Rejected
This vulnerability has been rejected by the source.
Current Description
** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2012-6496, CVE-2012-6497. Reason: this candidate was intended for one issue, but the candidate was publicly used to label concerns about multiple products. Notes: All CVE users should consult CVE-2012-6496 and CVE-2012-6497 to determine which ID is appropriate. All references and descriptions in this candidate have been removed to prevent accidental usage.
Source:
MITRE
Description Last Modified:
12/26/2012
View Analysis Description
Analysis Description
SQL injection vulnerability in the Authlogic gem for Ruby on Rails allows remote attackers to execute arbitrary SQL commands via a crafted parameter in conjunction with a secret_token value.
Source:
MITRE
Description Last Modified:
12/26/2012
References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving NIST webspace. We have provided these links to other web sites because
they may have information that would be of interest to you. No inferences should be drawn on account of other sites
being referenced, or not, from this page. There may be other web sites that are more appropriate for your purpose.
NIST does not necessarily endorse the views expressed, or concur with the facts presented on these sites. Further,
NIST does not endorse any commercial products that may be mentioned on these sites. Please address comments about
this page to nvd@nist.gov.
Change History
2 change records found
- show changes
CVE Translated -
6/19/2015 6:45:00 AM
| Action |
Type |
Old Value |
New Value |
| Added |
Translation |
|
Record truncated, showing 500 of 559 characters.
View Entire Change Record
** RECHAZADA ** NO UTILICE ESTE NÚMERO DE CANDIDATO. Consulte los identificadores: CVE-2012-6496, CVE-2012-6497. Motivo: este candidato fue pensado para un problema, pero el candidato se utilizó públicamente para etiquetar preocupaciones sobre múltiples productos. Notas: Todos los usuarios de los CVEs deben consultar CVE-2012-6496 y CVE-2012-6497 para determinar cual de los identificadores es el indicado. Todas las referencias y descripciones en este c |
| Removed |
Translation |
Una vulnerabilidad de inyección SQL en Authlogic gem para Ruby on Rails, permite a atacantes remotos ejecutar comandos SQL a través de un parámetro modificado para tal fin junto con un valor de secret_token. Se trata de un problema relacionado con un determinado comportamiento de find_by_id y otros métodos "find_by_" .
|
|
Initial CVE Analysis -
12/27/2012 12:03:00 PM