CVE-2011-0448
Ruby on Rails 3.0.x before 3.0.4 does not ensure that arguments to the limit function specify integer values, which makes it easier for remote attackers to conduct SQL injection attacks via a non-numeric argument.
- Affected products
- Ruby On Rails, Suse
- Rubyonrails Rails
- = 3.0.0, 3.0.1, 3.0.2, 3.0.3, 3.0.4
- Fix
- Available
- CVSS 2.0
- 7.5 HIGH
- EPSS
- 2.2% (81th percentile)
- Weakness
- CWE-89
- NVD status
- Modified
- Published
- 2011-02-21
CVE-2011-0448 at NVD
1 known exploit for CVE-2011-0448
Proof-of-concept code and exploit modules indexed by Sploitus