actionpack/lib/action_dispatch/http/request.rb in Ruby on Rails before 3.0.14, 3.1.x before 3.1.6, and 3.2.x before 3.2.6 does not properly consider differences in parameter handling between the Active Record component and the Rack interface, which allows remote attackers to bypass intended database-query restrictions and perform NULL checks via a crafted request, as demonstrated by certain "['xyz', nil]" values, a related issue to CVE-2012-2660.
History

No history.

cve-icon MITRE Information

Status: PUBLISHED

Assigner: redhat

Published: 2012-06-22T14:00:00

Updated: 2012-09-07T09:00:00

Reserved: 2012-05-14T00:00:00


Link: CVE-2012-2694

JSON object: View

cve-icon NVD Information

Status : Modified

Published: 2012-06-22T14:55:01.097

Modified: 2019-08-08T15:42:45.623


Link: CVE-2012-2694

JSON object: View

cve-icon Redhat Information

No data.

CWE