CVE-2013-6415
published 2013-12-07CVE-2013-6415: Cross-site scripting (XSS) vulnerability in the number_to_currency helper in actionpack/lib/action_view/helpers/number_helper.rb in Ruby on Rails before 3.2.16…
PriorityP420medium4.3CVSS 2.0
AVNACMAuNCNIPAN
EPSS
3.17%
86.6th percentile
Cross-site scripting (XSS) vulnerability in the number_to_currency helper in actionpack/lib/action_view/helpers/number_helper.rb in Ruby on Rails before 3.2.16 and 4.x before 4.0.2 allows remote attackers to inject arbitrary web script or HTML via the unit parameter.
Affected
56 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| actionpack_project | actionpack | >= 3.0.0 < 3.2.16 | 3.2.16 |
| actionpack_project | actionpack | >= 4.0.0 < 4.0.2 | 4.0.2 |
| debian | rails | — | — |
| rubyonrails | rails | <= 4.0.1 | — |
| rubyonrails | rails | — | — |
| rubyonrails | rails | — | — |
| rubyonrails | rails | — | — |
| rubyonrails | rails | — | — |
| rubyonrails | rails | — | — |
| rubyonrails | rails | — | — |
| rubyonrails | rails | — | — |
| rubyonrails | rails | — | — |
| rubyonrails | rails | — | — |
| rubyonrails | rails | — | — |
| rubyonrails | rails | — | — |
| rubyonrails | rails | — | — |
| rubyonrails | rails | — | — |
| rubyonrails | rails | — | — |
| rubyonrails | rails | — | — |
| rubyonrails | rails | — | — |
| rubyonrails | rails | — | — |
| rubyonrails | rails | — | — |
| rubyonrails | rails | — | — |
| rubyonrails | rails | — | — |
| rubyonrails | rails | — | — |
CVSS provenance
nvdv2.04.3MEDIUMAV:N/AC:M/Au:N/C:N/I:P/A:N
osv4.3MEDIUM
vendor_debian4.3LOW
vendor_redhat4.3MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
rubygem-actionpack: number_to_currency XSS
vendor_redhat·2013-12-03·CVSS 4.3
CVE-2013-6415 [MEDIUM] CWE-79 rubygem-actionpack: number_to_currency XSS
rubygem-actionpack: number_to_currency XSS
Cross-site scripting (XSS) vulnerability in the number_to_currency helper in actionpack/lib/action_view/helpers/number_helper.rb in Ruby on Rails before 3.2.16 and 4.x before 4.0.2 allows remote attackers to inject arbitrary web script or HTML via the unit parameter.
It was found that the number_to_currency Action View helper did not properly escape the unit parameter. An attacker could use this flaw to perform a cross-site scripting (XSS) attack on an application that uses data submitted by a user in the unit parameter.
Package: ruby193-rubygem-actionpack (CloudForms Management Engine 5) - Affected
Package: ruby193-rubygem-actionpack (OpenShift Enterprise 1) - Will not fix
Package: ruby193-rubygem-actionpack (Red Hat OpenStack Platform 4) -
Debian
CVE-2013-6415: rails - Cross-site scripting (XSS) vulnerability in the number_to_currency helper in act...
vendor_debian·2013·CVSS 4.3
CVE-2013-6415 [MEDIUM] CVE-2013-6415: rails - Cross-site scripting (XSS) vulnerability in the number_to_currency helper in act...
Cross-site scripting (XSS) vulnerability in the number_to_currency helper in actionpack/lib/action_view/helpers/number_helper.rb in Ruby on Rails before 3.2.16 and 4.x before 4.0.2 allows remote attackers to inject arbitrary web script or HTML via the unit parameter.
Scope: local
bookworm: resolved
bullseye: resolved
forky: resolved
sid: resolved
trixie: resolved
OSV
actionpack vulnerable to Cross-site Scripting
osv·2017-10-24
CVE-2013-6415 [MEDIUM] actionpack vulnerable to Cross-site Scripting
actionpack vulnerable to Cross-site Scripting
Cross-site scripting (XSS) vulnerability in the `number_to_currency` helper in `actionpack/lib/action_view/helpers/number_helper.rb` in Ruby on Rails before 3.2.16 and 4.x before 4.0.2 allows remote attackers to inject arbitrary web script or HTML via the unit parameter.
