Vulnerabilities > Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')

DATE CVE VULNERABILITY TITLE RISK
2020-01-21 CVE-2019-14767 Path Traversal vulnerability in Dimo-Crm Yellowbox CRM
In DIMO YellowBox CRM before 6.3.4, Path Traversal in images/Apparence (dossier=../) and servletrecuperefichier (document=../) allows an unauthenticated user to download arbitrary files from the server.
network
low complexity
dimo-crm CWE-22
7.5
2020-01-21 CVE-2019-14766 Path Traversal vulnerability in Dimo-Crm Yellowbox CRM
Path Traversal in the file browser of DIMO YellowBox CRM before 6.3.4 allows a standard authenticated user to browse the server filesystem.
network
low complexity
dimo-crm CWE-22
6.5
2020-01-17 CVE-2014-5007 Path Traversal vulnerability in Zohocorp products
Directory traversal vulnerability in the agentLogUploader servlet in ZOHO ManageEngine Desktop Central (DC) and Desktop Central Managed Service Providers (MSP) edition before 9 build 90055 allows remote attackers to write to and execute arbitrary files as SYSTEM via a ..
network
low complexity
zohocorp CWE-22
critical
9.8
2020-01-17 CVE-2019-15855 Path Traversal vulnerability in Maarch RM
An issue was discovered in Maarch RM before 2.5.
network
low complexity
maarch CWE-22
critical
9.1
2020-01-15 CVE-2015-6591 Path Traversal vulnerability in Freereprintables Articlefr 3.0.4/3.0.6/3.0.7
Directory traversal vulnerability in application/templates/amelia/loadjs.php in Free Reprintables ArticleFR 3.0.7 and earlier allows local users to read arbitrary files via the s parameter.
local
low complexity
freereprintables CWE-22
5.5
2020-01-15 CVE-2015-5952 Path Traversal vulnerability in Thomsonreuters Fatca
Directory traversal vulnerability in Thomson Reuters for FATCA before 5.2 allows remote attackers to execute arbitrary files via the item parameter.
network
low complexity
thomsonreuters CWE-22
critical
9.8
2020-01-15 CVE-2020-1606 Path Traversal vulnerability in Juniper Junos
A path traversal vulnerability in the Juniper Networks Junos OS device may allow an authenticated J-web user to read files with 'world' readable permission and delete files with 'world' writeable permission.
network
low complexity
juniper CWE-22
8.1
2020-01-14 CVE-2015-3151 Path Traversal vulnerability in Redhat Automatic BUG Reporting Tool
Directory traversal vulnerability in abrt-dbus in Automatic Bug Reporting Tool (ABRT) allows local users to read, write to, or change ownership of arbitrary files via unspecified vectors to the (1) NewProblem, (2) GetInfo, (3) SetElement, or (4) DeleteElement method.
local
low complexity
redhat CWE-22
7.8
2020-01-13 CVE-2013-6225 Path Traversal vulnerability in Livezilla 5.0.1.4
LiveZilla 5.0.1.4 has a Remote Code Execution vulnerability
network
low complexity
livezilla CWE-22
critical
9.8
2020-01-06 CVE-2020-5513 Path Traversal vulnerability in Gilacms Gila CMS 1.11.8
Gila CMS 1.11.8 allows /cm/delete?t=../ Directory Traversal.
network
low complexity
gilacms CWE-22
6.8