CVE-2008-4094
published 2008-09-30CVE-2008-4094: Multiple SQL injection vulnerabilities in Ruby on Rails before 2.1.1 allow remote attackers to execute arbitrary SQL commands via the (1) :limit and (2)…
PriorityP342high7.5CVSS 2.0
AVNACLAuNCPIPAP
EPSS
3.03%
86.0th percentile
Multiple SQL injection vulnerabilities in Ruby on Rails before 2.1.1 allow remote attackers to execute arbitrary SQL commands via the (1) :limit and (2) :offset parameters, related to ActiveRecord, ActiveSupport, ActiveResource, ActionPack, and ActionMailer.
Affected
55 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| activerecord_project | activerecord | >= 0 < 2.1.1 | 2.1.1 |
| debian | rails | < rails 2.1.0-1 (bookworm) | rails 2.1.0-1 (bookworm) |
| rubyonrails | rails | — | — |
| rubyonrails | rails | — | — |
| rubyonrails | rails | — | — |
| rubyonrails | rails | — | — |
| rubyonrails | rails | — | — |
| rubyonrails | rails | — | — |
| rubyonrails | rails | — | — |
| rubyonrails | rails | — | — |
| rubyonrails | rails | — | — |
| rubyonrails | rails | — | — |
| rubyonrails | rails | — | — |
| rubyonrails | rails | — | — |
| rubyonrails | rails | — | — |
| rubyonrails | rails | — | — |
| rubyonrails | rails | — | — |
| rubyonrails | rails | — | — |
| rubyonrails | rails | — | — |
| rubyonrails | rails | — | — |
| rubyonrails | rails | — | — |
| rubyonrails | rails | — | — |
| rubyonrails | rails | — | — |
| rubyonrails | rails | — | — |
| rubyonrails | rails | — | — |
CVSS provenance
nvdv2.07.5HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
osv7.5HIGH
vendor_debian7.5MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
OSV
Rails ActiveRecord gem vulnerable to SQL injection
osv·2017-10-24
CVE-2008-4094 [HIGH] Rails ActiveRecord gem vulnerable to SQL injection
Rails ActiveRecord gem vulnerable to SQL injection
Multiple SQL injection vulnerabilities in Ruby on Rails before 2.1.1 allow remote attackers to execute arbitrary SQL commands via the (1) `:limit` and (2) `:offset` parameters, related to ActiveRecord, ActiveSupport, ActiveResource, ActionPack, and ActionMailer.
GHSA
Rails ActiveRecord gem vulnerable to SQL injection
ghsa·2017-10-24
CVE-2008-4094 [HIGH] CWE-89 Rails ActiveRecord gem vulnerable to SQL injection
Rails ActiveRecord gem vulnerable to SQL injection
Multiple SQL injection vulnerabilities in Ruby on Rails before 2.1.1 allow remote attackers to execute arbitrary SQL commands via the (1) `:limit` and (2) `:offset` parameters, related to ActiveRecord, ActiveSupport, ActiveResource, ActionPack, and ActionMailer.
OSV
CVE-2008-4094: Multiple SQL injection vulnerabilities in Ruby on Rails before 2
osv·2008-09-30·CVSS 7.5
CVE-2008-4094 [HIGH] CVE-2008-4094: Multiple SQL injection vulnerabilities in Ruby on Rails before 2
Multiple SQL injection vulnerabilities in Ruby on Rails before 2.1.1 allow remote attackers to execute arbitrary SQL commands via the (1) :limit and (2) :offset parameters, related to ActiveRecord, ActiveSupport, ActiveResource, ActionPack, and ActionMailer.
Debian
CVE-2008-4094: rails - Multiple SQL injection vulnerabilities in Ruby on Rails before 2.1.1 allow remot...
vendor_debian·2008·CVSS 7.5
CVE-2008-4094 [HIGH] CVE-2008-4094: rails - Multiple SQL injection vulnerabilities in Ruby on Rails before 2.1.1 allow remot...
Multiple SQL injection vulnerabilities in Ruby on Rails before 2.1.1 allow remote attackers to execute arbitrary SQL commands via the (1) :limit and (2) :offset parameters, related to ActiveRecord, ActiveSupport, ActiveResource, ActionPack, and ActionMailer.
Scope: local
bookworm: resolved (fixed in 2.1.0-1)
bullseye: resolved (fixed in 2.1.0-1)
forky: resolved (fixed in 2.1.0-1)
sid: resolved (fixed in 2.1.0-1)
trixie: resolved (fixed in 2.1.0-1)
No detection rules found.
No public exploits indexed.
http://blog.innerewut.de/2008/6/16/why-you-should-upgrade-to-rails-2-1http://gist.github.com/8946http://lists.opensuse.org/opensuse-security-announce/2008-12/msg00002.htmlhttp://rails.lighthouseapp.com/projects/8994/tickets/288http://rails.lighthouseapp.com/projects/8994/tickets/964http://secunia.com/advisories/31875http://secunia.com/advisories/31909http://secunia.com/advisories/31910http://www.openwall.com/lists/oss-security/2008/09/13/2http://www.openwall.com/lists/oss-security/2008/09/16/1http://www.rorsecurity.info/2008/09/08/sql-injection-issue-in-limit-and-offset-parameter/http://www.securityfocus.com/bid/31176http://www.securitytracker.com/id?1020871http://www.vupen.com/english/advisories/2008/2562https://exchange.xforce.ibmcloud.com/vulnerabilities/45109http://blog.innerewut.de/2008/6/16/why-you-should-upgrade-to-rails-2-1http://gist.github.com/8946http://lists.opensuse.org/opensuse-security-announce/2008-12/msg00002.htmlhttp://rails.lighthouseapp.com/projects/8994/tickets/288http://rails.lighthouseapp.com/projects/8994/tickets/964http://secunia.com/advisories/31875http://secunia.com/advisories/31909http://secunia.com/advisories/31910http://www.openwall.com/lists/oss-security/2008/09/13/2http://www.openwall.com/lists/oss-security/2008/09/16/1http://www.rorsecurity.info/2008/09/08/sql-injection-issue-in-limit-and-offset-parameter/http://www.securityfocus.com/bid/31176http://www.securitytracker.com/id?1020871http://www.vupen.com/english/advisories/2008/2562https://exchange.xforce.ibmcloud.com/vulnerabilities/45109
2008-09-30
Published