Ruby on Rails 2.3.9 and 3.0.0 does not properly handle nested attributes, which allows remote attackers to modify arbitrary records by changing the names of parameters for form inputs.
History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published: 2010-10-27T22:00:00Z

Updated: 2024-09-16T20:42:14.245Z

Reserved: 2010-10-12T00:00:00Z

Link: CVE-2010-3933

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Analyzed

Published: 2010-10-28T00:00:05.673

Modified: 2019-08-08T14:49:26.263

Link: CVE-2010-3933

cve-icon Redhat

No data.