Sploitus

CVE-2017-17920

No indexed exploits for CVE-2017-17920 yet

SQL injection vulnerability in the 'reorder' method in Ruby on Rails 5.1.4 and earlier allows remote attackers to execute arbitrary SQL commands via the 'name' parameter. NOTE: The vendor disputes this issue because the documentation states that this method is not intended for use with untrusted input

Affected products
Debian, Ruby On Rails
Rubyonrails Ruby On Rails
≤ 5.1.4
CVSS 3.0
8.1 HIGH
EPSS
1.5% (72th percentile)
Weakness
CWE-89
NVD status
Modified
Published
2017-12-29
CVE-2017-17920 at NVD
Authoritative description, scoring and affected products

No indexed exploits for CVE-2017-17920 yet

Our index is partial: it proves presence, never absence

No exploit for CVE-2017-17920 has been indexed yet. Our index is built from live traffic and upstream syncs, so this page can only say what it knows — not that no exploit exists.