CVE-2007-3227
published 2007-06-14CVE-2007-3227: Cross-site scripting (XSS) vulnerability in the to_json (ActiveRecord::Base#to_json) function in Ruby on Rails before edge 9606 allows remote attackers to…
PriorityP421medium4.3CVSS 2.0
AVNACMAuNCNIPAN
EXPLOIT
EPSS
3.68%
88.6th percentile
Cross-site scripting (XSS) vulnerability in the to_json (ActiveRecord::Base#to_json) function in Ruby on Rails before edge 9606 allows remote attackers to inject arbitrary web script via the input values.
Affected
7 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | rails | < rails 1.2.5-1 (bookworm) | rails 1.2.5-1 (bookworm) |
| rubyonrails | rails | — | — |
| rubyonrails | rails | >= 0 < 1.2.5-1 | 1.2.5-1 |
| rubyonrails | rails | >= 0 < 1.2.5-1 | 1.2.5-1 |
| rubyonrails | rails | >= 0 < 1.2.5-1 | 1.2.5-1 |
| rubyonrails | rails | >= 0 < 1.2.5-1 | 1.2.5-1 |
| rubyonrails | rails | >= 0 < 1.2.5 | 1.2.5 |
CVSS provenance
nvdv2.04.3MEDIUMAV:N/AC:M/Au:N/C:N/I:P/A:N
osv4.3MEDIUM
vendor_debian4.3MEDIUM
CVEs like this are exactly what “Exploited This Week” covers.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
Moderate severity vulnerability that affects rails
ghsa·2017-10-24
CVE-2007-3227 [MEDIUM] CWE-79 Moderate severity vulnerability that affects rails
Moderate severity vulnerability that affects rails
Cross-site scripting (XSS) vulnerability in the to_json (ActiveRecord::Base#to_json) function in Ruby on Rails before edge 9606 allows remote attackers to inject arbitrary web script via the input values.
OSV
Moderate severity vulnerability that affects rails
osv·2017-10-24
CVE-2007-3227 [MEDIUM] Moderate severity vulnerability that affects rails
Moderate severity vulnerability that affects rails
Cross-site scripting (XSS) vulnerability in the to_json (ActiveRecord::Base#to_json) function in Ruby on Rails before edge 9606 allows remote attackers to inject arbitrary web script via the input values.
OSV
CVE-2007-3227: Cross-site scripting (XSS) vulnerability in the to_json (ActiveRecord::Base#to_json) function in Ruby on Rails before edge 9606 allows remote attacker
osv·2007-06-14·CVSS 4.3
CVE-2007-3227 [MEDIUM] CVE-2007-3227: Cross-site scripting (XSS) vulnerability in the to_json (ActiveRecord::Base#to_json) function in Ruby on Rails before edge 9606 allows remote attacker
Cross-site scripting (XSS) vulnerability in the to_json (ActiveRecord::Base#to_json) function in Ruby on Rails before edge 9606 allows remote attackers to inject arbitrary web script via the input values.
Debian
CVE-2007-3227: rails - Cross-site scripting (XSS) vulnerability in the to_json (ActiveRecord::Base#to_j...
vendor_debian·2007·CVSS 4.3
CVE-2007-3227 [MEDIUM] CVE-2007-3227: rails - Cross-site scripting (XSS) vulnerability in the to_json (ActiveRecord::Base#to_j...
Cross-site scripting (XSS) vulnerability in the to_json (ActiveRecord::Base#to_json) function in Ruby on Rails before edge 9606 allows remote attackers to inject arbitrary web script via the input values.
