Security Advisory
CVE-2010-3933
CVE vulnerability detail — eXtreme Datacenter Security Operations
Description
Ruby on Rails 2.3.9 and 3.0.0 does not properly handle nested attributes, which allows remote attackers to modify arbitrary records by changing the names of parameters for form inputs.