cbcvebase.
CVE-2013-4413
published 2014-03-11

CVE-2013-4413: Directory traversal vulnerability in controller/concerns/render_redirect.rb in the Wicked gem before 1.0.1 for Ruby allows remote attackers to read arbitrary…

PriorityP431medium5CVSS 2.0
AVNACLAuNCPINAN
EPSS
2.96%
85.7th percentile
Directory traversal vulnerability in controller/concerns/render_redirect.rb in the Wicked gem before 1.0.1 for Ruby allows remote attackers to read arbitrary files via a %2E%2E%2F (encoded dot dot slash) in the step.

Affected

21 ranges
VendorProductVersion rangeFixed in
opensusewicked>= 0 < 1.0.11.0.1
schneemswicked<= 1.0.0
schneemswicked
schneemswicked
schneemswicked
schneemswicked
schneemswicked
schneemswicked
schneemswicked
schneemswicked
schneemswicked
schneemswicked
schneemswicked
schneemswicked
schneemswicked
schneemswicked
schneemswicked
schneemswicked
schneemswicked
schneemswicked
schneemswicked
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.