Hacker News new | ask | show | jobs
by danso 4905 days ago
Are you referring to the OP? The OP states:

> There are multiple weaknesses in the parameter parsing code for Ruby on Rails which allows attackers to bypass authentication systems, inject arbitrary SQL, inject and execute arbitrary code, or perform a DoS attack on a Rails application. This vulnerability has been assigned the CVE identifier CVE-2013-0156.

1 comments

I'm stating direct knowledge of the vulnerability. It's worse than SQL injection.