Total
6174 CVE
CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
---|---|---|---|---|---|
CVE-2002-2233 | 1 Mollensoft Software | 1 Enceladus Server Suite | 2017-07-29 | 8.3 HIGH | N/A |
Directory traversal vulnerability in Enceladus Server Suite 3.9 allows remote attackers to list arbitrary directories and possibly cause a denial of service via "@" (at) characters in a CD (CWD) command, such as (1) "@/....\", (2) "@@@/..c:\", or (3) "@/..@/..". | |||||
CVE-2017-2240 | 2 Apple, Hammock | 2 Mac Os X, Assetview | 2017-07-28 | 4.0 MEDIUM | 6.5 MEDIUM |
Directory traversal vulnerability in AssetView for MacOS Ver.9.2.0 and earlier versions allows remote attackers to read arbitrary files via "File Transfer Web Service". | |||||
CVE-2017-1000002 | 1 Atutor | 1 Atutor | 2017-07-27 | 7.5 HIGH | 9.8 CRITICAL |
ATutor versions 2.2.1 and earlier are vulnerable to a directory traversal and file extension check bypass in the Course component resulting in code execution. ATutor versions 2.2.1 and earlier are vulnerable to a directory traversal vulnerability in the Course Icon component resulting in information disclosure. | |||||
CVE-2016-10106 | 1 Netgear | 8 Fvs318gv2, Fvs318gv2 Firmware, Fvs318n and 5 more | 2017-07-27 | 4.0 MEDIUM | 6.5 MEDIUM |
Directory traversal vulnerability in scgi-bin/platform.cgi on NETGEAR FVS336Gv3, FVS318N, FVS318Gv2, and SRX5308 devices with firmware before 4.3.3-8 allows remote authenticated users to read arbitrary files via a .. (dot dot) in the thispage parameter, as demonstrated by reading the /etc/shadow file. | |||||
CVE-2016-10400 | 1 Atutor | 1 Atutor | 2017-07-26 | 5.0 MEDIUM | 7.5 HIGH |
Directory Traversal exists in ATutor before 2.2.2 via the icon parameter to /mods/_core/courses/users/create_course.php. The attacker can read an arbitrary file by visiting get_course_icon.php?id= after the traversal attack. | |||||
CVE-2017-11456 | 1 Geneko | 8 Gwr202 Gprs Router, Gwr202 Gprs Router Firmware, Gwr252 Edge Router and 5 more | 2017-07-25 | 5.0 MEDIUM | 7.5 HIGH |
Geneko GWR routers allow directory traversal sequences starting with a /../ substring, as demonstrated by unauthenticated read access to the configuration file. | |||||
CVE-2017-11469 | 1 Idera | 1 Uptime Infrastructure Monitor | 2017-07-24 | 5.0 MEDIUM | 7.5 HIGH |
get2post.php in IDERA Uptime Monitor 7.8 has directory traversal in the file_name parameter. | |||||
CVE-2017-11440 | 1 Sitecore | 1 Cms | 2017-07-21 | 4.0 MEDIUM | 4.9 MEDIUM |
In Sitecore 8.2, there is absolute path traversal via the shell/Applications/Layouts/IDE.aspx fi parameter and the admin/LinqScratchPad.aspx Reference parameter. | |||||
CVE-2006-5981 | 1 Biba Software | 1 Seleniumserver Ftp Server | 2017-07-20 | 6.4 MEDIUM | N/A |
Multiple directory traversal vulnerabilities in SeleniumServer FTP Server 1.0, and possibly earlier, allow remote attackers to list arbitrary directories, read arbitrary files, and upload arbitrary files via directory traversal sequences in the (1) DIR (LIST or NLST), (2) GET (RETR), and (3) PUT (STOR) commands. | |||||
CVE-2006-5846 | 1 Freewebshop | 1 Freewebshop | 2017-07-20 | 6.4 MEDIUM | N/A |
Directory traversal vulnerability in index.php in FreeWebshop 2.2.2 and earlier allows remote attackers to read and include arbitrary files via a .. (dot dot) in the page parameter, a different vector than CVE-2006-5773. | |||||
