CVE-2014-0130

Ruby on Rails Directory Traversal Vulnerability

Description

Directory traversal vulnerability in actionpack/lib/abstract_controller/base.rb in the implicit-render implementation in Ruby on Rails allows remote attackers to read arbitrary files via a crafted request.

Severity: HIGH

CVSS Score: 7.5

Vendor: Rails

Product: Ruby on Rails

Loading CVE details...