[Forgot Password]
Login  Register Subscribe

30479

 
 

423868

 
 

249622

 
 

909

 
 

195521

 
 

282

Paid content will be excluded from the download.


Download | Alert*
OVAL

DSA-2301-1 rails -- several

ID: oval:org.secpod.oval:def:600612Date: (C)2011-10-13   (M)2022-10-10
Class: PATCHFamily: unix




Several vulnerabilities have been discovered in Rails, the Ruby web application framework. The Common Vulnerabilities and Exposures project identifies the following problems: CVE-2009-4214 A cross-site scripting vulnerability had been found in the strip_tags function. An attacker may inject non-printable characters that certain browsers will then evaluate. This vulnerability only affects the oldstable distribution . CVE-2011-2930 A SQL injection vulnerability had been found in the quote_table_name method could allow malicious users to inject arbitrary SQL into a query. CVE-2011-2931 A cross-site scripting vulnerability had been found in the strip_tags helper. An parsing error can be exploited by an attacker, who can confuse the parser and may inject HTML tags into the output document. CVE-2011-3186 A newline injection vulnerability had been found in response.rb. This vulnerability allows an attacker to inject arbitrary HTTP headers and conduct HTTP response splitting attacks via the Content-Type header.

Platform:
Debian 5.0
Debian 6.0
Product:
rails
Reference:
DSA-2301-1
CVE-2011-2930
CVE-2011-2931
CVE-2011-3186
CVE-2009-4214
CVE    4
CVE-2011-2931
CVE-2011-2930
CVE-2011-3186
CVE-2009-4214
...
CPE    3
cpe:/a:ruby:rails
cpe:/o:debian:debian_linux:5.0
cpe:/o:debian:debian_linux:6.0

© SecPod Technologies