Vulnerabilities > Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')

DATE CVE VULNERABILITY TITLE RISK
2018-08-07 CVE-2018-11455 Path Traversal vulnerability in Siemens Automation License Manager
A vulnerability has been identified in Automation License Manager 5 (All versions < 5.3.4.4), Automation License Manager 6 (All versions < 6.0.1).
network
low complexity
siemens CWE-22
8.8
2018-08-06 CVE-2017-16654 Path Traversal vulnerability in multiple products
An issue was discovered in Symfony before 2.7.38, 2.8.31, 3.2.14, 3.3.13, 3.4-BETA5, and 4.0-BETA5.
network
low complexity
sensiolabs debian CWE-22
7.5
2018-08-06 CVE-2018-7092 Path Traversal vulnerability in HP Intelligent Management Center 7.3
A potential security vulnerability has been identified in HPE Intelligent Management Center Platform (IMC Plat) 7.3 E0506P09.
network
low complexity
hp CWE-22
7.5
2018-08-05 CVE-2018-14942 Path Traversal vulnerability in Harmonicinc NSG 9000 Firmware
Harmonic NSG 9000 devices allow remote authenticated users to conduct directory traversal attacks, as demonstrated by "POST /PY/EMULATION_GET_FILE" or "POST /PY/EMULATION_EXPORT" with FileName=../../../passwd in the POST data.
network
low complexity
harmonicinc CWE-22
8.8
2018-08-03 CVE-2018-14927 Path Traversal vulnerability in Matera Banco 1.0.0
Matera Banco 1.0.0 is vulnerable to path traversal (allowing access to system files outside the default application folder) via the /contingency/servlet/ServletFileDownload file parameter, related to /contingency/web/receiptQuery/receiptDisplay.jsp.
network
low complexity
matera CWE-22
5.3
2018-08-03 CVE-2018-14912 Path Traversal vulnerability in multiple products
cgit_clone_objects in CGit before 1.2.1 has a directory traversal vulnerability when `enable-http-clone=1` is not turned off, as demonstrated by a cgit/cgit.cgi/git/objects/?path=../ request.
network
low complexity
cgit-project debian CWE-22
7.5
2018-08-02 CVE-2018-14847 Path Traversal vulnerability in Mikrotik Routeros
MikroTik RouterOS through 6.42 allows unauthenticated remote attackers to read arbitrary files and remote authenticated attackers to write arbitrary files due to a directory traversal vulnerability in the WinBox interface.
network
low complexity
mikrotik CWE-22
critical
9.1
2018-07-31 CVE-2018-12939 Path Traversal vulnerability in Seeddms
A directory traversal flaw in SeedDMS (formerly LetoDMS and MyDMS) before 5.1.8 allows an authenticated attacker to write to (or potentially delete) arbitrary files via a ..
network
low complexity
seeddms CWE-22
6.5
2018-07-27 CVE-2017-2595 Path Traversal vulnerability in Redhat Jboss Enterprise Application Platform
It was found that the log file viewer in Red Hat JBoss Enterprise Application 6 and 7 allows arbitrary file read to authenticated user via path traversal.
network
low complexity
redhat CWE-22
6.5
2018-07-27 CVE-2018-10862 Path Traversal vulnerability in Redhat products
WildFly Core before version 6.0.0.Alpha3 does not properly validate file paths in .war archives, allowing for the extraction of crafted .war archives to overwrite arbitrary files.
local
low complexity
redhat CWE-22
5.5