Vulnerability   
Search   
    Search 324607 CVE descriptions
and 145615 test descriptions,
access 10,000+ cross references.
Tests   CVE   All  

CVE ID:CVE-2014-3483
Description:SQL injection vulnerability in activerecord/lib/active_record/connecti on_adapters/postgresql/quoting.rb in the PostgreSQL adapter for Active Record in Ruby on Rails 4.x before 4.0.7 and 4.1.x before 4.1.3 allows remote attackers to execute arbitrary SQL commands by leveraging improper range quoting.
Test IDs: None available
Cross References: Common Vulnerability Exposure (CVE) ID: CVE-2014-3483
BugTraq ID: 68341
http://www.securityfocus.com/bid/68341
Debian Security Information: DSA-2982 (Google Search)
http://www.debian.org/security/2014/dsa-2982
http://openwall.com/lists/oss-security/2014/07/02/5
https://groups.google.com/forum/message/raw?msg=rubyonrails-security/wDxePLJGZdI/WP7EasCJTA4J
RedHat Security Advisories: RHSA-2014:0877
http://rhn.redhat.com/errata/RHSA-2014-0877.html
http://secunia.com/advisories/59971
http://secunia.com/advisories/60214




© 1998-2025 E-Soft Inc. All rights reserved.