Vulnerabilities > Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')

DATE CVE VULNERABILITY TITLE RISK
2018-09-21 CVE-2018-17297 Path Traversal vulnerability in Hutool
The unzip function in ZipUtil.java in Hutool before 4.1.12 allows remote attackers to overwrite arbitrary files via directory traversal sequences in a filename within a ZIP archive.
network
low complexity
hutool CWE-22
7.5
2018-09-20 CVE-2018-6500 Path Traversal vulnerability in HP Arcsight Management Center 2.0/2.9.1
A potential Directory Traversal Security vulnerability has been identified in ArcSight Management Center (ArcMC) in all versions prior to 2.81.
network
low complexity
hp CWE-22
7.5
2018-09-19 CVE-2018-8889 Path Traversal vulnerability in Blackberry Enterprise Mobility Server 2.6/2.8/2.8.17.29
A directory traversal vulnerability in the Connect Service of the BlackBerry Enterprise Mobility Server (BEMS) 2.8.17.29 and earlier could allow an attacker to retrieve arbitrary files in the context of a BEMS administrator account.
local
high complexity
blackberry CWE-22
4.7
2018-09-19 CVE-2018-11762 Path Traversal vulnerability in Apache Tika
In Apache Tika 0.9 to 1.18, in a rare edge case where a user does not specify an extract directory on the commandline (--extract-dir=) and the input file has an embedded file with an absolute path, such as "C:/evil.bat", tika-app would overwrite that file.
network
high complexity
apache CWE-22
5.9
2018-09-18 CVE-2018-16820 Path Traversal vulnerability in Monstra 3.0.4
admin/index.php in Monstra CMS 3.0.4 allows arbitrary directory listing via id=filesmanager&path=uploads/.......//./.......//./ requests.
network
low complexity
monstra CWE-22
7.5
2018-09-18 CVE-2018-16819 Path Traversal vulnerability in Monstra 3.0.4
admin/index.php in Monstra CMS 3.0.4 allows arbitrary file deletion via id=filesmanager&path=uploads/.......//./.......//./&delete_file= requests.
network
low complexity
monstra CWE-22
4.9
2018-09-18 CVE-2018-13982 Path Traversal vulnerability in multiple products
Smarty_Security::isTrustedResourceDir() in Smarty before 3.1.33 is prone to a path traversal vulnerability due to insufficient template code sanitization.
network
low complexity
smarty debian CWE-22
7.5
2018-09-17 CVE-2018-8041 Path Traversal vulnerability in Apache Camel
Apache Camel's Mail 2.20.0 through 2.20.3, 2.21.0 through 2.21.1 and 2.22.0 is vulnerable to path traversal.
network
low complexity
apache CWE-22
5.3
2018-09-17 CVE-2018-17125 Path Traversal vulnerability in Chshcms Cscms 4.1
CScms 4.1 allows arbitrary directory deletion via a dir=..\\ substring to plugins\sys\admin\Plugins.php.
network
low complexity
chshcms CWE-22
7.5
2018-09-12 CVE-2018-15610 Path Traversal vulnerability in Avaya IP Office 10.0/10.1/9.1
A vulnerability in the one-X Portal component of Avaya IP Office allows an authenticated attacker to read and delete arbitrary files on the system.
network
low complexity
avaya CWE-22
8.8