Vulnerabilities > Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')

DATE CVE VULNERABILITY TITLE RISK
2018-09-04 CVE-2018-0646 Path Traversal vulnerability in Ponsoftware Explzh
Directory traversal vulnerability in Explzh v.7.58 and earlier allows an attacker to read arbitrary files via unspecified vectors.
local
low complexity
ponsoftware CWE-22
7.8
2018-09-04 CVE-2018-16446 Path Traversal vulnerability in Seamcms Seacms
An issue was discovered in SeaCMS through 6.61.
network
low complexity
seamcms CWE-22
7.5
2018-09-02 CVE-2018-16367 Path Traversal vulnerability in Qduoj Onlinejudge 2.0
In OnlineJudge 2.0, the sandbox has an incorrect access control vulnerability that can write a file anywhere.
network
low complexity
qduoj CWE-22
critical
9.9
2018-09-02 CVE-2018-16344 Path Traversal vulnerability in Zzcms 8.3
An issue was discovered in zzcms 8.3.
network
low complexity
zzcms CWE-22
7.5
2018-09-01 CVE-2018-16320 Path Traversal vulnerability in Idreamsoft Icms 7.0.11
idreamsoft iCMS 7.0.11 allows admincp.php?app=config Directory Traversal, resulting in execution of arbitrary PHP code from a ZIP file.
network
low complexity
idreamsoft CWE-22
7.2
2018-08-31 CVE-2018-3787 Path Traversal vulnerability in Simplehttpserver Project Simplehttpserver
Path traversal in simplehttpserver <v0.2.1 allows listing any file on the server.
network
low complexity
simplehttpserver-project CWE-22
7.5
2018-08-30 CVE-2018-16237 Path Traversal vulnerability in Damicms 6.0.1
An issue was discovered in damiCMS V6.0.1.
network
low complexity
damicms CWE-22
2.7
2018-08-30 CVE-2018-15745 Path Traversal vulnerability in Argussurveillance DVR 4.0.0.0
Argus Surveillance DVR 4.0.0.0 devices allow Unauthenticated Directory Traversal, leading to File Disclosure via a ..%2F in the WEBACCOUNT.CGI RESULTPAGE parameter.
network
low complexity
argussurveillance CWE-22
7.5
2018-08-30 CVE-2018-11720 Path Traversal vulnerability in Xovis PC2 Firmware, Pc2R Firmware and PC3 Firmware
Xovis PC2, PC2R, and PC3 devices through 3.6.0 allow Directory Traversal.
network
low complexity
xovis CWE-22
7.5
2018-08-30 CVE-2018-16141 Path Traversal vulnerability in Thinkcmf Thinkcmfx X2.2.3
ThinkCMF X2.2.3 has an arbitrary file deletion vulnerability in do_avatar in \application\User\Controller\ProfileController.class.php via an imgurl parameter with a ..\ sequence.
network
low complexity
thinkcmf CWE-22
6.5