Sploitus

CVE-2012-6496

1 known exploit for CVE-2012-6496

SQL injection vulnerability in the Active Record component in Ruby on Rails before 3.0.18, 3.1.x before 3.1.9, and 3.2.x before 3.2.10 allows remote attackers to execute arbitrary SQL commands via a crafted request that leverages incorrect behavior of dynamic finders in applications that can use unexpected data types in certain find_by_ method calls.

Affected products
Ruby On Rails
Rubyonrails Rails
= 3.1.0, 3.1.1, 3.1.2, 3.1.3, 3.1.4, 3.1.5, 3.1.6, 3.1.7, 3.1.8
Fix
Available
CVSS 2.0
7.5 HIGH
EPSS
4.5% (91th percentile)
Weakness
CWE-89
NVD status
Modified
Published
2013-01-04
CVE-2012-6496 at NVD
Authoritative description, scoring and affected products

1 known exploit for CVE-2012-6496

Proof-of-concept code and exploit modules indexed by Sploitus