Ruby on Rails 3.0.x before 3.0.4 does not ensure that arguments to the limit function specify integer values, which makes it easier for remote attackers to conduct SQL injection attacks via a non-numeric argument.
References
Configurations
Configuration 1 (hide)
|
Information
Published : 2011-02-21 10:00
Updated : 2019-08-08 08:41
NVD link : CVE-2011-0448
Mitre link : CVE-2011-0448
JSON object : View
CWE
CWE-89
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
Products Affected
rubyonrails
- rails