Vulnerabilities > Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')

DATE CVE VULNERABILITY TITLE RISK
2018-11-17 CVE-2018-19329 Path Traversal vulnerability in Greencms 2.3.0603
GreenCMS v2.3.0603 allows remote authenticated administrators to delete arbitrary files by modifying a base64-encoded pathname in an m=admin&c=media&a=delfilehandle&id= call, related to the m=admin&c=media&a=restorefile delete button.
network
low complexity
greencms CWE-22
4.9
2018-11-17 CVE-2018-19328 Path Traversal vulnerability in Laobancms 2.0
LAOBANCMS 2.0 allows install/mysql_hy.php?riqi=../ Directory Traversal.
network
low complexity
laobancms CWE-22
critical
9.8
2018-11-17 CVE-2018-19326 Path Traversal vulnerability in Zyxel Vmg1312-B10D Firmware
Zyxel VMG1312-B10D devices before 5.13(AAXA.8)C0 allow ../ Directory Traversal, as demonstrated by reading /etc/passwd.
network
low complexity
zyxel CWE-22
7.5
2018-11-16 CVE-2018-1797 Path Traversal vulnerability in IBM Websphere Application Server
IBM WebSphere Application Server 7.0, 8.0, 8.5, and 9.0 using Enterprise bundle Archives (EBA) could allow a local attacker to traverse directories on the system.
local
low complexity
ibm CWE-22
5.5
2018-11-15 CVE-2018-0693 Path Traversal vulnerability in Soliton Filezen
Directory traversal vulnerability in FileZen V3.0.0 to V4.2.1 allows remote attackers to upload an arbitrary file in the specific directory in FileZen via unspecified vectors.
network
low complexity
soliton CWE-22
7.5
2018-11-15 CVE-2018-0673 Path Traversal vulnerability in Cybozu Garoon
Directory traversal vulnerability in Cybozu Garoon 3.5.0 to 4.6.3 allows authenticated attackers to read arbitrary files via unspecified vectors.
network
low complexity
cybozu CWE-22
8.1
2018-11-13 CVE-2018-8009 Path Traversal vulnerability in Apache Hadoop
Apache Hadoop 3.1.0, 3.0.0-alpha to 3.0.2, 2.9.0 to 2.9.1, 2.8.0 to 2.8.4, 2.0.0-alpha to 2.7.6, 0.23.0 to 0.23.11 is exploitable via the zip slip vulnerability in places that accept a zip file.
network
low complexity
apache CWE-22
8.8
2018-11-12 CVE-2018-19228 Path Traversal vulnerability in Laobancms 2.0
An issue was discovered in LAOBANCMS 2.0.
network
low complexity
laobancms CWE-22
7.5
2018-11-12 CVE-2018-1884 Path Traversal vulnerability in IBM Case Manager
IBM Case Manager 5.2.0.0, 5.2.0.4, 5.2.1.0, 5.2.1.7, 5.3.0.0, and 5.3.3.0 is vulnerable to a "zip slip" vulnerability which could allow a remote attacker to execute code using directory traversal techniques.
local
low complexity
ibm CWE-22
7.8
2018-11-12 CVE-2018-19197 Path Traversal vulnerability in Xiaocms 20141229
An issue was discovered in XiaoCms 20141229.
network
low complexity
xiaocms CWE-22
4.9