Vulnerabilities > Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')

DATE CVE VULNERABILITY TITLE RISK
2019-06-11 CVE-2019-12144 Path Traversal vulnerability in Ipswitch WS FTP Server
An issue was discovered in SSHServerAPI.dll in Progress ipswitch WS_FTP Server 2018 before 8.6.1.
network
low complexity
ipswitch CWE-22
critical
9.8
2019-06-11 CVE-2019-12143 Path Traversal vulnerability in Progress WS FTP Server
A Directory Traversal issue was discovered in SSHServerAPI.dll in Progress ipswitch WS_FTP Server 2018 before 8.6.1.
network
low complexity
progress CWE-22
5.3
2019-06-07 CVE-2019-12477 Path Traversal vulnerability in Supra Stv-Lc40Lt0020F Firmware
Supra Smart Cloud TV allows remote file inclusion in the openLiveURL function, which allows a local attacker to broadcast fake video without any authentication via a /remote/media_control?action=setUri&uri= URI.
local
low complexity
supra CWE-22
5.5
2019-06-06 CVE-2019-8320 Path Traversal vulnerability in Rubygems
A Directory Traversal issue was discovered in RubyGems 2.7.6 and later through 3.0.2.
network
high complexity
rubygems CWE-22
7.4
2019-06-05 CVE-2019-9157 Path Traversal vulnerability in Gemalto Ezio DS3 Server 2.6.1
Gemalto DS3 Authentication Server 2.6.1-SP01 allows Local File Disclosure.
low complexity
gemalto CWE-22
5.7
2019-06-05 CVE-2019-8385 Path Traversal vulnerability in Thomsonreuters Concourse Matter Room and Firm Central Desktop
An issue was discovered in Thomson Reuters Desktop Extensions 1.9.0.358.
network
low complexity
thomsonreuters CWE-22
critical
9.8
2019-06-05 CVE-2019-12276 Path Traversal vulnerability in Grandnode 4.40
A Path Traversal vulnerability in Controllers/LetsEncryptController.cs in LetsEncryptController in GrandNode 4.40 allows remote, unauthenticated attackers to retrieve arbitrary files on the web server via specially crafted LetsEncrypt/Index?fileName= HTTP requests.
network
low complexity
grandnode CWE-22
7.5
2019-06-05 CVE-2019-5356 Path Traversal vulnerability in HP Intelligent Management Center
A remote code execution vulnerability was identified in HPE Intelligent Management Center (IMC) PLAT earlier than version 7.3 E0506P09.
network
low complexity
hp CWE-22
critical
9.8
2019-06-04 CVE-2018-13379 Path Traversal vulnerability in Fortinet Fortios and Fortiproxy
An Improper Limitation of a Pathname to a Restricted Directory ("Path Traversal") in Fortinet FortiOS 6.0.0 to 6.0.4, 5.6.3 to 5.6.7 and 5.4.6 to 5.4.12 and FortiProxy 2.0.0, 1.2.0 to 1.2.8, 1.1.0 to 1.1.6, 1.0.0 to 1.0.7 under SSL VPN web portal allows an unauthenticated attacker to download system files via special crafted HTTP resource requests.
network
low complexity
fortinet CWE-22
critical
9.8
2019-06-03 CVE-2019-10009 Path Traversal vulnerability in Southrivertech Titan FTP Server 2019
A Directory Traversal issue was discovered in the Web GUI in Titan FTP Server 2019 Build 3505.
network
low complexity
southrivertech CWE-22
6.5