rubygeocoder records
1 published records for vendor rubygeocoder.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 0 · 0%
- Pre-auth RCE
- 0
- With a fix record
- 100%
- Median publish → KEV
- No record has entered KEV
Attack profile
All records
1 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
39Monitor | CVE-2020-7981No exploit | sql.rb in Geocoder before 1.6.1 allows Boolean-based SQL injection when within_bounding_box is used in conjunction with untrusted sw_lat, swrubygeocoder · geocoder · CWE-89 | Critical9.8 | — | 1.5% | Jan 25, 2020 |
- CVE-2020-798139Monitor
sql.rb in Geocoder before 1.6.1 allows Boolean-based SQL injection when within_bounding_box is used in conjunction with untrusted sw_lat, sw
CriticalCVSS 9.8No exploitEPSS 1%rubygeocoder · geocoderJan 25, 2020