|
|
|
![]() |
Vulnerability Note VU#699540Ruby on Rails fails to properly verify input passed via the URLOverviewRuby on Rails fails to properly validate input. This may allow a remote attacker to execute arbitrary code on a vulnerable system.I. DescriptionRuby on Rails is a web application programming framework. Ruby on Rails 1.1.4 and earlier contain a vulnerability in the processing of user input. Rails 1.0 and earlier are not affected.II. ImpactA remote attacker may be able to execute arbitrary code on a vulnerable system.III. SolutionUpgrade or patchThis vulnerability has been addressed in Ruby on Rails 1.1.6.
References
This vulnerability was publicly reported by David August. This document was written by Will Dormann.
If you have feedback, comments, or additional information about this vulnerability, please send us
email. |
||||||||||||||||||||||||||||||||||||||||
|
||||||||||||||||||||||||||||||||||||||||||