Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
The cross-site scripting (XSS) prevention feature in Ruby on Rails 2.x before 2.3.12, 3.0.x before 3.0.8, and 3.1.x before 3.1.0.rc2 does not properly handle mutation of safe buffers, which makes it easier for remote attackers to conduct XSS attacks via crafted strings to an application that uses a problematic string method, as demonstrated by the sub method.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
Ruby on Rails跨站脚本攻击漏洞
Vulnerability Description
Ruby on Rails(Rails)是Rails核心团队开发维护的一套基于Ruby语言的开源Web应用框架,它是由大卫-海纳梅尔-韩森从美国37signals公司的项目管理工具Basecamp里分离出来的。 Ruby on Rails 2.3.12之前的2.x版本,3.0.8之前的3.0.x版本,3.1.0.rc2之前的3.1.x版本中的跨站脚本攻击预防功能不能正确处理安全缓冲区的突变。远程攻击者可借助应用程序中的特制字符串执行跨站脚本攻击,该应用程序使用了不确定的string方法。
CVSS Information
N/A
Vulnerability Type
N/A