-controller framework for web application development. Action Pack implements the controller and the view components. Security Fix: * It was discovered that Action View tag helpers did not escape quotes when using strings declared as HTML safe as attribute values. A rem ...

oval:org.secpod.oval:def:111263
Simple, battle-tested conventions and helpers for building web pages.

oval:org.secpod.oval:def:111260
Simple, battle-tested conventions and helpers for building web pages.

oval:org.secpod.oval:def:602597
Andrew Carpenter of Critical Juncture discovered a cross-site scripting vulnerability affecting Action View in rails, a web application framework written in Ruby. Text declared as "HTML safe" will not have quotes escaped when used as attribute values in tag helpers.

CPE    2
cpe:/a:rubyonrails:ruby_on_rails:3.0.4
cpe:/o:debian:debian_linux:8.0
CWE    1
CWE-79
*CVE
CVE-2016-6316

© SecPod Technologies