cbcvebase.
CVE-2011-0448
published 2011-02-21

CVE-2011-0448: Ruby on Rails 3.0.x before 3.0.4 does not ensure that arguments to the limit function specify integer values, which makes it easier for remote attackers to…

PriorityP336high7.5CVSS 2.0
AVNACLAuNCPIPAP
EPSS
2.17%
80.3th percentile
Ruby on Rails 3.0.x before 3.0.4 does not ensure that arguments to the limit function specify integer values, which makes it easier for remote attackers to conduct SQL injection attacks via a non-numeric argument.

Affected

7 ranges
VendorProductVersion rangeFixed in
activerecord_projectactiverecord>= 3.0.0 < 3.0.43.0.4
debianrails
rubyonrailsrails
rubyonrailsrails
rubyonrailsrails
rubyonrailsrails
rubyonrailsrails

CVSS provenance

nvdv2.07.5HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
vendor_debian7.5LOW
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.