Looking for the vulnerability index of Invicti's legacy products?
Ruby on Rails Use of Externally-Controlled Format String Vulnerability (CVE-2013-4389) - Vulnerability Database

Ruby on Rails Use of Externally-Controlled Format String Vulnerability (CVE-2013-4389)

Description

Multiple format string vulnerabilities in log_subscriber.rb files in the log subscriber component in Action Mailer in Ruby on Rails 3.x before 3.2.15 allow remote attackers to cause a denial of service via a crafted e-mail address that is improperly handled during construction of a log message.

References

Related Vulnerabilities