Total
6658 CVE
CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
---|---|---|---|---|---|
CVE-2014-4941 | 1 Cross-rss Plugin Project | 1 Wp-cross-rss | 2014-07-14 | 5.0 MEDIUM | N/A |
Absolute path traversal vulnerability in Cross-RSS (wp-cross-rss) plugin 1.7 for WordPress allows remote attackers to read arbitrary files via a full pathname in the rss parameter to proxy.php. | |||||
CVE-2014-2933 | 1 Caldera | 1 Caldera | 2014-07-01 | 5.0 MEDIUM | N/A |
Directory traversal vulnerability in dirmng/index.php in Caldera 9.20 allows remote attackers to access arbitrary directories via a crafted pathname. | |||||
CVE-2013-7138 | 1 Horizon Quick Content Management System Project | 1 Horizon Quick Content Management System | 2014-06-27 | 5.0 MEDIUM | N/A |
Directory traversal vulnerability in lib/functions/d-load.php in Horizon Quick Content Management System (QCMS) 4.0 and earlier allows remote attackers to read arbitrary files via a .. (dot dot) in the start parameter. | |||||
CVE-2014-2610 | 1 Hp | 1 Executive Scorecard | 2014-06-26 | 7.1 HIGH | N/A |
Directory traversal vulnerability in the Content Acceleration Pack (CAP) web application in HP Executive Scorecard 9.40 and 9.41 allows remote authenticated users to execute arbitrary code by uploading an executable file, aka ZDI-CAN-2117. | |||||
CVE-2014-3227 | 1 Debian | 1 Dpkg | 2014-06-24 | 6.4 MEDIUM | N/A |
dpkg 1.15.9, 1.16.x before 1.16.14, and 1.17.x before 1.17.9 expect the patch program to be compliant with a need for the "C-style encoded filenames" feature, but is supported in environments with noncompliant patch programs, which triggers an interaction error that allows remote attackers to conduct directory traversal attacks and modify files outside of the intended directories via a crafted source package. NOTE: this vulnerability exists because of reliance on unrealistic constraints on the behavior of an external program. | |||||
CVE-2014-4507 | 1 Theforeman | 1 Foreman | 2014-06-23 | 6.4 MEDIUM | N/A |
Directory traversal vulnerability in Smart-Proxy in Foreman before 1.4.5 and 1.5.x before 1.5.1 allows remote attackers to overwrite arbitrary files via a .. (dot dot) in the dst parameter to tftp/fetch_boot_file. | |||||
CVE-2014-4306 | 1 Webtitan | 1 Webtitan | 2014-06-19 | 5.0 MEDIUM | N/A |
Directory traversal vulnerability in logs-x.php in WebTitan before 4.04 allows remote attackers to read arbitrary files via a .. (dot dot) in the logfile parameter in a download action. | |||||
CVE-2012-3521 | 1 Qbnz | 1 Geshi | 2014-06-13 | 5.0 MEDIUM | N/A |
Multiple directory traversal vulnerabilities in the cssgen contrib module in GeSHi before 1.0.8.11 allow remote attackers to read arbitrary files via a .. (dot dot) in the (1) geshi-path or (2) geshi-lang-path parameter. | |||||
CVE-2013-3739 | 1 Network-weathermap | 1 .network Weathermap | 2014-06-06 | 5.0 MEDIUM | N/A |
Directory traversal vulnerability in editor.php in Network Weathermap 0.97c and earlier allows remote attackers to read arbitrary files via a .. (dot dot) in the mapname parameter in a show_config action. | |||||
CVE-2014-3975 | 1 Auracms | 1 Auracms | 2014-06-06 | 5.0 MEDIUM | N/A |
Absolute path traversal vulnerability in filemanager.php in AuraCMS 3.0 allows remote attackers to list a directory via a full pathname in the viewdir parameter. | |||||
CVE-2014-2352 | 1 Cogentdatahub | 1 Cogent Datahub | 2014-06-05 | 6.4 MEDIUM | N/A |
