Search CVE reports


Toggle filters

141 – 150 of 150 results


CVE-2009-3009

Medium priority
Ignored

Cross-site scripting (XSS) vulnerability in Ruby on Rails 2.x before 2.2.3, and 2.3.x before 2.3.4, allows remote attackers to inject arbitrary web script or HTML by placing malformed Unicode strings into a form helper.

1 affected package

rails

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
rails
Show less packages

CVE-2009-2422

Low priority
Not affected

The example code for the digest authentication functionality (http_authentication.rb) in Ruby on Rails before 2.3.3 defines an authenticate_or_request_with_http_digest block that returns nil instead of false when the user does not...

1 affected package

rails

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
rails
Show less packages

CVE-2008-5189

Low priority
Ignored

CRLF injection vulnerability in Ruby on Rails before 2.0.5 allows remote attackers to inject arbitrary HTTP headers and conduct HTTP response splitting attacks via a crafted URL to the redirect_to function.

1 affected package

rails

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
rails
Show less packages

CVE-2008-4094

Low priority
Ignored

Multiple SQL injection vulnerabilities in Ruby on Rails before 2.1.1 allow remote attackers to execute arbitrary SQL commands via the (1) :limit and (2) :offset parameters, related to ActiveRecord, ActiveSupport, ActiveResource,...

1 affected package

rails

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
rails
Show less packages

CVE-2007-6077

Low priority

Some fixes available 1 of 4

The session fixation protection mechanism in cgi_process.rb in Rails 1.2.4, as used in Ruby on Rails, removes the :cookie_only attribute from the DEFAULT_SESSION_OPTIONS constant, which effectively causes cookie_only to be applied...

1 affected package

rails

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
rails
Show less packages

CVE-2007-5380

Low priority
Ignored

Session fixation vulnerability in Rails before 1.2.4, as used for Ruby on Rails, allows remote attackers to hijack web sessions via unspecified vectors related to "URL-based sessions."

1 affected package

rails

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
rails
Show less packages

CVE-2007-5379

Low priority
Ignored

Rails before 1.2.4, as used for Ruby on Rails, allows remote attackers and ActiveResource servers to determine the existence of arbitrary files and read arbitrary XML files via the Hash.from_xml (Hash#from_xml) method, which uses...

1 affected package

rails

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
rails
Show less packages

CVE-2007-3227

Medium priority
Ignored

Cross-site scripting (XSS) vulnerability in the to_json (ActiveRecord::Base#to_json) function in Ruby on Rails before edge 9606 allows remote attackers to inject arbitrary web script via the input values.

1 affected package

rails

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
rails
Show less packages

CVE-2006-4112

Medium priority
Fixed

Unspecified vulnerability in the "dependency resolution mechanism" in Ruby on Rails 1.1.0 through 1.1.5 allows remote attackers to execute arbitrary Ruby code via a URL that is not properly handled in the routing code, which leads...

1 affected package

rails

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
rails
Show less packages

CVE-2006-4111

Medium priority
Fixed

Ruby on Rails before 1.1.5 allows remote attackers to execute Ruby code with "severe" or "serious" impact via a File Upload request with an HTTP header that modifies the LOAD_PATH variable, a different vulnerability than CVE-2006-4112.

1 affected package

rails

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
rails
Show less packages