Sploitus

CVE-2013-0156

28 known exploits for CVE-2013-0156

active_support/core_ext/hash/conversions.rb in Ruby on Rails before 2.3.15, 3.0.x before 3.0.19, 3.1.x before 3.1.10, and 3.2.x before 3.2.11 does not properly restrict casts of string values, which allows remote attackers to conduct object-injection attacks and execute arbitrary code, or cause a denial of service (memory and CPU consumption) involving nested XML entity references, by leveraging Action Pack support for (1) YAML type conversion or (2) Symbol type conversion.

Affected products
Ruby On Rails, Suse
Rubyonrails Rails
< 3.2.11
Rubyonrails Ruby On Rails
< 2.3.15, 3.0.19, 3.1.10
Fix
Available
CVSS 2.0
7.5 HIGH
EPSS
99.4% (100th percentile)
Weakness
CWE-20
NVD status
Modified
Published
2013-01-13
CVE-2013-0156 at NVD
Authoritative description, scoring and affected products

28 known exploits for CVE-2013-0156

Proof-of-concept code and exploit modules indexed by Sploitus

rails-exploit-cve-2013-0156
2026-08-28 KitPloitKITPLOIT
kuang_grade_mk11
2026-08-28 KitPloitKITPLOIT
CVE-2013-0156
2026-08-27 KitPloitKITPLOIT
CVE-2013-0156
2026-08-26 KitPloitKITPLOIT
CVE-2013-0156
2026-08-25 KitPloitKITPLOIT
heroku-CVE-2013-0156
2026-08-25 KitPloitKITPLOIT
Exploit for Improper Input Validation in Rubyonrails Rails
2025-08-28 kaungsithu19GITHUB
Ruby On Rails XML Processor YAML Deserialization Scanner
2024-09-01 H D Moore, jjarmoc, metasploit.comPACKETSTORMRuby
Ruby On Rails JSON Processor YAML Deserialization Scanner
2024-09-01 H D Moore, jjarmoc, metasploit.comPACKETSTORMRuby
Ruby on Rails XML Processor YAML Deserialization Code Execution
2014-07-01 RootSEEBUGRuby
[Nmap v6.40] Free Security Scanner For Network Exploration & Security Audits
2013-08-21 KitPloitKITPLOIT
Ruby on Rails - Known Secret Session Cookie Remote Code Execution (Metasploit)
2013-08-12 MetasploitEXPLOITDBRuby
Ruby on Rails Known Secret Session Cookie Remote Code Execution
2013-04-11 joernchen of Phenoelit <joernchen@phenoelit.de>METASPLOITRuby
Ruby on Rails XML Processor YAML Deserialization
2013-02-15 SAINT CorporationSAINT
Ruby on Rails XML Processor YAML Deserialization
2013-02-15 SAINT CorporationSAINT
Ruby on Rails XML Processor YAML Deserialization
2013-02-15 SAINT CorporationSAINT
Ruby on Rails XML Processor YAML Deserialization
2013-02-15 SAINT CorporationSAINT
Ruby on Rails JSON Processor YAML Deserialization Scanner
2013-02-11 jjarmoc, hdm <x@hdm.io>METASPLOITRuby
Ruby on Rails JSON Processor YAML Deserialization Code Execution
2013-02-03 RootSEEBUGRuby
Ruby on Rails JSON Processor YAML Deserialization Code Execution
2013-01-29 metasploitZDTRuby
Ruby on Rails JSON Processor YAML Deserialization Code Execution
2013-01-29 egyptPACKETSTORMRuby
Exploit for Improper Input Validation in Rubyonrails Rails
2013-01-12 bsodmikeGITHUB
Ruby On Rails XML Processor YAML Deserialization Code Execution
2013-01-11 metasploitZDTRuby
Ruby On Rails XML Processor YAML Deserialization Code Execution
2013-01-11 H D MoorePACKETSTORMRuby
Ruby on Rails - XML Processor YAML Deserialization Code Execution (Metasploit)
2013-01-10 MetasploitEXPLOITDBRuby
Ruby on Rails XML Processor YAML Deserialization Scanner
2013-01-09 hdm <x@hdm.io>, jjarmocMETASPLOITRuby
Action Pack Multiple Vulnerabilities
2013-01-09 Aaron PattersonZDT
Ruby on Rails XML Processor YAML Deserialization Code Execution
2013-01-07 charliesome, espes, lian, hdm <x@hdm.io>METASPLOITRuby