Description
The safe-level feature in Ruby 1.8.7 allows context-dependent attackers to modify strings via the NameError#to_s method when operating on Ruby objects. NOTE: this issue is due to an incomplete fix for CVE-2011-1005.
Remediation
References
Related Vulnerabilities
MySQL CVE-2024-21239 Vulnerability (CVE-2024-21239)
WordPress Plugin Email Templates HTML Injection (1.3)
WordPress Plugin Author Manager Multiple Vulnerabilities (1.0)
Oracle Database Server CVE-2006-3699 Vulnerability (CVE-2006-3699)
WordPress Plugin Contact Form Submissions Unspecified Vulnerability (1.6.3)