CVE-2012-5664: Ruby on Rails: find_by_* SQL Injection(bugzilla.redhat.com)
bugzilla.redhat.com
CVE-2012-5664: Ruby on Rails: find_by_* SQL Injection
https://bugzilla.redhat.com/show_bug.cgi?id=889649
1 comments
Although devise is by far the most popular, by looking at rubygems[1] it seems AuthLogic still is fairly widely used.
[1] http://rubygems.org/gems/authlogic
[1] http://rubygems.org/gems/authlogic
So, to see this you must:
This still is a bad bug, but the instances of this bug being used in an attack are going to be very few.