PT-2011-2351 · Ruby+1 · Ruby On Rails+1

Nzkoz

+1

·

Published

2011-02-21

·

Updated

2023-12-07

·

CVE-2011-0448

CVSS v2.0

7.5

High

VectorAV:N/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions Ruby on Rails versions 3.0.x through 3.0.3
Description The issue allows remote attackers to conduct SQL injection attacks via a non-numeric argument to the limit function, as it does not ensure that arguments specify integer values.
Recommendations For Ruby on Rails versions 3.0.x through 3.0.3, update to version 3.0.4 or later to resolve the issue.

Exploit

Fix

SQL injection

Weakness Enumeration

Related Identifiers

CVE-2011-0448
GHSA-JMM9-2P29-VH2W

Affected Products

Ruby On Rails
Suse