Secunia Logo
 
CVE Reference: CVE-2007-3227
NOTE: The text on this page is written by CVE MITRE and reflects neither the opinions of Secunia or the results of our research. All data on this page is written and maintained by CVE MITRE.

Original Page at CVE MITRE:
CVE-2007-3227

Description:
Cross-site scripting (XSS) vulnerability in the to_json (ActiveRecord::Base#to_json) function in Ruby on Rails before edge 9606 allows remote attackers to inject arbitrary web script via the input values.

CVE Status:
Candidate

References:

SUSE
  http://www.novell.com/linux/security/advisories/2007_24_sr.html

SAID
  Secunia Advisory: SA25699
  Secunia Advisory: SA27657
  Secunia Advisory: SA27756

GENTOO
  http://security.gentoo.org/glsa/glsa-200711-17.xml

CONFIRM
  http://bugs.gentoo.org/show_bug.cgi?id=195315
  http://weblog.rubyonrails.org/2007/10/5/rails-1-2-4-maintenance-release
  http://pastie.caboo.se/65550.txt
  http://weblog.rubyonrails.org/2007/10/12/rails-1-2-5-maintenance-release
  http://dev.rubyonrails.org/ticket/8371

BID
  24161


Return to the previous page.