Lumension® Endpoint Intelligence Center

Intelligence Center » Browse All Vulnerabilities » CVE-2012-6497

Overview

Vulnerability Score 5.0 5.0
CVE Id CVE-2012-6497
Last Modified 04 Jan 2013 09:39:16
Published 03 Jan 2013 11:46:02
Confidentiality Impact PARTIAL PARTIAL
Integrity Impact NONE NONE
Availability Impact NONE NONE
Access Vector NETWORK
Access Complexity LOW
Authentication NONE

CVE-2012-6497

Summary

The Authlogic gem for Ruby on Rails, when used with certain versions before 3.2.10, makes potentially unsafe find_by_id method calls, which might allow remote attackers to conduct CVE-2012-6496 SQL injection attacks via a crafted parameter in environments that have a known secret_token value, as demonstrated by a value contained in secret_token.rb in an open-source product.

Vulnerable Systems

Application

  • Rubyonrails Ruby On Rails 0.10.0

  • Rubyonrails Ruby On Rails 0.10.1

  • Rubyonrails Ruby On Rails 0.11.0

  • Rubyonrails Ruby On Rails 0.11.1

  • Rubyonrails Ruby On Rails 0.12.0

  • Rubyonrails Ruby On Rails 0.12.1

  • Rubyonrails Ruby On Rails 0.13.0

  • Rubyonrails Ruby On Rails 0.13.1

  • Rubyonrails Ruby On Rails 0.14.1

  • Rubyonrails Ruby On Rails 0.14.2

  • Rubyonrails Ruby On Rails 0.14.3

  • Rubyonrails Ruby On Rails 0.14.4

  • Rubyonrails Ruby On Rails 0.5.0

  • Rubyonrails Ruby On Rails 0.5.5

  • Rubyonrails Ruby On Rails 0.5.6

  • Rubyonrails Ruby On Rails 0.5.7

  • Rubyonrails Ruby On Rails 0.6.0

  • Rubyonrails Ruby On Rails 0.6.5

  • Rubyonrails Ruby On Rails 0.7.0

  • Rubyonrails Ruby On Rails 0.8.0

  • Rubyonrails Ruby On Rails 0.8.5

  • Rubyonrails Ruby On Rails 0.9.0

  • Rubyonrails Ruby On Rails 0.9.1

  • Rubyonrails Ruby On Rails 0.9.2

  • Rubyonrails Ruby On Rails 0.9.3

  • Rubyonrails Ruby On Rails 0.9.4

  • Rubyonrails Ruby On Rails 0.9.4.1

  • Rubyonrails Ruby On Rails 1.0.0

  • Rubyonrails Ruby On Rails 1.1.0

  • Rubyonrails Ruby On Rails 1.1.1

  • Rubyonrails Ruby On Rails 1.1.2

  • Rubyonrails Ruby On Rails 1.1.3

  • Rubyonrails Ruby On Rails 1.1.4

  • Rubyonrails Ruby On Rails 1.1.5

  • Rubyonrails Ruby On Rails 1.1.6

  • Rubyonrails Ruby On Rails 1.2.0

  • Rubyonrails Ruby On Rails 1.2.1

  • Rubyonrails Ruby On Rails 1.2.2

  • Rubyonrails Ruby On Rails 1.2.3

  • Rubyonrails Ruby On Rails 1.2.4

  • Rubyonrails Ruby On Rails 1.2.5

  • Rubyonrails Ruby On Rails 1.2.6

  • Rubyonrails Ruby On Rails 1.9.5

  • Rubyonrails Ruby On Rails 2.0.0

  • Rubyonrails Ruby On Rails 2.0.1

  • Rubyonrails Ruby On Rails 2.0.2

  • Rubyonrails Ruby On Rails 2.0.4

  • Rubyonrails Ruby On Rails 2.1

  • Rubyonrails Ruby On Rails 2.1.0

  • Rubyonrails Ruby On Rails 2.1.1

  • Rubyonrails Ruby On Rails 2.1.2

  • Rubyonrails Ruby On Rails 2.2.0

  • Rubyonrails Ruby On Rails 2.2.1

  • Rubyonrails Ruby On Rails 2.2.2

  • Rubyonrails Ruby On Rails 2.3.10

  • Rubyonrails Ruby On Rails 2.3.11

  • Rubyonrails Ruby On Rails 2.3.12

  • Rubyonrails Ruby On Rails 2.3.2

  • Rubyonrails Ruby On Rails 2.3.3

  • Rubyonrails Ruby On Rails 2.3.4

  • Rubyonrails Ruby On Rails 2.3.9

  • Rubyonrails Ruby On Rails 3.0.0

  • Rubyonrails Ruby On Rails 3.0.1

  • Rubyonrails Ruby On Rails 3.0.10

  • Rubyonrails Ruby On Rails 3.0.11

  • Rubyonrails Ruby On Rails 3.0.12

  • Rubyonrails Ruby On Rails 3.0.13

  • Rubyonrails Ruby On Rails 3.0.14

  • Rubyonrails Ruby On Rails 3.0.16

  • Rubyonrails Ruby On Rails 3.0.17

  • Rubyonrails Ruby On Rails 3.0.2

  • Rubyonrails Ruby On Rails 3.0.3

  • Rubyonrails Ruby On Rails 3.0.4

  • Rubyonrails Ruby On Rails 3.0.5

  • Rubyonrails Ruby On Rails 3.0.6

  • Rubyonrails Ruby On Rails 3.0.7

  • Rubyonrails Ruby On Rails 3.0.8

  • Rubyonrails Ruby On Rails 3.0.9

  • Rubyonrails Ruby On Rails 3.1.0

  • Rubyonrails Ruby On Rails 3.1.1

  • Rubyonrails Ruby On Rails 3.1.2

  • Rubyonrails Ruby On Rails 3.1.3

  • Rubyonrails Ruby On Rails 3.1.4

  • Rubyonrails Ruby On Rails 3.1.5

  • Rubyonrails Ruby On Rails 3.1.6

  • Rubyonrails Ruby On Rails 3.1.7

  • Rubyonrails Ruby On Rails 3.1.8

  • Rubyonrails Ruby On Rails 3.2.0

  • Rubyonrails Ruby On Rails 3.2.1

  • Rubyonrails Ruby On Rails 3.2.2

  • Rubyonrails Ruby On Rails 3.2.3

  • Rubyonrails Ruby On Rails 3.2.4

  • Rubyonrails Ruby On Rails 3.2.5

  • Rubyonrails Ruby On Rails 3.2.6

  • Rubyonrails Ruby On Rails 3.2.7

  • Rubyonrails Ruby On Rails 3.2.8

  • Rubyonrails Ruby On Rails 3.2.9


References

MISC - http://phenoelit.org/blog/archives/2012/12/21/let_me_github_that_for_you/index.html

MLIST - [oss-security] 20130103 Re: SQL Injection Vulnerability in Ruby on Rails (CVE-2012-5664)

MISC - http://blog.phusion.nl/2013/01/03/rails-sql-injection-vulnerability-hold-your-horses-here-are-the-facts/


Last Updated: 27 May 2016 11:01:34