CVE-2011-0446: XSS
Multiple cross-site scripting (XSS) vulnerabilities in the mailto helper in Ruby on Rails before 2.3.11, and 3.x before 3.0.4, when javascript encoding is used, allow remote attackers to inject arbitrary web script or HTML via a crafted (1) name or (2) email value.
Other sources
Multiple cross-site scripting (XSS) vulnerabilities in the mailto helper in Ruby on Rails before 2.3.11, and 3.x before 3.0.4, when javascript encoding is used, allow remote attackers to inject arbitrary web script or HTML via a crafted (1) name or (2) email value.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2011-0446?
The severity of CVE-2011-0446 is considered medium due to the potential impact of cross-site scripting (XSS) attacks.
How do I fix CVE-2011-0446?
To fix CVE-2011-0446, upgrade Ruby on Rails to version 3.0.4 or 2.3.11 or later.
What are the affected versions related to CVE-2011-0446?
CVE-2011-0446 affects Ruby on Rails versions prior to 2.3.11 and 3.x prior to 3.0.4.
What types of vulnerabilities does CVE-2011-0446 represent?
CVE-2011-0446 represents multiple cross-site scripting (XSS) vulnerabilities.
Can CVE-2011-0446 lead to remote attacks?
Yes, CVE-2011-0446 can allow remote attackers to inject arbitrary web scripts or HTML.