Vulnerabilities (CVE)

Filtered by CWE-22
Total 6658 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2020-8641 1 Lotus Core Cms Project 1 Lotus Core Cms 2020-02-07 6.5 MEDIUM 8.8 HIGH
Lotus Core CMS 1.0.1 allows authenticated Local File Inclusion of .php files via directory traversal in the index.php page_slug parameter.
CVE-2020-7966 1 Gitlab 1 Gitlab 2020-02-07 5.0 MEDIUM 7.5 HIGH
GitLab EE 11.11 and later through 12.7.2 allows Directory Traversal.
CVE-2014-5236 1 Open-xchange 1 Open-xchange Appsuite 2020-02-06 5.0 MEDIUM 7.5 HIGH
Multiple absolute path traversal vulnerabilities in documentconverter in Open-Xchange (OX) AppSuite before 7.4.2-rev10 and 7.6.x before 7.6.0-rev10 allow remote attackers to read application files via a full pathname in a crafted (1) OLE Object or (2) image in an OpenDocument text file.
CVE-2020-8009 1 Motu 21 112d, 1248, 16a and 18 more 2020-02-06 5.0 MEDIUM 7.5 HIGH
AVB MOTU devices through 2020-01-22 allow /.. Directory Traversal, as demonstrated by reading the /etc/passwd file.
CVE-2019-4674 1 Ibm 1 Security Identity Manager 2020-02-06 4.0 MEDIUM 4.9 MEDIUM
IBM Security Identity Manager 7.0.1 could allow a remote attacker to traverse directories on the system. An attacker could send a specially-crafted URL request containing "dot dot" sequences (/../) to view arbitrary files on the system. IBM X-Force ID: 171510.
CVE-2020-8545 1 Circl 1 Ail Framework 2020-02-06 5.0 MEDIUM 7.5 HIGH
Global.py in AIL framework 2.8 allows path traversal.
CVE-2014-8799 1 Dukapress 1 Dukapress 2020-02-05 5.0 MEDIUM N/A
Directory traversal vulnerability in the dp_img_resize function in php/dp-functions.php in the DukaPress plugin before 2.5.4 for WordPress allows remote attackers to read arbitrary files via a .. (dot dot) in the src parameter to lib/dp_image.php.
CVE-2018-16836 1 Rubedo Project 1 Rubedo 2020-02-05 7.5 HIGH 9.8 CRITICAL
Rubedo through 3.4.0 contains a Directory Traversal vulnerability in the theme component, allowing unauthenticated attackers to read and execute arbitrary files outside of the service root path, as demonstrated by a /theme/default/img/%2e%2e/..//etc/passwd URI.
CVE-2013-6785 1 Supermicro 1 Intelligent Platform Management Interface 2020-02-04 4.0 MEDIUM 4.3 MEDIUM
Directory traversal vulnerability in url_redirect.cgi in Supermicro IPMI before SMT_X9_315 allows authenticated attackers to read arbitrary files via the url_name parameter.
CVE-2012-6609 1 Polycom 3 Hdx 8000, Hdx Video End Points, Uc Apl 2020-02-04 5.0 MEDIUM 7.5 HIGH
Directory traversal vulnerability in a_getlog.cgi in Polycom HDX Video End Points before 3.0.4 and UC APL before 2.7.1.J allows remote attackers to read arbitrary files via a .. (dot dot) in the name parameter.
CVE-2013-4861 1 Micasaverde 2 Veralite, Veralite Firmware 2020-02-04 4.0 MEDIUM 6.5 MEDIUM
Directory traversal vulnerability in cgi-bin/cmh/get_file.sh in MiCasaVerde VeraLite with firmware 1.5.408 allows remote authenticated users to read arbirary files via a .. (dot dot) in the filename parameter.
CVE-2020-3717 1 Magento 1 Magento 2020-01-30 5.0 MEDIUM 5.3 MEDIUM
Magento versions 2.3.3 and earlier, 2.2.10 and earlier, 1.14.4.3 and earlier, and 1.9.4.3 and earlier have a path traversal vulnerability. Successful exploitation could lead to sensitive information disclosure.
CVE-2014-1923 1 Koha 1 Koha 2020-01-30 5.0 MEDIUM 7.5 HIGH
Multiple directory traversal vulnerabilities in the (1) staff interface help editor (edithelp.pl) or (2) member-picupload.pl in Koha before 3.8.23, 3.10.x before 3.10.13, 3.12.x before 3.12.10, and 3.14.x before 3.14.3 allow remote attackers to write to arbitrary files via unspecified vectors.
CVE-2014-1922 1 Koha 1 Koha 2020-01-30 5.0 MEDIUM 7.5 HIGH
Absolute path traversal vulnerability in tools/pdfViewer.pl in Koha before 3.8.23, 3.10.x before 3.10.13, 3.12.x before 3.12.10, and 3.14.x before 3.14.3 allows remote attackers to read arbitrary files via unspecified vectors.
CVE-2020-5221 1 Troglobit 1 Uftpd 2020-01-30 6.4 MEDIUM 7.2 HIGH
In uftpd before 2.11, it is possible for an unauthenticated user to perform a directory traversal attack using multiple different FTP commands and read and write to arbitrary locations on the filesystem due to the lack of a well-written chroot jail in compose_abspath(). This has been fixed in version 2.11
CVE-2019-19893 1 Ixpdata 1 Easyinstall 2020-01-29 7.8 HIGH 7.5 HIGH
In IXP EasyInstall 6.2.13723, there is Directory Traversal on TCP port 8000 via the Engine Service by an unauthenticated attacker, who can access the server's filesystem with the access rights of NT AUTHORITY\SYSTEM.
CVE-2013-2474 1 Aws-dms 1 Aws Xms 2020-01-29 5.0 MEDIUM 7.5 HIGH
Directory traversal vulnerability in AWS XMS 2.5 allows remote attackers to view arbitrary files via the 'what' parameter.
CVE-2014-8741 1 Lexmark 1 Markvision Enterprise 2020-01-29 10.0 HIGH 9.8 CRITICAL
Directory traversal vulnerability in the GfdFileUploadServerlet servlet in Lexmark MarkVision Enterprise before 2.1 allows remote attackers to write to arbitrary files via unspecified vectors.
CVE-2014-8742 1 Lexmark 1 Markvision Enterprise 2020-01-29 7.8 HIGH 7.5 HIGH
Directory traversal vulnerability in the ReportDownloadServlet servlet in Lexmark MarkVision Enterprise before 2.1 allows remote attackers to read arbitrary files via unspecified vectors.
CVE-2013-6056 1 Alienvault 1 Open Source Security Information Management 2020-01-29 7.8 HIGH 7.5 HIGH
OSSIM before 4.3.3.1 has tele_compress.php path traversal vulnerability