Lumension® Endpoint Intelligence Center

Intelligence Center » Browse All Vulnerabilities » CVE-2011-4319

Overview

Vulnerability Score 4.3 4.3
CVE Id CVE-2011-4319
Last Modified 24 Aug 2012 11:22:13
Published 28 Nov 2011 06:55:09
Confidentiality Impact NONE NONE
Integrity Impact PARTIAL PARTIAL
Availability Impact NONE NONE
Access Vector NETWORK
Access Complexity MEDIUM
Authentication NONE

CVE-2011-4319

Summary

Cross-site scripting (XSS) vulnerability in the i18n translations helper method in Ruby on Rails 3.0.x before 3.0.11 and 3.1.x before 3.1.2, and the rails_xss plugin in Ruby on Rails 2.3.x, allows remote attackers to inject arbitrary web script or HTML via vectors related to a translations string whose name ends with an "html" substring.

Vulnerable Systems

Application

  • Ruby On Rails 2.3.10

  • Ruby On Rails 2.3.11

  • Ruby On Rails 2.3.12

  • Ruby On Rails 2.3.2

  • Ruby On Rails 2.3.3

  • Ruby On Rails 2.3.4

  • Ruby On Rails 2.3.9

  • Ruby On Rails 3.0.0

  • Ruby On Rails 3.0.1

  • Ruby On Rails 3.0.10

  • Ruby On Rails 3.0.2

  • Ruby On Rails 3.0.3

  • Ruby On Rails 3.0.4

  • Ruby On Rails 3.0.5

  • Ruby On Rails 3.0.6

  • Ruby On Rails 3.0.7

  • Ruby On Rails 3.0.8

  • Ruby On Rails 3.0.9

  • Ruby On Rails 3.1.0

  • Ruby On Rails 3.1.1

  • Ruby On Rails Rails Xss Plugin

  • Rubyonrails Ruby On Rails 2.3.10

  • Rubyonrails Ruby On Rails 2.3.11

  • Rubyonrails Ruby On Rails 2.3.12

  • Rubyonrails Ruby On Rails 2.3.2

  • Rubyonrails Ruby On Rails 2.3.3

  • Rubyonrails Ruby On Rails 2.3.4

  • Rubyonrails Ruby On Rails 2.3.9

  • Rubyonrails Ruby On Rails 3.0.0

  • Rubyonrails Ruby On Rails 3.0.1

  • Rubyonrails Ruby On Rails 3.0.10

  • Rubyonrails Ruby On Rails 3.0.2

  • Rubyonrails Ruby On Rails 3.0.3

  • Rubyonrails Ruby On Rails 3.0.4

  • Rubyonrails Ruby On Rails 3.0.5

  • Rubyonrails Ruby On Rails 3.0.6

  • Rubyonrails Ruby On Rails 3.0.7

  • Rubyonrails Ruby On Rails 3.0.8

  • Rubyonrails Ruby On Rails 3.0.9

  • Rubyonrails Ruby On Rails 3.1.0

  • Rubyonrails Ruby On Rails 3.1.1


References

CONFIRM - http://weblog.rubyonrails.org/2011/11/18/rails-3-1-2-has-been-released

CONFIRM - http://weblog.rubyonrails.org/2011/11/18/rails-3-0-11-has-been-released

MLIST - [oss-security] 20111118 Re: CVE Request -- Ruby on Rails / rubygem-actionpack -- XSS in the 'translate' helper method

MLIST - [rubyonrails-security] 20111118 XSS vulnerability in the translate helper method in Ruby on Rails

XF - rubyonrails-translatehelper-xss(71364)

SECTRACK - 1026342

BID - 50722

OSVDB - 77199

CONFIRM - http://groups.google.com/group/rubyonrails-security/browse_thread/thread/2b61d70fb73c7cc5?pli=1


Last Updated: 27 May 2016 10:54:50