CVE-2012-5664 | Ruby on Rails up to 3.0.17/3.1.8/3.2.9 ActiveRecord find_by_* sql injection (ID 165768 / XFDB-80850)
A vulnerability, which was classified as critical, was found in Ruby on Rails up to 3.0.17/3.1.8/3.2.9. Affected is the function find_by_* of the component ActiveRecord. The manipulation leads to sql injection.
This vulnerability is traded as CVE-2012-5664. It is possible to launch the attack remotely. Furthermore, there is an exploit available. This vulnerability has a historic impact due to its background and reception.
It is recommended to upgrade the affected component.