CVE-2013-4413
published 2014-03-11CVE-2013-4413: Directory traversal vulnerability in controller/concerns/render_redirect.rb in the Wicked gem before 1.0.1 for Ruby allows remote attackers to read arbitrary…
PriorityP431medium5CVSS 2.0
AVNACLAuNCPINAN
EPSS
2.96%
85.7th percentile
Directory traversal vulnerability in controller/concerns/render_redirect.rb in the Wicked gem before 1.0.1 for Ruby allows remote attackers to read arbitrary files via a %2E%2E%2F (encoded dot dot slash) in the step.
Affected
21 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| opensuse | wicked | >= 0 < 1.0.1 | 1.0.1 |
| schneems | wicked | <= 1.0.0 | — |
| schneems | wicked | — | — |
| schneems | wicked | — | — |
| schneems | wicked | — | — |
| schneems | wicked | — | — |
| schneems | wicked | — | — |
| schneems | wicked | — | — |
| schneems | wicked | — | — |
| schneems | wicked | — | — |
| schneems | wicked | — | — |
| schneems | wicked | — | — |
| schneems | wicked | — | — |
| schneems | wicked | — | — |
| schneems | wicked | — | — |
| schneems | wicked | — | — |
| schneems | wicked | — | — |
| schneems | wicked | — | — |
| schneems | wicked | — | — |
| schneems | wicked | — | — |
| schneems | wicked | — | — |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
Wicked gem contains Path traversal vulnerability
ghsa·2017-10-24
CVE-2013-4413 [MEDIUM] CWE-22 Wicked gem contains Path traversal vulnerability
Wicked gem contains Path traversal vulnerability
The Wicked gem prior to v1.0.1 allows a remote attacker to traverse directories on the system via a vulnerability in `controller/concerns/render_redirect.rb`. An attacker can send a specially-crafted URL request containing `%2E%2E%2F` directory traversal sequences to read arbitrary files on the system.
OSV
Wicked gem contains Path traversal vulnerability
osv·2017-10-24
CVE-2013-4413 [MEDIUM] Wicked gem contains Path traversal vulnerability
Wicked gem contains Path traversal vulnerability
The Wicked gem prior to v1.0.1 allows a remote attacker to traverse directories on the system via a vulnerability in `controller/concerns/render_redirect.rb`. An attacker can send a specially-crafted URL request containing `%2E%2E%2F` directory traversal sequences to read arbitrary files on the system.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
http://seclists.org/oss-sec/2013/q4/43http://secunia.com/advisories/55151http://www.securityfocus.com/bid/62891https://exchange.xforce.ibmcloud.com/vulnerabilities/87783https://github.com/schneems/wicked/commit/fe31bb2533fffc9d098c69ebeb7afc3b80509f53http://seclists.org/oss-sec/2013/q4/43http://secunia.com/advisories/55151http://www.securityfocus.com/bid/62891https://exchange.xforce.ibmcloud.com/vulnerabilities/87783https://github.com/schneems/wicked/commit/fe31bb2533fffc9d098c69ebeb7afc3b80509f53
2014-03-11
Published