Scope: local
bookworm: resolved (fixed in 1.2.5-1)
bullseye: resolved (fixed in 1.2.5-1)
forky: resolved (fixed in 1.2.5-1)
sid: resolved (fixed in 1.2.5-1)
trixie: resolved (fixed in 1.2.5-1)
Suricata
ET WEB_SPECIFIC_APPS Eclectic Designs CascadianFAQ SQL Injection Attempt -- index.php catid DELETE
suricata·2010-07-30·CVSS 7.5
CVE-2007-0631 [HIGH] ET WEB_SPECIFIC_APPS Eclectic Designs CascadianFAQ SQL Injection Attempt -- index.php catid DELETE
ET WEB_SPECIFIC_APPS Eclectic Designs CascadianFAQ SQL Injection Attempt -- index.php catid DELETE
Rule: alert http $EXTERNAL_NET any -> $HTTP_SERVERS any (msg:"ET WEB_SPECIFIC_APPS Eclectic Designs CascadianFAQ SQL Injection Attempt -- index.php catid DELETE"; flow:established,to_server; http.uri; content:"/index.php?"; nocase; content:"catid="; nocase; fast_pattern; content:"DELETE"; nocase; content:"FROM"; nocase; distance:0; reference:cve,CVE-2007-0631; reference:url,www.milw0rm.com/exploits/3227; classtype:web-application-attack; sid:2005114; rev:9; metadata:affected_product Web_Server_Applications, attack_target Web_Server, created_at 2010_07_30, deployment Datacenter, confidence Medium, signature_severity Major, tag SQL_Injection, updated_at 2020_09_11, mitre_tactic_id TA0001, mitr
Suricata
ET WEB_SPECIFIC_APPS Eclectic Designs CascadianFAQ SQL Injection Attempt -- index.php catid UNION SELECT
suricata·2010-07-30·CVSS 7.5
CVE-2007-0631 [HIGH] ET WEB_SPECIFIC_APPS Eclectic Designs CascadianFAQ SQL Injection Attempt -- index.php catid UNION SELECT
ET WEB_SPECIFIC_APPS Eclectic Designs CascadianFAQ SQL Injection Attempt -- index.php catid UNION SELECT
Rule: alert http $EXTERNAL_NET any -> $HTTP_SERVERS any (msg:"ET WEB_SPECIFIC_APPS Eclectic Designs CascadianFAQ SQL Injection Attempt -- index.php catid UNION SELECT"; flow:established,to_server; http.uri; content:"/index.php?"; nocase; content:"catid="; nocase; fast_pattern; content:"UNION"; nocase; content:"SELECT"; nocase; distance:0; reference:cve,CVE-2007-0631; reference:url,www.milw0rm.com/exploits/3227; classtype:web-application-attack; sid:2005112; rev:10; metadata:affected_product Web_Server_Applications, attack_target Web_Server, created_at 2010_07_30, deployment Datacenter, confidence Medium, signature_severity Major, tag SQL_Injection, updated_at 2020_09_11, mitre_tactic_i
Suricata
ET WEB_SPECIFIC_APPS Eclectic Designs CascadianFAQ SQL Injection Attempt -- index.php catid ASCII
suricata·2010-07-30·CVSS 7.5
CVE-2007-0631 [HIGH] ET WEB_SPECIFIC_APPS Eclectic Designs CascadianFAQ SQL Injection Attempt -- index.php catid ASCII
ET WEB_SPECIFIC_APPS Eclectic Designs CascadianFAQ SQL Injection Attempt -- index.php catid ASCII
Rule: alert http $EXTERNAL_NET any -> $HTTP_SERVERS any (msg:"ET WEB_SPECIFIC_APPS Eclectic Designs CascadianFAQ SQL Injection Attempt -- index.php catid ASCII"; flow:established,to_server; http.uri; content:"/index.php?"; nocase; content:"catid="; nocase; fast_pattern; content:"ASCII("; nocase; content:"SELECT"; nocase; distance:0; reference:cve,CVE-2007-0631; reference:url,www.milw0rm.com/exploits/3227; classtype:web-application-attack; sid:2005115; rev:9; metadata:affected_product Web_Server_Applications, attack_target Web_Server, created_at 2010_07_30, deployment Datacenter, confidence Medium, signature_severity Major, tag SQL_Injection, updated_at 2020_09_11, mitre_tactic_id TA0001, mitr
