Sha256: 34e3fc34ddbb5b57b8e79c5940a606efc521bb0cdb2a25126377ce3e7f1c5fb9

Contents?: true

Size: 709 Bytes

Versions: 5

Compression:

Stored size: 709 Bytes

Contents

---
gem: fat_free_crm
osvdb: 101448
cve: 2013-7225
url: http://osvdb.org/show/osvdb/101448
title: Fat Free CRM Gem for Ruby allows remote attackers to inject or
  manipulate SQL queries
date: 2013-12-24
description: |
  Fat Free CRM contains a flaw that may allow carrying out an SQL injection
  attack. The issue is due to the app/controllers/home_controller.rb script
  not properly sanitizing user-supplied input to the 'state' parameter or
  input passed via comments and emails. This may allow a remote attacker to
  inject or manipulate SQL queries in the back-end database, allowing for
  the manipulation or disclosure of arbitrary data.
cvss_v2: 6.5
patched_versions:
  - ">= 0.13.0"
  - "~> 0.12.1"

Version data entries

5 entries across 5 versions & 2 rubygems

Version Path
bundler-budit-0.6.2 data/ruby-advisory-db/gems/fat_free_crm/OSVDB-101448.yml
bundler-budit-0.6.1 data/ruby-advisory-db/gems/fat_free_crm/OSVDB-101448.yml
bundler-audit-0.6.1 data/ruby-advisory-db/gems/fat_free_crm/OSVDB-101448.yml
bundler-audit-0.6.0 data/ruby-advisory-db/gems/fat_free_crm/OSVDB-101448.yml
bundler-audit-0.5.0 data/ruby-advisory-db/gems/fat_free_crm/OSVDB-101448.yml