4.3
CVSSv2

CVE-2011-4319

Published: 28/11/2011 Updated: 08/08/2019
CVSS v2 Base Score: 4.3 | Impact Score: 2.9 | Exploitability Score: 8.6
VMScore: 383
Vector: AV:N/AC:M/Au:N/C:N/I:P/A:N

Vulnerability Summary

Cross-site scripting (XSS) vulnerability in the i18n translations helper method in Ruby on Rails 3.0.x prior to 3.0.11 and 3.1.x prior to 3.1.2, and the rails_xss plugin in Ruby on Rails 2.3.x, allows remote malicious users to inject arbitrary web script or HTML via vectors related to a translations string whose name ends with an "html" substring.

Vulnerable Product Search on Vulmon Subscribe to Product

rubyonrails rails 3.0.8

rubyonrails rails 3.0.5

rubyonrails rails 3.0.7

rubyonrails ruby on rails 3.0.4

rubyonrails rails 3.0.2

rubyonrails rails 3.0.9

rubyonrails rails 3.0.10

rubyonrails rails 3.0.0

rubyonrails rails 3.0.6

rubyonrails rails 3.0.3

rubyonrails rails 3.0.1

rubyonrails rails 3.0.4

rubyonrails rails 3.1.0

rubyonrails rails 3.1.1

rubyonrails rails 2.3.10

rubyonrails rails 2.3.11

rubyonrails rails 2.3.12

rubyonrails rails 2.3.9

rubyonrails rails 2.3.4

rubyonrails rails 2.3.3

rubyonrails rails 2.3.2