Anfälligkeitssuche        Suche in 219043 CVE Beschreibungen
und 99761 Test Beschreibungen,
Zugriff auf 10,000+ Quellverweise.
Tests   CVE   Alle  

Test Kennung:1.3.6.1.4.1.25623.1.0.807379
Kategorie:Web application abuses
Titel:Ruby on Rails Action View Cross Site Scripting Vulnerability (Windows)
Zusammenfassung:This host is running Ruby on Rails and is; prone to cross site scripting vulnerability.
Beschreibung:Summary:
This host is running Ruby on Rails and is
prone to cross site scripting vulnerability.

Vulnerability Insight:
The flaw is due to the Text declared as
'HTML safe' when passed as an attribute value to a tag helper will not have
quotes escaped which can lead to an XSS attack.

Vulnerability Impact:
Successful exploitation will allow a remote
attacker to inject arbitrary web script or HTML via crafted parameters.

Affected Software/OS:
Ruby on Rails 3.x before 3.2.22.3,
Ruby on Rails 4.x before 4.2.7.1 and
Ruby on Rails 5.x before 5.0.0.1 on Windows.

Solution:
Upgrade to Ruby on Rails 3.2.22.3 or 4.2.7.1 or
5.0.0.1 or later.

CVSS Score:
4.3

CVSS Vector:
AV:N/AC:M/Au:N/C:N/I:P/A:N

Querverweis: BugTraq ID: 92430
Common Vulnerability Exposure (CVE) ID: CVE-2016-6316
http://www.securityfocus.com/bid/92430
Debian Security Information: DSA-3651 (Google Search)
http://www.debian.org/security/2016/dsa-3651
http://www.openwall.com/lists/oss-security/2016/08/11/3
https://groups.google.com/forum/#!topic/ruby-security-ann/8B2iV2tPRSE
RedHat Security Advisories: RHSA-2016:1855
http://rhn.redhat.com/errata/RHSA-2016-1855.html
RedHat Security Advisories: RHSA-2016:1856
http://rhn.redhat.com/errata/RHSA-2016-1856.html
RedHat Security Advisories: RHSA-2016:1857
http://rhn.redhat.com/errata/RHSA-2016-1857.html
RedHat Security Advisories: RHSA-2016:1858
http://rhn.redhat.com/errata/RHSA-2016-1858.html
CopyrightCopyright (C) 2016 Greenbone Networks GmbH

Dies ist nur einer von 99761 Anfälligkeitstests in unserem Testpaket. Finden Sie mehr über unsere vollständigen Sicherheitsüberprüfungen heraus.

Um einen gratis Test für diese Anfälligkeit auf Ihrem System durchlaufen zu lassen, registrieren Sie sich bitte unten.




© 1998-2024 E-Soft Inc. Alle Rechte vorbehalten.