Vulnerabilities > Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')

DATE CVE VULNERABILITY TITLE RISK
2021-09-16 CVE-2021-27341 Path Traversal vulnerability in Os4Ed Opensis 7.3/7.6
OpenSIS Community Edition version <= 7.6 is affected by a local file inclusion vulnerability in DownloadWindow.php via the "filename" parameter.
network
low complexity
os4ed CWE-22
critical
9.8
2021-09-15 CVE-2021-33692 Path Traversal vulnerability in SAP Cloud Connector 2.0
SAP Cloud Connector, version - 2.0, allows the upload of zip files as backup.
network
low complexity
sap CWE-22
7.5
2021-09-15 CVE-2021-40964 Path Traversal vulnerability in Tinyfilemanager Project Tinyfilemanager 2.4.6
A Path Traversal vulnerability exists in TinyFileManager all version up to and including 2.4.6 that allows attackers to upload a file (with Admin credentials or with the CSRF vulnerability) with the "fullpath" parameter containing path traversal strings (../ and ..\) in order to escape the server's intended working directory and write malicious files onto any directory on the computer.
network
low complexity
tinyfilemanager-project CWE-22
6.5
2021-09-15 CVE-2020-19146 Path Traversal vulnerability in Jflyfox Jfinal CMS
Improper Access Control in Jfinal CMS v4.7.1 and earlier allows remote attackers to obtain sensitive information via the 'TemplatePath' parameter in the component 'jfinal_cms/admin/folder/list'.
network
low complexity
jflyfox CWE-22
6.5
2021-09-15 CVE-2020-19147 Path Traversal vulnerability in Jflyfox Jfinal CMS
Improper Access Control in Jfinal CMS v4.7.1 and earlier allows remote attackers to obtain sensitive infromation via the 'getFolder()' function in the component '/modules/filemanager/FileManager.java'.
network
low complexity
jflyfox CWE-22
6.5
2021-09-15 CVE-2020-19150 Path Traversal vulnerability in Jflyfox Jfinal CMS
Improper Access Control in Jfinal CMS v4.7.1 and earlier allows remote attackers to obtain sensitive information or cause a denial of service via the 'FileManager.delete()' function in the component 'modules/filemanager/FileManagerController.java'.
network
low complexity
jflyfox CWE-22
8.1
2021-09-15 CVE-2020-19154 Path Traversal vulnerability in Jflyfox Jfinal CMS
Improper Access Control in Jfinal CMS v4.7.1 and earlier allows remote attackers to obtain sensitive information via the 'FileManager.editFile()' function in the component 'modules/filemanager/FileManagerController.java'.
network
low complexity
jflyfox CWE-22
6.5
2021-09-14 CVE-2021-23043 Path Traversal vulnerability in F5 products
On BIG-IP, on all versions of 16.1.x, 16.0.x, 15.1.x, 14.1.x, 13.1.x, 12.1.x, and 11.6.x, a directory traversal vulnerability exists in an undisclosed page of the BIG-IP Configuration utility that allows an attacker to access arbitrary files.
network
low complexity
f5 CWE-22
6.5
2021-09-14 CVE-2021-33685 Path Traversal vulnerability in SAP Business ONE 10.0
SAP Business One version - 10.0 allows low-level authorized attacker to traverse the file system to access files or directories that are outside of the restricted directory.
network
low complexity
sap CWE-22
6.5
2021-09-14 CVE-2021-37532 Path Traversal vulnerability in SAP Business ONE 10.0
SAP Business One version - 10, due to improper input validation, allows an authenticated User to gain access to directory and view the contents of index in the directory, which would otherwise be restricted to high privileged User.
network
low complexity
sap CWE-22
4.3