CVE-2006-5031 | 1 Cakefoundation | 1 Cakephp | 2017-07-20 | 5.0 MEDIUM | N/A |
Directory traversal vulnerability in app/webroot/js/vendors.php in Cake Software Foundation CakePHP before 1.1.8.3544 allows remote attackers to read arbitrary files via a .. (dot dot) in the file parameter, followed by a filename ending with "%00" and a .js filename. | |||||
CVE-2006-4013 | 1 Symantec | 1 Brightmail Antispam | 2017-07-20 | 7.6 HIGH | N/A |
Multiple directory traversal vulnerabilities in Symantec Brightmail AntiSpam (SBAS) before 6.0.4, when the Control Center is allowed to connect from any computer, allow remote attackers to read and overwrite certain files via directory traversal sequences in (1) DATABLOB-GET and (2) DATABLOB-SAVE requests. | |||||
CVE-2006-1746 | 1 Tincan | 1 Phplist | 2017-07-20 | 5.0 MEDIUM | N/A |
Directory traversal vulnerability in PHPList 2.10.2 and earlier allows remote attackers to include arbitrary local files via the (1) GLOBALS[database_module] or (2) GLOBALS[language_module] parameters, which overwrite the underlying $GLOBALS variable. | |||||
CVE-2006-1095 | 1 Apache | 1 Mod Python | 2017-07-20 | 7.2 HIGH | N/A |
Directory traversal vulnerability in the FileSession object in Mod_python module 3.2.7 for Apache allows local users to execute arbitrary code via a crafted session cookie. | |||||
CVE-2006-0223 | 1 Topcmm Computing | 1 123 Flash Chat Server | 2017-07-20 | 5.0 MEDIUM | N/A |
Directory traversal vulnerability in Shanghai TopCMM 123 Flash Chat Server Software 5.1 allows attackers to create or overwrite arbitrary files on the server via ".." (dot dot) sequences in the username field. | |||||
CVE-2017-1000062 | 1 Kitto Project | 1 Kitto | 2017-07-19 | 5.0 MEDIUM | 7.5 HIGH |
kittoframework kitto 0.5.1 is vulnerable to directory traversal in the router resulting in remote code execution | |||||
CVE-2017-8003 | 1 Emc | 1 Data Protection Advisor | 2017-07-17 | 6.8 MEDIUM | 4.9 MEDIUM |
EMC Data Protection Advisor prior to 6.4 contains a path traversal vulnerability. A remote authenticated high privileged user may potentially exploit this vulnerability to access unauthorized information from the underlying OS server by supplying specially crafted strings in input parameters of the application. | |||||
CVE-2015-1579 | 1 Elegant Themes | 1 Divi | 2017-07-17 | 5.0 MEDIUM | N/A |
Directory traversal vulnerability in the Elegant Themes Divi theme for WordPress allows remote attackers to read arbitrary files via a .. (dot dot) in the img parameter in a revslider_show_image action to wp-admin/admin-ajax.php. NOTE: this vulnerability may be a duplicate of CVE-2014-9734. | |||||
CVE-2017-10974 | 1 Yaws | 1 Yaws | 2017-07-14 | 5.0 MEDIUM | 7.5 HIGH |
Yaws 1.91 allows Unauthenticated Remote File Disclosure via HTTP Directory Traversal with /%5C../ to port 8080. NOTE: this CVE is only about use of an initial /%5C sequence to defeat traversal protection mechanisms; the initial /%5C sequence was apparently not discussed in earlier research on this product. | |||||
CVE-2015-3297 | 1 Etherpad | 1 Etherpad | 2017-07-14 | 5.0 MEDIUM | 7.5 HIGH |
Directory traversal vulnerability in node/utils/Minify.js in Etherpad 1.1.1 through 1.5.2 allows remote attackers to read arbitrary files by leveraging replacement of backslashes with slashes in the path parameter of HTTP API requests. |