Vulnerabilities > CVE-2011-1497 - Unspecified vulnerability in Rubyonrails Rails
Attack vector
NETWORK Attack complexity
LOW Privileges required
NONE Confidentiality impact
LOW Integrity impact
LOW Availability impact
NONE Summary
A cross-site scripting vulnerability flaw was found in the auto_link function in Rails before version 3.0.6.
Vulnerable Configurations
References
- https://github.com/rails/rails/blob/38df020c95beca7e12f0188cb7e18f3c37789e20/actionpack/CHANGELOG
- https://www.openwall.com/lists/oss-security/2011/04/06/13
- https://github.com/rails/rails/blob/38df020c95beca7e12f0188cb7e18f3c37789e20/actionpack/CHANGELOG
- https://www.openwall.com/lists/oss-security/2011/04/06/13