Vulnerabilities
Vulnerable Software
Rubyonrails:  >> Rails  Security Vulnerabilities
Cross-site scripting (XSS) vulnerability in the to_json (ActiveRecord::Base#to_json) function in Ruby on Rails before edge 9606 allows remote attackers to inject arbitrary web script via the input values.
CVSS Score
4.3
EPSS Score
0.12
Published
2007-06-14
Ruby on Rails before 1.1.5 allows remote attackers to execute Ruby code with "severe" or "serious" impact via a File Upload request with an HTTP header that modifies the LOAD_PATH variable, a different vulnerability than CVE-2006-4112.
CVSS Score
7.5
EPSS Score
0.029
Published
2006-08-14
Unspecified vulnerability in the "dependency resolution mechanism" in Ruby on Rails 1.1.0 through 1.1.5 allows remote attackers to execute arbitrary Ruby code via a URL that is not properly handled in the routing code, which leads to a denial of service (application hang) or "data loss," a different vulnerability than CVE-2006-4111.
CVSS Score
7.5
EPSS Score
0.086
Published
2006-08-14


Contact Us

Shodan ® - All rights reserved