GHSA
actionpack vulnerable to Cross-site Scripting
ghsa·2017-10-24
CVE-2013-6415 [MEDIUM] CWE-79 actionpack vulnerable to Cross-site Scripting
actionpack vulnerable to Cross-site Scripting
Cross-site scripting (XSS) vulnerability in the `number_to_currency` helper in `actionpack/lib/action_view/helpers/number_helper.rb` in Ruby on Rails before 3.2.16 and 4.x before 4.0.2 allows remote attackers to inject arbitrary web script or HTML via the unit parameter.
OSV
CVE-2013-6415: Cross-site scripting (XSS) vulnerability in the number_to_currency helper in actionpack/lib/action_view/helpers/number_helper
osv·2013-12-07·CVSS 4.3
CVE-2013-6415 [MEDIUM] CVE-2013-6415: Cross-site scripting (XSS) vulnerability in the number_to_currency helper in actionpack/lib/action_view/helpers/number_helper
Cross-site scripting (XSS) vulnerability in the number_to_currency helper in actionpack/lib/action_view/helpers/number_helper.rb in Ruby on Rails before 3.2.16 and 4.x before 4.0.2 allows remote attackers to inject arbitrary web script or HTML via the unit parameter.
No detection rules found.
No public exploits indexed.
http://lists.opensuse.org/opensuse-updates/2013-12/msg00079.htmlhttp://lists.opensuse.org/opensuse-updates/2013-12/msg00080.htmlhttp://lists.opensuse.org/opensuse-updates/2013-12/msg00081.htmlhttp://lists.opensuse.org/opensuse-updates/2013-12/msg00082.htmlhttp://lists.opensuse.org/opensuse-updates/2014-01/msg00003.htmlhttp://lists.opensuse.org/opensuse-updates/2014-01/msg00013.htmlhttp://rhn.redhat.com/errata/RHSA-2013-1794.htmlhttp://rhn.redhat.com/errata/RHSA-2014-0008.htmlhttp://rhn.redhat.com/errata/RHSA-2014-1863.htmlhttp://secunia.com/advisories/56093http://weblog.rubyonrails.org/2013/12/3/Rails_3_2_16_and_4_0_2_have_been_released/http://www.debian.org/security/2014/dsa-2888http://www.securityfocus.com/bid/64077https://groups.google.com/forum/message/raw?msg=ruby-security-ann/9WiRn2nhfq0/2K2KRB4LwCMJhttps://puppet.com/security/cve/cve-2013-6415http://lists.opensuse.org/opensuse-updates/2013-12/msg00079.htmlhttp://lists.opensuse.org/opensuse-updates/2013-12/msg00080.htmlhttp://lists.opensuse.org/opensuse-updates/2013-12/msg00081.htmlhttp://lists.opensuse.org/opensuse-updates/2013-12/msg00082.htmlhttp://lists.opensuse.org/opensuse-updates/2014-01/msg00003.htmlhttp://lists.opensuse.org/opensuse-updates/2014-01/msg00013.htmlhttp://rhn.redhat.com/errata/RHSA-2013-1794.htmlhttp://rhn.redhat.com/errata/RHSA-2014-0008.htmlhttp://rhn.redhat.com/errata/RHSA-2014-1863.htmlhttp://secunia.com/advisories/56093http://weblog.rubyonrails.org/2013/12/3/Rails_3_2_16_and_4_0_2_have_been_released/http://www.debian.org/security/2014/dsa-2888http://www.securityfocus.com/bid/64077https://groups.google.com/forum/message/raw?msg=ruby-security-ann/9WiRn2nhfq0/2K2KRB4LwCMJhttps://puppet.com/security/cve/cve-2013-6415
2013-12-07
Published