6.4
CVSSv2

CVE-2013-3221

Published: 22/04/2013 Updated: 08/08/2019
CVSS v2 Base Score: 6.4 | Impact Score: 4.9 | Exploitability Score: 10
VMScore: 570
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:N

Vulnerability Summary

The Active Record component in Ruby on Rails 2.3.x, 3.0.x, 3.1.x, and 3.2.x does not ensure that the declared data type of a database column is used during comparisons of input values to stored values in that column, which makes it easier for remote malicious users to conduct data-type injection attacks against Ruby on Rails applications via a crafted value, as demonstrated by unintended interaction between the "typed XML" feature and a MySQL database.

Vulnerable Product Search on Vulmon Subscribe to Product

rubyonrails rails 2.3.14

rubyonrails rails 2.3.13

rubyonrails rails 2.3.4

rubyonrails rails 2.3.12

rubyonrails rails 2.3.10

rubyonrails rails 2.3.9

rubyonrails rails 2.3.1

rubyonrails rails 2.3.16

rubyonrails rails 2.3.15

rubyonrails rails 2.3.3

rubyonrails rails 2.3.11

rubyonrails rails 2.3.0

rubyonrails rails 2.3.2

rubyonrails rails 3.0.8

rubyonrails rails 3.0.6

rubyonrails rails 3.0.5

rubyonrails rails 3.0.2

rubyonrails rails 3.0.3

rubyonrails rails 3.0.9

rubyonrails rails 3.0.13

rubyonrails rails 3.0.0

rubyonrails rails 3.0.4

rubyonrails rails 3.0.7

rubyonrails rails 3.0.1

rubyonrails rails 3.0.12

rubyonrails ruby on rails 3.0.4

rubyonrails rails 3.0.17

rubyonrails rails 3.0.14

rubyonrails rails 3.0.10

rubyonrails rails 3.0.19

rubyonrails rails 3.0.16

rubyonrails rails 3.0.18

rubyonrails rails 3.0.11

rubyonrails rails 3.0.20

rubyonrails rails 3.1.8

rubyonrails rails 3.1.7

rubyonrails rails 3.1.0

rubyonrails rails 3.1.1

rubyonrails rails 3.1.5

rubyonrails rails 3.1.2

rubyonrails rails 3.1.9

rubyonrails rails 3.1.3

rubyonrails rails 3.1.4

rubyonrails rails 3.1.10

rubyonrails rails 3.1.6

rubyonrails rails 3.2.0

rubyonrails rails 3.2.11

rubyonrails rails 3.2.1

rubyonrails rails 3.2.2

rubyonrails rails 3.2.8

rubyonrails rails 3.2.4

rubyonrails rails 3.2.6

rubyonrails rails 3.2.5

rubyonrails rails 3.2.10

rubyonrails rails 3.2.3

rubyonrails rails 3.2.7

rubyonrails rails 3.2.9