|
Ruby on Rails ':offset' And ':limit' Parameters SQL Injection Vulnerabilities
Ruby on Rails is prone to multiple SQL-injection vulnerabilities because the application fails to properly sanitize user-supplied input before using it in SQL queries. A successful exploit could allow an attacker to compromise the application, access or modify data, or exploit vulnerabilities in the underlying database. Versions prior to Ruby on Rails 2.1.1 are affected. |
|
|
Privacy Statement |