Alex Reisner

1 exploit Active since Jan 2020
CVE-2020-7981 WRITEUP CRITICAL WRITEUP
Geocoder < 1.6.1 - SQL Injection via within_bounding_box Coordinates
sql.rb in Geocoder before 1.6.1 allows Boolean-based SQL injection when within_bounding_box is used in conjunction with untrusted sw_lat, sw_lng, ne_lat, or ne_lng data.
CVSS 9.8