CVE Database
/

CVE-2010-3933

Back to search

CVE-2010-3933

Published: Oct 27, 2010

Modified: Sep 16, 2024

PUBLISHED

Description

Ruby on Rails 2.3.9 and 3.0.0 does not properly handle nested attributes, which allows remote attackers to modify arbitrary records by changing the names of parameters for form inputs.

VendorProductVersions

n/a

n/a

affected
n/a

References

ADV-2010-2719
vdb-entry
x_refsource_VUPEN
41930
third-party-advisory
x_refsource_SECUNIA
1024624
vdb-entry
x_refsource_SECTRACK

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now