Description
Cross-site scripting (XSS) vulnerability in actionpack/lib/action_view/helpers/form_tag_helper.rb in Ruby on Rails 3.x before 3.0.17, 3.1.x before 3.1.8, and 3.2.x before 3.2.8 allows remote attackers to inject arbitrary web script or HTML via the prompt field to the select_tag helper.
Remediation
References
Related Vulnerabilities
WordPress Plugin jQuery Reply to Comment Cross-Site Request Forgery (1.31)
WordPress Plugin All-In-One Security (AIOS)-Security and Firewall SQL Injection (4.0.8)
Oracle Database Server CVE-2010-0903 Vulnerability (CVE-2010-0903)
WordPress Plugin WP Featured Post with thumbnail 'src' Parameter Cross-Site Scripting (3.0)