Directory traversal vulnerability in Cogent DataHub before 7.3.5 allows remote attackers to read arbitrary files of unspecified types, or cause a web-server denial of service, via a crafted pathname. | |||||
CVE-2014-3127 | 1 Debian | 1 Dpkg | 2014-06-05 | 7.1 HIGH | N/A |
dpkg 1.15.9 on Debian squeeze introduces support for the "C-style encoded filenames" feature without recognizing that the squeeze patch program lacks this feature, which triggers an interaction error that allows remote attackers to conduct directory traversal attacks and modify files outside of the intended directories via a crafted source package. NOTE: this can be considered a release engineering problem in the effort to fix CVE-2014-0471. | |||||
CVE-2014-2976 | 1 Sixnet | 1 Sixview Manager | 2014-05-16 | 5.0 MEDIUM | N/A |
Directory traversal vulnerability in Sixnet SixView Manager 2.4.1 allows remote attackers to read arbitrary files via a .. (dot dot) in an HTTP GET request to TCP port 18081. | |||||
CVE-2013-5655 | 1 Xiaowen Huang | 1 Yingzhi Python Programming Language | 2014-05-15 | 6.4 MEDIUM | N/A |
Directory traversal vulnerability in the FTP server in YingZhi Python Programming Language for iOS 1.9 allows remote attackers to read and possibly write arbitrary files via a .. (dot dot) in the default URI. | |||||
CVE-2013-3514 | 1 Openx | 1 Openx | 2014-05-15 | 4.3 MEDIUM | N/A |
Multiple directory traversal vulnerabilities in OpenX before 2.8.10 revision 82710 allow remote administrators to read arbitrary files via a .. (dot dot) in the group parameter to (1) plugin-preferences.php or (2) plugin-settings.php in www/admin, a different vulnerability than CVE-2013-7376. NOTE: this can be leveraged using CSRF to allow remote unauthenticated attackers to read arbitrary files. | |||||
CVE-2013-5984 | 1 Microweber | 1 Microweber | 2014-05-13 | 6.4 MEDIUM | N/A |
Directory traversal vulnerability in userfiles/modules/admin/backup/delete.php in Microweber before 0.830 allows remote attackers to delete arbitrary files via a .. (dot dot) in the file parameter. | |||||
CVE-2014-1442 | 1 Coreftp | 1 Core Ftp | 2014-05-02 | 4.0 MEDIUM | N/A |
Directory traversal vulnerability in Core FTP Server 1.2 before build 515 allows remote authenticated users to determine the existence of arbitrary files via a /../ sequence in an XCRC command. | |||||
CVE-2013-1806 | 1 Php-fusion | 1 Php-fusion | 2014-05-01 | 6.5 MEDIUM | N/A |
Multiple directory traversal vulnerabilities in PHP-Fusion before 7.02.06 allow remote authenticated users to include and execute arbitrary files via a .. (dot dot) in the (1) user_theme parameter to maincore.php; or remote authenticated administrators to delete arbitrary files via the (2) enable parameter to administration/user_fields.php or (3) file parameter to administration/db_backup.php. | |||||
CVE-2014-1974 | 1 Lyesoft | 1 Andexplorer | 2014-04-24 | 6.4 MEDIUM | N/A |
Directory traversal vulnerability in the LYSESOFT AndExplorer application before 20140403 and AndExplorerPro application before 20140405 for Android allows attackers to overwrite or create arbitrary files via unspecified vectors. | |||||
CVE-2014-2864 | 1 Paperthin | 1 Commonspot Content Server | 2014-04-16 | 10.0 HIGH | N/A |
Multiple directory traversal vulnerabilities in PaperThin CommonSpot before 7.0.2 and 8.x before 8.0.3 allow remote attackers to have an unspecified impact via a filename parameter containing directory traversal sequences. |