Lucene search

K
cvelistMitreCVELIST:CVE-2010-3933
HistoryOct 03, 2022 - 4:20 p.m.

CVE-2010-3933

2022-10-0316:20:54
mitre
www.cve.org
cve-2010-3933
remote attackers
arbitrary records
form inputs

6.5 Medium

AI Score

Confidence

Low

0.003 Low

EPSS

Percentile

70.3%

Ruby on Rails 2.3.9 and 3.0.0 does not properly handle nested attributes, which allows remote attackers to modify arbitrary records by changing the names of parameters for form inputs.

6.5 Medium

AI Score

Confidence

Low

0.003 Low

EPSS

Percentile

70.3%