Total vulnerabilities in the database
Cross-site scripting (XSS) vulnerability in the simple_format helper in actionpack/lib/action_view/helpers/text_helper.rb in Ruby on Rails 4.x before 4.0.2 allows remote attackers to inject arbitrary web script or HTML via a crafted HTML attribute.
Software | From | Fixed in |
---|---|---|
rubyonrails / rails | 4.0.0 | 4.0.0.x |
rubyonrails / rails | - | 4.0.1.x |
rubyonrails / rails | 4.0.0-beta | 4.0.0-beta.x |
rubyonrails / rails | 4.0.0-rc1 | 4.0.0-rc1.x |
rubyonrails / rails | 4.0.0-rc2 | 4.0.0-rc2.x |
rubyonrails / rails | 4.0.1-rc1 | 4.0.1-rc1.x |
![]() |
4.0.0 | 4.0.2 |