Debian Security Advisory 2597-1

newsbot

newsbot

RSS Feed
Debian Linux Security Advisory 2597-1 - joernchen of Phenoelit discovered that rails, an MVC ruby based framework geared for web application development, is not properly treating user-supplied input to "find_by_*" methods. Depending on how the ruby on rails application is using these methods, this allows an attacker to perform SQL injection attacks, e.g., to bypass authentication if Authlogic is used and the session secret token is known.

Weiterlesen...
 

Ähnliche Themen

Red Hat Security Advisory 2013-0154-01

Red Hat Security Advisory 2013-0153-01

Debian Security Advisory 2604-1

Red Hat Security Advisory 2013-0155-01

Secunia Security Advisory 51637

Zurück
Oben