Looking for the vulnerability index of Invicti's legacy products?
Ruby on Rails Improper Input Validation Vulnerability (CVE-2016-2098) - Vulnerability Database

Ruby on Rails Improper Input Validation Vulnerability (CVE-2016-2098)

Description

Action Pack in Ruby on Rails before 3.2.22.2, 4.x before 4.1.14.2, and 4.2.x before 4.2.5.2 allows remote attackers to execute arbitrary Ruby code by leveraging an application's unrestricted use of the render method.

References

Related Vulnerabilities