hypnosec writes: All version of Ruby on Rails bar the three new versions are vulnerable to an SQL injection vulnerability, the developers of the web framework have warned through an advisory. The advisory notes that the vulnerability exists because of the manner in which dynamic finders in ActiveRecord extract options from method parameters. Because of the extraction mechanism an attacker can use a method parameter as a scope, manipulate it carefully and thereby inject arbitrary SQL code leading to an SQL injection. The vulnerability has been assigned the CVE identifier CVE-2012-5664.
DEAL: For $25 - Add A Second Phone Number To Your Smartphone for life! Use promo code SLASHDOT25. Also, Slashdot's Facebook page has a chat bot now. Message it for stories and more. Check out the new SourceForge HTML5 internet speed test! ×