Sploitus

CVE-2011-0448

1 known exploit for CVE-2011-0448

Ruby on Rails 3.0.x before 3.0.4 does not ensure that arguments to the limit function specify integer values, which makes it easier for remote attackers to conduct SQL injection attacks via a non-numeric argument.

Affected products
Ruby On Rails, Suse
Rubyonrails Rails
= 3.0.0, 3.0.1, 3.0.2, 3.0.3, 3.0.4
Fix
Available
CVSS 2.0
7.5 HIGH
EPSS
2.2% (81th percentile)
Weakness
CWE-89
NVD status
Modified
Published
2011-02-21
CVE-2011-0448 at NVD
Authoritative description, scoring and affected products

1 known exploit for CVE-2011-0448

Proof-of-concept code and exploit modules indexed by Sploitus