Ruby on Rails Improper Neutralization of Special Elements used in an SQL Command (SQL Injection) Vulnerability - CVE-2014-0080 - Vulnerability Database

Ruby on Rails Improper Neutralization of Special Elements used in an SQL Command (SQL Injection) Vulnerability - CVE-2014-0080

Medium
Reference: CVE-2014-0080
Title: Ruby on Rails Improper Neutralization of Special Elements used in an SQL Command (SQL Injection) Vulnerability
Overview:

SQL injection vulnerability in activerecord/lib/active_record/connection_adapters/postgresql/cast.rb in Active Record in Ruby on Rails 4.0.x before 4.0.3 and 4.1.0.beta1 when PostgreSQL is used allows remote attackers to execute quotadd dataquot SQL commands via vectors involving (backslash) characters that are not properly handled in operations on array columns.