4.3
CVSSv2

CVE-2011-2932

Published: 29/08/2011 Updated: 08/08/2019
CVSS v2 Base Score: 4.3 | Impact Score: 2.9 | Exploitability Score: 8.6
VMScore: 383
Vector: AV:N/AC:M/Au:N/C:N/I:P/A:N

Vulnerability Summary

Cross-site scripting (XSS) vulnerability in activesupport/lib/active_support/core_ext/string/output_safety.rb in Ruby on Rails 2.x prior to 2.3.13, 3.0.x prior to 3.0.10, and 3.1.x prior to 3.1.0.rc5 allows remote malicious users to inject arbitrary web script or HTML via a malformed Unicode string, related to a "UTF-8 escaping vulnerability."

Vulnerable Product Search on Vulmon Subscribe to Product

rubyonrails rails 2.2.1

rubyonrails rails 2.1.1

rubyonrails rails 2.1.2

rubyonrails rails 2.1.0

rubyonrails rails 3.0.8

rubyonrails rails 3.0.6

rubyonrails rails 3.0.9

rubyonrails rails 3.0.1

rubyonrails rails 3.0.2

rubyonrails rails 3.0.3

rubyonrails rails 2.2.2

rubyonrails rails 2.2.0

rubyonrails rails 2.0.4

rubyonrails rails 2.3.9

rubyonrails ruby on rails 3.0.4

rubyonrails rails 3.0.0

rubyonrails rails 3.1.0

rubyonrails rails 2.3.11

rubyonrails rails 2.0.1

rubyonrails rails 2.0.0

rubyonrails rails 2.3.3

rubyonrails rails 3.0.7

rubyonrails rails 3.0.4

rubyonrails rails 2.3.12

rubyonrails rails 2.3.10

rubyonrails rails 2.0.2

rubyonrails rails 2.3.2

rubyonrails rails 2.3.4

rubyonrails rails 3.0.5

rubyonrails rails 3.0.10

Vendor Advisories

Several cross-site-scripting and denial of service vulnerabilities were discovered in Ruby on Rails, a Ruby framework for web application development For the stable distribution (squeeze), these problems have been fixed in version 235-12+squeeze8 For the testing distribution (wheezy) and the unstable distribution (sid), these problems have bee ...