Wednesday, January 9, 2013

Multiple vulnerabilities in parameter parsing in Action Pack (CVE-2013-0156) - Google Groups

Multiple vulnerabilities in parameter parsing in Action Pack (CVE-2013-0156) - Google Groups: There are multiple weaknesses in the parameter parsing code for Ruby on Rails which allows attackers to bypass authentication systems, inject arbitrary SQL, inject and execute arbitrary code, or perform a DoS attack on a Rails application. This vulnerability has been assigned the CVE identifier CVE-2013-0156.