Security Portal

Intrusion Prevention Service

 
Signature Version: 4.938

 



WEB Ruby on Rails Where Hash SQL Injection (CVE-2012-2695)
 
Threat Level: High
Release Date: 2012/7/30
 
Category: Web Attacks
Signature ID: 1056282
Included In:
Affected OS: Windows, Linux, FreeBSD, Solaris, Mac OS
 
Description: A vulnerability has been discovered in Ruby on Rails. The vulnerability is due to an improper input validation error while handling hash values.
 
Impact: SQL injection
Recommendation: Update vendor's patch.
 
False Positive: None
False Negative: None
 
Additional Information (Links open in new window):
Reference(s): CVE-2012-2695
 

Search the Threat Database
Enter Rule ID or Name