Description
Cross-site scripting (XSS) vulnerability in actionpack/lib/action_view/helpers/translation_helper.rb in the internationalization component in Ruby on Rails 3.x before 3.2.16 and 4.x before 4.0.2 allows remote attackers to inject arbitrary web script or HTML via a crafted string that triggers generation of a fallback string by the i18n gem.
Remediation
References
Related Vulnerabilities
WordPress 4.1.x Multiple Vulnerabilities (4.1 - 4.1.18)
MySQL CVE-2013-0371 Vulnerability (CVE-2013-0371)
Oracle Application Server Other Vulnerability (CVE-2007-3861)
Django Improper Authentication Vulnerability (CVE-2013-1443)
WordPress Plugin Quiz Maker Multiple SQL Injection Vulnerabilities (6.2.0.8)