Oval Definition:oval:org.mitre.oval:def:18552
Revision Date:2014-06-23Version:8
Title:DSA-2597-1 rails - input validation error
Description:joernchen of Phenoelit discovered that rails, an MVC ruby based framework geared for web application development, is not properly treating user-supplied input to find_by_* methods. Depending on how the ruby on rails application is using these methods, this allows an attacker to perform SQL injection attacks, e.g., to bypass authentication if Authlogic is used and the session secret token is known.
Family:unixClass:patch
Status:ACCEPTEDReference(s):CVE-2012-6496
CVE-2012-6497
DSA-2597-1
Platform(s):Debian GNU/kFreeBSD 6.0
Debian GNU/Linux 6.0
Product(s):rails
Definition Synopsis
  • Debian 6.0 is installed
  • AND GNU/Linux or GNU/kFreeBSD kernel
  • Debian GNU/Linux is installed
  • OR Debian GNU/kFreeBSD is installed
  • AND rails DPKG is earlier than 2.3.5-1.2+squeeze4
  • BACK