Sha256: d58d5533ba8d0b751703bf5f657da6d7921637ce38461e0bd760e7de7a45ff0c

Contents?: true

Size: 656 Bytes

Versions: 1

Compression:

Stored size: 656 Bytes

Contents

--- 
gem: actionpack
cve: 2012-3463
url: http://osvdb.org/84515
title: Ruby on Rails select_tag Helper Method prompt Value XSS

description: |
  Ruby on Rails contains a flaw that allows a remote cross-site scripting (XSS)
  attack. This flaw exists because input passed via the prompt value is not
  properly sanitized by the select_tag helper method before returning it to
  the user. This may allow a user to create a specially crafted request that
  would execute arbitrary script code in a user's browser within the trust
  relationship between their browser and the server.

cvss_v2: 4.3

patched_versions: 
  - ~> 3.0.17
  - ~> 3.1.8
  - ">= 3.2.8"

Version data entries

1 entries across 1 versions & 1 rubygems

Version Path
bundler-audit-0.1.2 data/ruby-advisory-db/gems/actionpack/2012-3463.yml