Ruby On Rails is vulnerable to local file inclusion caused by secondary decoding in Sprockets 3.7.1 and lower versions. An attacker can use %252e%252e/ to access the root directory and read or execute any file on the target server.
id: CVE-2018-3760
info:
name: Ruby On Rails - Local File Inclusion
author: 0xrudra,pikpikcu
s
...