TROYANOSYVIRUS
Zuruck zu CVEs

CVE-2017-17920

N/A

Beschreibung

SQL injection vulnerability in the 'reorder' method in Ruby on Rails 5.1.4 and earlier allows remote attackers to execute arbitrary SQL commands via the 'name' parameter. NOTE: The vendor disputes this issue because the documentation states that this method is not intended for use with untrusted input

CVE Details

CVSS v3.1 BewertungN/A
Veroffentlicht12/29/2017
Zuletzt geandert4/20/2025
Quellenvd
Honeypot-Sichtungen0

Betroffene Produkte

rubyonrails:ruby_on_rails

Schwachen (CWE)

CWE-89

IOC Korrelationen

Keine Korrelationen erfasst

This product uses data from the NVD API but is not endorsed or certified by the NVD.