4.3
CVSSv2

CVE-2007-3227

Published: 14/06/2007 Updated: 08/08/2019
CVSS v2 Base Score: 4.3 | Impact Score: 2.9 | Exploitability Score: 8.6
VMScore: 435
Vector: AV:N/AC:M/Au:N/C:N/I:P/A:N

Vulnerability Summary

Cross-site scripting (XSS) vulnerability in the to_json (ActiveRecord::Base#to_json) function in Ruby on Rails before edge 9606 allows remote malicious users to inject arbitrary web script via the input values.

Vulnerable Product Search on Vulmon Subscribe to Product

rubyonrails rails 1.1.5

Vendor Advisories

Debian Bug report logs - #429177 [CVE-2007-3227] XSS vulnerability in to_json Package: rails; Maintainer for rails is Debian Ruby Extras Maintainers <pkg-ruby-extras-maintainers@listsaliothdebianorg>; Source for rails is src:rails (PTS, buildd, popcon) Reported by: Florian Weimer <fw@denebenyode> Date: Sat, 16 J ...

Exploits

source: wwwsecurityfocuscom/bid/24161/info Ruby on Rails is prone to a script-injection vulnerability because the application fails to properly sanitize user-supplied input before using it in dynamically generated content Attacker-supplied script code would run in the context of the affected site, potentially allowing the attacker to st ...