Ruby on Rails 3.0.x before 3.0.4 does not ensure that arguments to the limit function specify integer values, which makes it easier for remote attackers to conduct SQL injection attacks via a non-numeric argument.
Metrics
Affected Vendors & Products
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2017-0265 | Ruby on Rails 3.0.x before 3.0.4 does not ensure that arguments to the limit function specify integer values, which makes it easier for remote attackers to conduct SQL injection attacks via a non-numeric argument. |
Github GHSA |
GHSA-jmm9-2p29-vh2w | activerecord vulnerable to SQL Injection |
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
No history.
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2024-08-06T21:51:09.165Z
Reserved: 2011-01-13T00:00:00
Link: CVE-2011-0448
No data.
Status : Deferred
Published: 2011-02-21T18:00:01.287
Modified: 2025-04-11T00:51:21.963
Link: CVE-2011-0448
No data.
OpenCVE Enrichment
No data.
EUVD
Github GHSA