4.3
CVSSv2

CVE-2013-4492

Published: 07/12/2013 Updated: 13/02/2023
CVSS v2 Base Score: 4.3 | Impact Score: 2.9 | Exploitability Score: 8.6
VMScore: 383
Vector: AV:N/AC:M/Au:N/C:N/I:P/A:N

Vulnerability Summary

Cross-site scripting (XSS) vulnerability in exceptions.rb in the i18n gem prior to 0.6.6 for Ruby allows remote malicious users to inject arbitrary web script or HTML via a crafted I18n::MissingTranslationData.new call.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

i18n project i18n

Vendor Advisories

Peter McLarnan discovered that the internationalization component of Ruby on Rails does not properly encode parameters in generated HTML code, resulting in a cross-site scripting vulnerability This update corrects the underlying vulnerability in the i18n gem, as provided by the ruby-i18n package The oldstable distribution (squeeze) is not affecte ...
Cross-site scripting (XSS) vulnerability in exceptionsrb in the i18n gem before 066 for Ruby allows remote attackers to inject arbitrary web script or HTML via a crafted I18n::MissingTranslationDatanew call ...