Description
The URI.decode_www_form_component method in Ruby before 1.9.2-p330 allows remote attackers to cause a denial of service (catastrophic regular expression backtracking, resource consumption, or application crash) via a crafted string.
Remediation
References
Related Vulnerabilities
WordPress Plugin Responsive Poll Cross-Site Scripting (1.5.8)
WordPress Plugin AI ChatBot Cross-Site Scripting (4.9.6)
WordPress Plugin Code Snippets Cross-Site Request Forgery (2.13.3)
WordPress 3.8.3 Multiple Vulnerabilities (3.8 - 3.8.3)
WordPress Plugin Archive Posts Sort Customize Cross-Site Scripting (1.5)