Total
6658 CVE
CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
---|---|---|---|---|---|
CVE-2015-4704 | 1 Download Zip Attachments Project | 1 Download Zip Attachments | 2017-05-31 | 5.0 MEDIUM | 7.5 HIGH |
Directory traversal vulnerability in the Download Zip Attachments plugin 1.0 for WordPress allows remote attackers to read arbitrary files via a .. (dot dot) in the File parameter to download.php. | |||||
CVE-2017-8921 | 1 Flightgear | 1 Flightgear | 2017-05-26 | 5.0 MEDIUM | 7.5 HIGH |
In FlightGear before 2017.2.1, the FGCommand interface allows overwriting any file the user has write access to, but not with arbitrary data: only with the contents of a FlightGear flightplan (XML). A resource such as a malicious third-party aircraft could exploit this to damage files belonging to the user. Both this issue and CVE-2016-9956 are directory traversal vulnerabilities in Autopilot/route_mgr.cxx - this one exists because of an incomplete fix for CVE-2016-9956. | |||||
CVE-2017-9030 | 1 Codextrous | 1 B2j Contact | 2017-05-26 | 5.0 MEDIUM | 7.5 HIGH |
The Codextrous B2J Contact (aka b2j_contact) extension before 2.1.13 for Joomla! allows a directory traversal attack that bypasses a uniqid protection mechanism, and makes it easier to read arbitrary uploaded files. | |||||
CVE-2016-7982 | 1 Spip | 1 Spip | 2017-05-24 | 5.0 MEDIUM | 7.5 HIGH |
Directory traversal vulnerability in ecrire/exec/valider_xml.php in SPIP 3.1.2 and earlier allows remote attackers to enumerate the files on the system via the var_url parameter in a valider_xml action. | |||||
CVE-2017-2163 | 1 N-i-agroinformatics | 1 Soy Cms | 2017-05-23 | 5.0 MEDIUM | 7.5 HIGH |
Directory traversal vulnerability in SOY CMS Ver.1.8.1 to Ver.1.8.12 allows authenticated attackers to read arbitrary files via shop_id. | |||||
CVE-2017-8868 | 1 Flatcore | 1 Flatcore-cms | 2017-05-17 | 5.0 MEDIUM | 7.5 HIGH |
acp/core/files.browser.php in flatCore 1.4.7 allows file deletion via directory traversal in the delete parameter to acp/acp.php. The risk might be limited to requests submitted through CSRF. | |||||
CVE-2016-10367 | 1 Opsview | 1 Opsview | 2017-05-17 | 5.0 MEDIUM | 7.5 HIGH |
In Opsview Monitor Pro (Prior to 5.1.0.162300841, prior to 5.0.2.27475, prior to 4.6.4.162391051, and 4.5.x without a certain 2016 security patch), an unauthenticated Directory Traversal vulnerability can be exploited by issuing a specially crafted HTTP GET request utilizing a simple URL encoding bypass, %252f instead of /. | |||||
CVE-2017-8853 | 1 Fiyo | 1 Fiyo Cms | 2017-05-17 | 6.4 MEDIUM | 7.5 HIGH |
Fiyo CMS v2.0.7 has an arbitrary file delete vulnerability in dapur/apps/app_config/controller/backuper.php via directory traversal in the file parameter during an act=db action. | |||||
CVE-2016-7843 | 1 Hibara Software | 3 Attachecase For Java, Attachecase Lite, Attachecase Pro | 2017-05-10 | 4.3 MEDIUM | 5.5 MEDIUM |
Directory traversal vulnerability in AttacheCase for Java 0.60 and earlier, AttacheCase Lite 1.4.6 and earlier, and AttacheCase Pro 1.5.7 and earlier allows remote attackers to read arbitrary files via specially crafted ATC file. | |||||
CVE-2017-8283 | 1 Debian | 1 Dpkg | 2017-05-10 | 7.5 HIGH | 9.8 CRITICAL |
