Vulnerabilities > Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')

DATE CVE VULNERABILITY TITLE RISK
2019-01-23 CVE-2018-1000997 Path Traversal vulnerability in Jenkins
A path traversal vulnerability exists in the Stapler web framework used by Jenkins 2.145 and earlier, LTS 2.138.1 and earlier in core/src/main/java/org/kohsuke/stapler/Facet.java, groovy/src/main/java/org/kohsuke/stapler/jelly/groovy/GroovyFacet.java, jelly/src/main/java/org/kohsuke/stapler/jelly/JellyFacet.java, jruby/src/main/java/org/kohsuke/stapler/jelly/jruby/JRubyFacet.java, jsp/src/main/java/org/kohsuke/stapler/jsp/JSPFacet.java that allows attackers to render routable objects using any view in Jenkins, exposing internal information about those objects not intended to be viewed, such as their toString() representation.
network
low complexity
jenkins CWE-22
6.5
2019-01-21 CVE-2019-6500 Path Traversal vulnerability in Axway File Tranfer Direct 2.7.1
In Axway File Transfer Direct 2.7.1, an unauthenticated Directory Traversal vulnerability can be exploited by issuing a specially crafted HTTP GET request with %2e instead of '.' characters, as demonstrated by an initial /h2hdocumentation//%2e%2e/ substring.
network
low complexity
axway CWE-22
7.5
2019-01-16 CVE-2018-15782 Path Traversal vulnerability in RSA Authentication Manager
The Quick Setup component of RSA Authentication Manager versions prior to 8.4 is vulnerable to a relative path traversal vulnerability.
local
low complexity
rsa CWE-22
7.8
2019-01-16 CVE-2015-9277 Path Traversal vulnerability in Mailenable
MailEnable before 8.60 allows Directory Traversal for reading the messages of other users, uploading files, and deleting files because "/../" and "/..
network
low complexity
mailenable CWE-22
critical
9.1
2019-01-15 CVE-2018-20714 Path Traversal vulnerability in Woocommerce
The logging system of the Automattic WooCommerce plugin before 3.4.6 for WordPress is vulnerable to a File Deletion vulnerability.
network
low complexity
woocommerce CWE-22
8.1
2019-01-10 CVE-2019-5887 Path Traversal vulnerability in Shopxo 1.2.0
An issue was discovered in ShopXO 1.2.0.
network
low complexity
shopxo CWE-22
7.5
2019-01-09 CVE-2018-16202 Path Traversal vulnerability in Ionicframework Ionic web View
Directory traversal vulnerability in cordova-plugin-ionic-webview versions prior to 2.2.0 (not including 2.0.0-beta.0, 2.0.0-beta.1, 2.0.0-beta.2, and 2.1.0-0) allows remote attackers to access arbitrary files via unspecified vectors.
network
low complexity
ionicframework CWE-22
8.6
2019-01-09 CVE-2018-16171 Path Traversal vulnerability in Cybozu Remote Service Manager
Directory traversal vulnerability in Cybozu Remote Service 3.0.0 to 3.1.8 allows remote attackers to execute Java code file on the server via unspecified vectors.
network
low complexity
cybozu CWE-22
8.8
2019-01-09 CVE-2018-16170 Path Traversal vulnerability in Cybozu Remote Service Manager
Directory traversal vulnerability in Cybozu Remote Service 3.0.0 to 3.1.8 for Windows allows remote authenticated attackers to read arbitrary files via unspecified vectors.
network
low complexity
cybozu CWE-22
8.1
2019-01-09 CVE-2018-1000406 Path Traversal vulnerability in Jenkins
A path traversal vulnerability exists in Jenkins 2.145 and earlier, LTS 2.138.1 and earlier in core/src/main/java/hudson/model/FileParameterValue.java that allows attackers with Job/Configure permission to define a file parameter with a file name outside the intended directory, resulting in an arbitrary file write on the Jenkins master when scheduling a build.
network
low complexity
jenkins CWE-22
6.5