CVE-2013-0333 | Ruby on Rails up to 3.0 yaml.rb convert_json_to_yaml sql injection (VU#628463 / EDB-24434)
A vulnerability was found in Ruby on Rails up to 3.0. It has been declared as very critical. This vulnerability affects the function convert_json_to_yaml in the library lib/active_support/json/backends/yaml.rb. The manipulation leads to sql injection.
This vulnerability was named CVE-2013-0333. The attack can be initiated remotely. Furthermore, there is an exploit available.
It is recommended to upgrade the affected component.