CVE-2011-0448
Ruby on Rails 3.0.x before 3.0.4 does not ensure that arguments to the limit function specify integer values, which make
Ruby on Rails 3.0.x before 3.0.4 does not ensure that arguments to the limit function specify integer values, which makes it easier for remote attackers to conduct SQL injection attacks via a non-numeric argument.
HIGH · CVSS 7.5
EPSS 0.00689
Schedule remediation
- CVSS base score ≥ 7.0
Sigma rules1
YARA rules0