Vulnerabilities > Files or Directories Accessible to External Parties

DATE CVE VULNERABILITY TITLE RISK
2020-05-11 CVE-2020-12743 Files or Directories Accessible to External Parties vulnerability in Gazie Project Gazie
An issue was discovered in Gazie 7.32.
network
low complexity
gazie-project CWE-552
7.5
2020-04-29 CVE-2020-12470 Files or Directories Accessible to External Parties vulnerability in Mono Monox 5.1.40.5152
MonoX through 5.1.40.5152 allows administrators to execute arbitrary code by modifying an ASPX template.
network
low complexity
mono CWE-552
6.5
2020-04-10 CVE-2019-7305 Files or Directories Accessible to External Parties vulnerability in Extplorer 2.0.0/2.1.0
Information Exposure vulnerability in eXtplorer makes the /usr/ and /etc/extplorer/ system directories world-accessible over HTTP.
network
low complexity
extplorer CWE-552
7.5
2020-04-01 CVE-2020-11469 Files or Directories Accessible to External Parties vulnerability in Zoom Meetings 4.6.8
Zoom Client for Meetings through 4.6.8 on macOS copies runwithroot to a user-writable temporary directory during installation, which allows a local process (with the user's privileges) to obtain root access by replacing runwithroot.
local
low complexity
zoom CWE-552
7.2
2020-03-30 CVE-2020-5289 Files or Directories Accessible to External Parties vulnerability in Elide
In Elide before 4.5.14, it is possible for an adversary to "guess and check" the value of a model field they do not have access to assuming they can read at least one other field in the model.
network
low complexity
elide CWE-552
4.0
2020-03-05 CVE-2020-5250 Files or Directories Accessible to External Parties vulnerability in Prestashop
In PrestaShop before version 1.7.6.4, when a customer edits their address, they can freely change the id_address in the form, and thus steal someone else's address.
4.9
2020-02-17 CVE-2015-4715 Files or Directories Accessible to External Parties vulnerability in Owncloud
The fetch function in OAuth/Curl.php in Dropbox-PHP, as used in ownCloud Server before 6.0.8, 7.x before 7.0.6, and 8.x before 8.0.4 when an external Dropbox storage has been mounted, allows remote administrators of Dropbox.com to read arbitrary files via an @ (at sign) character in unspecified POST values.
network
low complexity
owncloud CWE-552
4.0
2020-02-11 CVE-2020-1726 Files or Directories Accessible to External Parties vulnerability in multiple products
A flaw was discovered in Podman where it incorrectly allows containers when created to overwrite existing files in volumes, even if they are mounted as read-only.
network
high complexity
libpod-project redhat CWE-552
5.9
2020-02-11 CVE-2019-13941 Files or Directories Accessible to External Parties vulnerability in Siemens Ozw672 Firmware and Ozw772 Firmware
A vulnerability has been identified in OZW672 (All versions < V10.00), OZW772 (All versions < V10.00).
network
low complexity
siemens CWE-552
5.0
2020-02-03 CVE-2020-3927 Files or Directories Accessible to External Parties vulnerability in Changingtec Servisign 1.0.19.0617
An arbitrary-file-access vulnerability exists in ServiSign security plugin, as long as the attackers learn the specific API function, they may access arbitrary files on target system via crafted API parameter.
network
low complexity
changingtec CWE-552
8.5