Sploitus

CVE-2017-17917

1 known exploit for CVE-2017-17917

SQL injection vulnerability in the 'where' method in Ruby on Rails 5.1.4 and earlier allows remote attackers to execute arbitrary SQL commands via the 'id' parameter. NOTE: The vendor disputes this issue because the documentation states that this method is not intended for use with untrusted input

Affected products
Debian, Ruby On Rails
Rubyonrails Rails
≤ 5.1.4
CVSS 3.1
8.1 HIGH
EPSS
2.3% (82th percentile)
Weakness
CWE-89
NVD status
Modified
Published
2017-12-29
CVE-2017-17917 at NVD
Authoritative description, scoring and affected products

1 known exploit for CVE-2017-17917

Proof-of-concept code and exploit modules indexed by Sploitus