Vulnerability   
Search   
    Search 324607 CVE descriptions
and 145615 test descriptions,
access 10,000+ cross references.
Tests   CVE   All  

CVE ID:CVE-2011-2197
Description:The cross-site scripting (XSS) prevention feature in Ruby on Rails 2.x before 2.3.12, 3.0.x before 3.0.8, and 3.1.x before 3.1.0.rc2 does not properly handle mutation of safe buffers, which makes it easier for remote attackers to conduct XSS attacks via crafted strings to an application that uses a problematic string method, as demonstrated by the sub method.
Test IDs: 1.3.6.1.4.1.25623.1.0.863358   1.3.6.1.4.1.25623.1.0.69923   1.3.6.1.4.1.25623.1.0.802115   1.3.6.1.4.1.25623.1.0.69896   1.3.6.1.4.1.25623.1.0.863315  
Cross References: Common Vulnerability Exposure (CVE) ID: CVE-2011-2197
44789
http://secunia.com/advisories/44789
FEDORA-2011-8494
http://lists.fedoraproject.org/pipermail/package-announce/2011-June/062090.html
FEDORA-2011-8580
http://lists.fedoraproject.org/pipermail/package-announce/2011-July/062514.html
[oss-security] 20110609 CVE Request: Ruby on Rails 3/rails_xss XSS
http://openwall.com/lists/oss-security/2011/06/09/2
[oss-security] 20110613 Re: CVE Request: Ruby on Rails 3/rails_xss XSS
http://openwall.com/lists/oss-security/2011/06/13/9
[rubyonrails-security] 20110607 Potential XSS Vulnerability in Ruby on Rails Applications
http://groups.google.com/group/rubyonrails-security/msg/663b600d4471e0d4?dmode=source&output=gplain
http://weblog.rubyonrails.org/2011/6/8/potential-xss-vulnerability-in-ruby-on-rails-applications
http://weblog.rubyonrails.org/2011/6/8/potential-xss-vulnerability-in-ruby-on-rails-applications




© 1998-2025 E-Soft Inc. All rights reserved.