CVE-2012-6496

Description

SQL injection vulnerability in the Active Record component in Ruby on Rails before 3.0.18, 3.1.x before 3.1.9, and 3.2.x before 3.2.10 allows remote attackers to execute arbitrary SQL commands via a crafted request that leverages incorrect behavior of dynamic finders in applications that can use unexpected data types in certain find_by_ method calls.

Risk Information

Base Score
9.8
MODERATE
Vector
AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS Score
Exploitation Probability
1.017

Associated Vulnerability

VulnerabilityOS Platform
Vulnerabilities CVE-2012-2695,CVE-2012-6496 are fixed in Ruby-activerecord 2.3.15Windows
Vulnerabilities CVE-2012-6496 are fixed in Ruby-activerecord 3.1.9Windows
Vulnerabilities CVE-2012-6496 are fixed in Ruby-activerecord 3.2.10Windows
Vulnerabilities CVE-2012-6496 are fixed in Ruby-activerecord 3.0.18Windows
Vulnerabilities CVE-2012-2695,CVE-2012-6496 are fixed in Ruby-activerecord for Linux 2.3.15Linux
Vulnerabilities CVE-2012-6496 are fixed in Ruby-activerecord for Linux 3.1.9Linux
Vulnerabilities CVE-2012-6496 are fixed in Ruby-activerecord for Linux 3.2.10Linux
Vulnerabilities CVE-2012-6496 are fixed in Ruby-activerecord for Linux 3.0.18Linux

Patch Details

No records found

References

https://nvd.nist.gov/vuln/detail/CVE-2023-1234
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-1234