Suricata
ET WEB_SPECIFIC_APPS Eclectic Designs CascadianFAQ SQL Injection Attempt -- index.php catid INSERT
suricata·2010-07-30·CVSS 7.5
CVE-2007-0631 [HIGH] ET WEB_SPECIFIC_APPS Eclectic Designs CascadianFAQ SQL Injection Attempt -- index.php catid INSERT
ET WEB_SPECIFIC_APPS Eclectic Designs CascadianFAQ SQL Injection Attempt -- index.php catid INSERT
Rule: alert http $EXTERNAL_NET any -> $HTTP_SERVERS any (msg:"ET WEB_SPECIFIC_APPS Eclectic Designs CascadianFAQ SQL Injection Attempt -- index.php catid INSERT"; flow:established,to_server; http.uri; content:"/index.php?"; nocase; content:"catid="; nocase; fast_pattern; content:"INSERT"; nocase; content:"INTO"; nocase; distance:0; reference:cve,CVE-2007-0631; reference:url,www.milw0rm.com/exploits/3227; classtype:web-application-attack; sid:2005113; rev:9; metadata:affected_product Web_Server_Applications, attack_target Web_Server, created_at 2010_07_30, deployment Datacenter, confidence Medium, signature_severity Major, tag SQL_Injection, updated_at 2020_09_11, mitre_tactic_id TA0001, mitr
Suricata
ET WEB_SPECIFIC_APPS Eclectic Designs CascadianFAQ SQL Injection Attempt -- index.php catid UPDATE
suricata·2010-07-30·CVSS 7.5
CVE-2007-0631 [HIGH] ET WEB_SPECIFIC_APPS Eclectic Designs CascadianFAQ SQL Injection Attempt -- index.php catid UPDATE
ET WEB_SPECIFIC_APPS Eclectic Designs CascadianFAQ SQL Injection Attempt -- index.php catid UPDATE
Rule: alert http $EXTERNAL_NET any -> $HTTP_SERVERS any (msg:"ET WEB_SPECIFIC_APPS Eclectic Designs CascadianFAQ SQL Injection Attempt -- index.php catid UPDATE"; flow:established,to_server; http.uri; content:"/index.php?"; nocase; content:"catid="; nocase; fast_pattern; content:"UPDATE"; nocase; content:"SET"; nocase; distance:0; reference:cve,CVE-2007-0631; reference:url,www.milw0rm.com/exploits/3227; classtype:web-application-attack; sid:2005116; rev:9; metadata:affected_product Web_Server_Applications, attack_target Web_Server, created_at 2010_07_30, deployment Datacenter, confidence Medium, signature_severity Major, tag SQL_Injection, updated_at 2020_09_11, mitre_tactic_id TA0001, mitre
No writeups or analysis indexed.
http://bugs.gentoo.org/show_bug.cgi?id=195315http://dev.rubyonrails.org/ticket/8371http://osvdb.org/36378http://pastie.caboo.se/65550.txthttp://secunia.com/advisories/25699http://secunia.com/advisories/27657http://secunia.com/advisories/27756http://security.gentoo.org/glsa/glsa-200711-17.xmlhttp://weblog.rubyonrails.org/2007/10/12/rails-1-2-5-maintenance-releasehttp://weblog.rubyonrails.org/2007/10/5/rails-1-2-4-maintenance-releasehttp://www.novell.com/linux/security/advisories/2007_24_sr.htmlhttp://www.securityfocus.com/bid/24161http://www.vupen.com/english/advisories/2007/2216http://bugs.gentoo.org/show_bug.cgi?id=195315http://dev.rubyonrails.org/ticket/8371http://osvdb.org/36378http://pastie.caboo.se/65550.txthttp://secunia.com/advisories/25699http://secunia.com/advisories/27657http://secunia.com/advisories/27756http://security.gentoo.org/glsa/glsa-200711-17.xmlhttp://weblog.rubyonrails.org/2007/10/12/rails-1-2-5-maintenance-releasehttp://weblog.rubyonrails.org/2007/10/5/rails-1-2-4-maintenance-releasehttp://www.novell.com/linux/security/advisories/2007_24_sr.htmlhttp://www.securityfocus.com/bid/24161http://www.vupen.com/english/advisories/2007/2216
2007-06-14
Published