SQL injection vulnerability in the 'find_by' method in Ruby on Rails 5.1.4 and earlier allows remote attackers to execute arbitrary SQL commands via the 'name' parameter. NOTE: The vendor disputes this issue because the documentation states that this method is not intended for use with untrusted input
                
            References
                    | Link | Resource | 
|---|---|
| https://kay-malwarebenchmark.github.io/blog/ruby-on-rails-arbitrary-sql-injection/ | Exploit Third Party Advisory | 
| https://kay-malwarebenchmark.github.io/blog/ruby-on-rails-arbitrary-sql-injection/ | Exploit Third Party Advisory | 
Configurations
                    History
                    21 Nov 2024, 03:18
| Type | Values Removed | Values Added | 
|---|---|---|
| References | () https://kay-malwarebenchmark.github.io/blog/ruby-on-rails-arbitrary-sql-injection/ - Exploit, Third Party Advisory | 
07 Nov 2023, 02:41
| Type | Values Removed | Values Added | 
|---|---|---|
| Summary | SQL injection vulnerability in the 'find_by' method in Ruby on Rails 5.1.4 and earlier allows remote attackers to execute arbitrary SQL commands via the 'name' parameter. NOTE: The vendor disputes this issue because the documentation states that this method is not intended for use with untrusted input | 
19 May 2023, 16:51
| Type | Values Removed | Values Added | 
|---|---|---|
| First Time | Rubyonrails rails | |
| CPE | cpe:2.3:a:rubyonrails:rails:*:*:*:*:*:*:*:* | 
Information
                Published : 2017-12-29 16:29
Updated : 2025-04-20 01:37
NVD link : CVE-2017-17916
Mitre link : CVE-2017-17916
CVE.ORG link : CVE-2017-17916
JSON object : View
Products Affected
                rubyonrails
- rails
CWE
                
                    
                        
                        CWE-89
                        
            Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
