Sploitus

CVE-2016-6316

No indexed exploits for CVE-2016-6316 yet

Cross-site scripting (XSS) vulnerability in Action View in Ruby on Rails 3.x before 3.2.22.3, 4.x before 4.2.7.1, and 5.x before 5.0.0.1 might allow remote attackers to inject arbitrary web script or HTML via text declared as "HTML safe" and used as attribute values in tag handlers.

Affected products
Ruby On Rails
Rubyonrails Rails
= 3.0.0, 3.0.1, 3.0.2, 3.0.3, 3.0.4, 3.0.5, 3.0.6, 3.0.7, 3.0.8, 3.0.9, 3.0.10, 3.0.11, 3.0.12, 3.0.13, 3.0.14, 3.0.16, 3.0.17, 3.0.18, 3.0.19, 3.0.20, 3.1.0, 3.1.1, 3.1.2, 3.1.3, 3.1.4, 3.1.5, 3.1.6, 3.1.7, 3.1.8, 3.1.9, 3.1.10, 3.1.12, 3.2.0, 3.2.1, 3.2.2, 3.2.3, 3.2.4, 3.2.5, 3.2.6, 3.2.7
Fix
Available
CVSS 3.0
6.1 MEDIUM
EPSS
3.4% (88th percentile)
Weakness
CWE-79
NVD status
Modified
Published
2016-09-07
CVE-2016-6316 at NVD
Authoritative description, scoring and affected products

No indexed exploits for CVE-2016-6316 yet

Our index is partial: it proves presence, never absence

No exploit for CVE-2016-6316 has been indexed yet. Our index is built from live traffic and upstream syncs, so this page can only say what it knows — not that no exploit exists.