Vulnerabilities > Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')

DATE CVE VULNERABILITY TITLE RISK
2020-01-27 CVE-2014-8742 Path Traversal vulnerability in Lexmark Markvision Enterprise
Directory traversal vulnerability in the ReportDownloadServlet servlet in Lexmark MarkVision Enterprise before 2.1 allows remote attackers to read arbitrary files via unspecified vectors.
network
low complexity
lexmark CWE-22
7.5
2020-01-27 CVE-2014-8741 Path Traversal vulnerability in Lexmark Markvision Enterprise
Directory traversal vulnerability in the GfdFileUploadServerlet servlet in Lexmark MarkVision Enterprise before 2.1 allows remote attackers to write to arbitrary files via unspecified vectors.
network
low complexity
lexmark CWE-22
critical
9.8
2020-01-27 CVE-2013-6056 Path Traversal vulnerability in Alienvault Open Source Security Information Management
OSSIM before 4.3.3.1 has tele_compress.php path traversal vulnerability
network
low complexity
alienvault CWE-22
7.5
2020-01-27 CVE-2020-8009 Path Traversal vulnerability in Motu AVB Firmware
AVB MOTU devices through 2020-01-22 allow /..
network
low complexity
motu CWE-22
7.5
2020-01-27 CVE-2018-12476 Path Traversal vulnerability in Suse Obs-Service-Tar SCM
Relative Path Traversal vulnerability in obs-service-tar_scm of SUSE Linux Enterprise Server 15; openSUSE Factory allows remote attackers with control over a repository to overwrite files on the machine of the local user if a malicious service is executed.
network
low complexity
suse CWE-22
7.5
2020-01-24 CVE-2013-1597 Path Traversal vulnerability in Vivotek Pt7135 Firmware 0300A/0400A
A Directory Traversal vulnerability exists in Vivotek PT7135 IP Cameras 0300a and 0400a via a specially crafted GET request, which could let a malicious user obtain user credentials.
network
low complexity
vivotek CWE-22
6.5
2020-01-24 CVE-2014-1923 Path Traversal vulnerability in Koha
Multiple directory traversal vulnerabilities in the (1) staff interface help editor (edithelp.pl) or (2) member-picupload.pl in Koha before 3.8.23, 3.10.x before 3.10.13, 3.12.x before 3.12.10, and 3.14.x before 3.14.3 allow remote attackers to write to arbitrary files via unspecified vectors.
network
low complexity
koha CWE-22
7.5
2020-01-24 CVE-2014-1922 Path Traversal vulnerability in Koha
Absolute path traversal vulnerability in tools/pdfViewer.pl in Koha before 3.8.23, 3.10.x before 3.10.13, 3.12.x before 3.12.10, and 3.14.x before 3.14.3 allows remote attackers to read arbitrary files via unspecified vectors.
network
low complexity
koha CWE-22
7.5
2020-01-23 CVE-2019-19893 Path Traversal vulnerability in Ixpdata Easyinstall 6.2.13723
In IXP EasyInstall 6.2.13723, there is Directory Traversal on TCP port 8000 via the Engine Service by an unauthenticated attacker, who can access the server's filesystem with the access rights of NT AUTHORITY\SYSTEM.
network
low complexity
ixpdata CWE-22
7.5
2020-01-23 CVE-2013-6785 Path Traversal vulnerability in Supermicro Intelligent Platform Management Interface
Directory traversal vulnerability in url_redirect.cgi in Supermicro IPMI before SMT_X9_315 allows authenticated attackers to read arbitrary files via the url_name parameter.
network
low complexity
supermicro CWE-22
4.3