dpkg-source in dpkg 1.3.0 through 1.18.23 is able to use a non-GNU patch program and does not offer a protection mechanism for blank-indented diff hunks, which allows remote attackers to conduct directory traversal attacks via a crafted Debian source package, as demonstrated by use of dpkg-source on NetBSD. | |||||
CVE-2016-8593 | 1 Trendmicro | 1 Threat Discovery Appliance | 2017-05-10 | 6.5 MEDIUM | 8.8 HIGH |
Directory traversal vulnerability in upload.cgi in Trend Micro Threat Discovery Appliance 2.6.1062r1 and earlier allows remote authenticated users to execute arbitrary code via a .. (dot dot) in the dID parameter. | |||||
CVE-2017-8297 | 1 Simple-file-manager Project | 1 Simple-file-manager | 2017-05-10 | 7.5 HIGH | 9.8 CRITICAL |
A path traversal vulnerability exists in simple-file-manager before 2017-04-26, affecting index.php (the sole "Simple PHP File Manager" component). | |||||
CVE-2016-7842 | 1 Hibara | 1 Attachecase | 2017-05-10 | 4.3 MEDIUM | 5.5 MEDIUM |
Directory traversal vulnerability in AttacheCase 2.8.2.8 and earlier and 3.2.0.4 and earlier allows remote attackers to read arbitrary files via specially crafted ATC file. | |||||
CVE-2017-8115 | 1 Modx | 1 Modx Revolution | 2017-05-05 | 5.0 MEDIUM | 5.3 MEDIUM |
Directory traversal in setup/processors/url_search.php (aka the search page of an unused processor) in MODX Revolution 2.5.7 might allow remote attackers to obtain system directory information. | |||||
CVE-2017-2150 | 1 Booking Calendar Project | 1 Booking Calendar | 2017-05-05 | 5.0 MEDIUM | 5.3 MEDIUM |
Directory traversal vulnerability in Booking Calendar version 7.0 and earlier allows remote attackers to read arbitrary files via specially crafted captcha_chalange parameter. | |||||
CVE-2017-2117 | 1 Cubecart | 1 Cubecart | 2017-05-05 | 4.0 MEDIUM | 4.9 MEDIUM |
Directory traversal vulnerability in CubeCart versions prior to 6.1.5 allows attacker with administrator rights to read arbitrary files via unspecified vectors. | |||||
CVE-2017-2090 | 1 Cubecart | 1 Cubecart | 2017-05-05 | 4.0 MEDIUM | 6.5 MEDIUM |
Directory traversal vulnerability in CubeCart versions prior to 6.1.4 allows remote authenticated attackers to read arbitrary files via unspecified vectors. | |||||
CVE-2017-2098 | 1 Cubecart | 1 Cubecart | 2017-05-05 | 4.0 MEDIUM | 6.5 MEDIUM |
Directory traversal vulnerability in CubeCart versions prior to 6.1.4 allows remote authenticated attackers to read arbitrary files via unspecified vectors. | |||||
CVE-2017-2119 | 1 Wbce | 1 Wbce Cms | 2017-05-03 | 5.0 MEDIUM | 8.6 HIGH |
Directory traversal vulnerability in WBCE CMS 1.1.10 and earlier allows remote attackers to read arbitrary files via unspecified vectors. | |||||
CVE-2015-0107 | 1 Ibm | 11 Change And Configuration Management Database, Maximo Asset Management, Maximo Asset Management Essentials and 8 more | 2017-04-27 | 4.0 MEDIUM | 6.5 MEDIUM |
IBM Tivoli IT Asset Management for IT, Tivoli Service Request Manager, and Change and Configuration Management Database 7.1 through 7.1.1.8 and 7.2 and Maximo Asset Management and Maximo Industry Solutions 7.1 through 7.1.1.8, 7.5 before 7.5.0.7 IFIX003, and 7.6 before 7.6.0.0 IFIX002 allow remote authenticated users to conduct directory traversal attacks via unspecified vectors. |