Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2012-6497

20
FAUCET Score

CVE-2012-6497 describes a SQL injection vulnerability in the Authlogic gem for Ruby on Rails, affecting versions prior to 3.2.10. This flaw arises from potentially unsafe find_by_id method calls, enabling remote attackers to inject malicious SQL queries if a known secret_token value is present. The vulnerability has a CVSS score of 5.0, indicating a medium severity with low attack complexity and no authentication required, potentially leading to partial confidentiality impact. There is no evidence of active exploitation, nor are there readily available exploit modules in Metasploit or Nuclei; however, it has garnered some community discussion and media coverage.

Impacted Technologies

VendorProductVersion(s)CPE
< 3.2.10CPE matchmatch criteria
cpe:2.3:a:rubyonrails:rails:*:*:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 2.0

5.0MEDIUM

AV:N/AC:L/Au:N/C:P/I:N/A:N

Confidentiality Impact
PARTIAL
Integrity Impact
NONE
Availability Impact
NONE
Access Vector
NETWORK
Access Complexity
LOW
Authentication
NONE
Exploitability Score
10.0
Impact Score
2.9
CvssVersion
2.0

Exploit Intelligence

EPSS Score
2.74%
Probability of exploitation in next 30 days
EPSS Percentile
84.6%
Percentile rank of EPSS score among Peer Group
As of 2026-07-27
Model: v2026.06.15
This CVE's current EPSS score of 0.0274 is in the 78th percentile among its peer group of 23,703 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.4 GitHub mentions.

Media Mentions

The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (1)

rubygemspatch availablevia ghsa
Product: authlogicFixed in: 3.3.0

Vendor Advisories (1)

rubygemsGHSA-rx7j-mw4c-76g9medium

Authlogic Information Exposure vulnerability

May 14, 2022

References

blog.phusion.nl / 2013/01/03/rails-sql-injection-vulnerability-hold-your-horses-here-are-the-facts
Exploit
openwall.com / lists/oss-security/2013/01/03/12
Mailing ListThird Party Advisory
phenoelit.org / blog/archives/2012/12/21/let_me_github_that_for_you/index.html
Broken LinkExploit
securityfocus.com / bid/57084
Broken LinkThird Party AdvisoryVDB Entry