CVE漏洞中文网

0DayBank一个专门收集整理全球互联网漏洞的公开发布网站
  1. 首页
  2. CVE
  3. 正文

漏洞编号:CVE-2015-3226 Ruby on Rails Cross-Site Scripting Vulnerability

2017年6月6日 1086点热度 0人点赞 0条评论

漏洞类别:CGI‘

’漏洞等级:

漏洞信息

Cross-site scripting (XSS) vulnerability in "json/encoding.rb" in Active Support in Ruby on Rails 3.x and 4.1.x before 4.1.11 and 4.2.x before 4.2.2 allows remote attackers to inject arbitrary web script or HTML via a crafted Hash that is mishandled during JSON encoding.

漏洞危害

Successful exploitation could allow an attacker to execute arbitrary HTML and script code in a user's browser session under the context of the site. This may allow the attacker to access sensitive browser-based information such as authentication cookies and recently submitted data.

解决方案

Update to the patched versions

Patch:
Following are links for downloading patches to fix the vulnerabilities:

Ruby on Rails

0daybank

标签: 暂无
最后更新:2017年6月6日

小助手

这个人很懒,什么都没留下

点赞
< 上一篇
下一篇 >

文章评论

您需要 登录 之后才可以评论

COPYRIGHT © 2024 www.pdr.cn CVE漏洞中文网. ALL RIGHTS RESERVED.

鲁ICP备2022031030号

联系邮箱:wpbgssyubnmsxxxkkk@proton.me