Ruby on Rails Active Record SQL Injection Vulnerability UPDATED
20 Aug. 2012
Summary
Ruby on Rails is prone to an SQL-injection vulnerability.
Credit:
The original article can be found at: http://www.securityfocus.com/bid/53970
The information has been provided by Justin Collins, Ernie Miller, Gabriel Quadros, Takeshi Terada of Mitsui Bussan.
Vulnerable Systems:
* Ruby on Rails Ruby on Rails 3.2.4 and prior
Exploiting this issue could allow an attacker to compromise the application, access or modify data, or exploit latent vulnerabilities in the underlying database.
Vendor Status:
Vendor as issued an updated vulnerability.