GHSA-rprj-g6xc-p5gq
MODERATECVE-2013-4413The Wicked gem prior to v1.0.1 allows a remote attacker to traverse directories on the system via a vulnerability in controller/concerns/renderredirect.rb. An attacker can send a specially-crafted URL request containing %2E%2E%2F directory traversal sequences to read arbitrary files on the system.
- Affected
- < 1.0.1
- Fixed in
- 1.0.1
- Weakness
- CWE-22
- Published
- 2017-10-24
- Source
- github