Vulnerability   
Search   
    Search 324607 CVE descriptions
and 145615 test descriptions,
access 10,000+ cross references.
Tests   CVE   All  

Test ID:1.3.6.1.4.1.25623.1.0.71507
Category:FreeBSD Local Security Checks
Title:FreeBSD Ports: rubygem-rails
Summary:The remote host is missing an update to the system; as announced in the referenced advisory.
Description:Summary:
The remote host is missing an update to the system
as announced in the referenced advisory.

Vulnerability Insight:
The following packages are affected:

rubygem-rails, rubygem-actionpack, rubygem-activesupport

CVE-2012-3463
Cross-site scripting (XSS) vulnerability in
actionpack/lib/action_view/helpers/form_tag_helper.rb in Ruby on Rails
3.x before 3.0.17, 3.1.x before 3.1.8, and 3.2.x before 3.2.8 allows
remote attackers to inject arbitrary web script or HTML via the prompt
field to the select_tag helper.
CVE-2012-3464
Cross-site scripting (XSS) vulnerability in
activesupport/lib/active_support/core_ext/string/output_safety.rb in
Ruby on Rails before 3.0.17, 3.1.x before 3.1.8, and 3.2.x before
3.2.8 might allow remote attackers to inject arbitrary web script or
HTML via vectors involving a ' (quote) character.
CVE-2012-3465
Cross-site scripting (XSS) vulnerability in
actionpack/lib/action_view/helpers/sanitize_helper.rb in the
strip_tags helper in Ruby on Rails before 3.0.17, 3.1.x before 3.1.8,
and 3.2.x before 3.2.8 allows remote attackers to inject arbitrary web
script or HTML via malformed HTML markup.

Solution:
Update your system with the appropriate patches or
software upgrades.

CVSS Score:
4.3

CVSS Vector:
AV:N/AC:M/Au:N/C:N/I:P/A:N

Cross-Ref: Common Vulnerability Exposure (CVE) ID: CVE-2012-3463
https://groups.google.com/group/rubyonrails-security/msg/961e18e514527078?dmode=source&output=gplain
RedHat Security Advisories: RHSA-2013:0154
http://rhn.redhat.com/errata/RHSA-2013-0154.html
Common Vulnerability Exposure (CVE) ID: CVE-2012-3464
https://groups.google.com/group/rubyonrails-security/msg/8f1bbe1cef8c6caf?dmode=source&output=gplain
http://secunia.com/advisories/50694
Common Vulnerability Exposure (CVE) ID: CVE-2012-3465
https://groups.google.com/group/rubyonrails-security/msg/7fbb5392d4d282b5?dmode=source&output=gplain
CopyrightCopyright (C) 2012 E-Soft Inc.

This is only one of 145615 vulnerability tests in our test suite. Find out more about running a complete security audit.

To run a free test of this vulnerability against your system, register below.




© 1998-2025 E-Soft Inc. All rights reserved.