{"id":"GHSA-8r6h-7x9g-xmw9","summary":"will_paginate Cross-site Scripting vulnerability","details":"Cross-site scripting (XSS) vulnerability in the will_paginate gem before 3.0.5 for Ruby allows remote attackers to inject arbitrary web script or HTML via vectors involving generated pagination links.","aliases":["CVE-2013-6459"],"modified":"2024-11-30T05:45:48.459872Z","published":"2017-10-24T18:33:36Z","database_specific":{"github_reviewed":true,"github_reviewed_at":"2020-06-16T21:26:31Z","nvd_published_at":"2013-12-31T16:04:23Z","cwe_ids":["CWE-79"],"severity":"MODERATE"},"references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2013-6459"},{"type":"WEB","url":"https://access.redhat.com/errata/RHSA-2018:0336"},{"type":"PACKAGE","url":"https://github.com/mislav/will_paginate"},{"type":"WEB","url":"https://github.com/mislav/will_paginate/releases/tag/v3.0.5"},{"type":"WEB","url":"https://web.archive.org/web/20150709163604/http://www.securityfocus.com/bid/64509"}],"affected":[{"package":{"name":"will_paginate","ecosystem":"RubyGems","purl":"pkg:gem/will_paginate"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"3.0.5"}]}],"versions":["2.1.0","2.2.0","2.2.1","2.2.2","2.3.11","2.3.12","2.3.14","2.3.15","2.3.16","2.3.17","3.0.0","3.0.1","3.0.2","3.0.3","3.0.4","3.0.pre","3.0.pre2","3.0.pre4"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2017/10/GHSA-8r6h-7x9g-xmw9/GHSA-8r6h-7x9g-xmw9.json"}}],"schema_version":"1.9.0"}