Moderate severityNVD Advisory· Published Dec 31, 2013· Updated Jun 17, 2026
CVE-2013-6459
CVE-2013-6459
Description
Cross-site scripting (XSS) vulnerability in the will_paginate gem before 3.0.5 for Ruby allows remote attackers to inject arbitrary web script or HTML via vectors involving generated pagination links.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
will_paginateRubyGems | < 3.0.5 | 3.0.5 |
Affected products
6cpe:2.3:a:mislav_marohnic:will_paginate:*:-:-:*:-:ruby:*:*+ 4 more
- cpe:2.3:a:mislav_marohnic:will_paginate:*:-:-:*:-:ruby:*:*range: <=3.0.4
- cpe:2.3:a:mislav_marohnic:will_paginate:3.0.1:-:-:*:-:ruby:*:*
- cpe:2.3:a:mislav_marohnic:will_paginate:3.0.2:-:-:*:-:ruby:*:*
- cpe:2.3:a:mislav_marohnic:will_paginate:3.0.3:-:-:*:-:ruby:*:*
- cpe:2.3:a:mislav_marohnic:will_paginate:3.0:-:-:*:-:ruby:*:*
Patches
Vulnerability mechanics
References
7- github.com/mislav/will_paginate/releases/tag/v3.0.5nvdPatchVendor AdvisoryWEB
- secunia.com/advisories/56180nvdVendor Advisory
- github.com/advisories/GHSA-8r6h-7x9g-xmw9ghsaADVISORY
- nvd.nist.gov/vuln/detail/CVE-2013-6459ghsaADVISORY
- access.redhat.com/errata/RHSA-2018:0336nvdWEB
- web.archive.org/web/20150709163604/http://www.securityfocus.com/bid/64509ghsaWEB
- www.securityfocus.com/bid/64509nvd
News mentions
0No linked articles in our index yet.