Vulnerabilities > Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')

DATE CVE VULNERABILITY TITLE RISK
2018-03-16 CVE-2017-14384 Path Traversal vulnerability in Dell Storage Manager
In Dell Storage Manager versions earlier than 16.3.20, the EMConfigMigration service is affected by a directory traversal vulnerability.
network
low complexity
dell CWE-22
6.5
2018-03-15 CVE-2018-7706 Path Traversal vulnerability in Securenvoy Securmail
Directory traversal vulnerability in SecurEnvoy SecurMail before 9.2.501 allows remote authenticated users to read arbitrary e-mail messages via a ..
network
low complexity
securenvoy CWE-22
6.5
2018-03-15 CVE-2018-7705 Path Traversal vulnerability in Securenvoy Securmail
Directory traversal vulnerability in SecurEnvoy SecurMail before 9.2.501 allows remote authenticated users to read e-mail messages to arbitrary recipients via a ..
network
low complexity
securenvoy CWE-22
8.1
2018-03-14 CVE-2018-8712 Path Traversal vulnerability in Webmin 1.840/1.880
An issue was discovered in Webmin 1.840 and 1.880 when the default Yes setting of "Can view any file as a log file" is enabled.
network
low complexity
webmin CWE-22
critical
9.8
2018-03-14 CVE-2018-2366 Path Traversal vulnerability in Redwood SAP Business Process Automation 9.0/9.1
SAP Business Process Automation (BPA) By Redwood, 9.0, 9.1, allows an attacker to exploit insufficient validation of path information provided by users, thus characters representing 'traverse to parent directory' are passed through to the file APIs.
network
low complexity
redwood CWE-22
4.3
2018-03-13 CVE-2018-1000083 Path Traversal vulnerability in Ajenti 2
Ajenti version version 2 contains a Improper Error Handling vulnerability in Login JSON request that can result in The requisition leaks a path of the server.
network
low complexity
ajenti CWE-22
5.3
2018-03-13 CVE-2018-1000079 Path Traversal vulnerability in Rubygems
RubyGems version Ruby 2.2 series: 2.2.9 and earlier, Ruby 2.3 series: 2.3.6 and earlier, Ruby 2.4 series: 2.4.3 and earlier, Ruby 2.5 series: 2.5.0 and earlier, prior to trunk revision 62422 contains a Directory Traversal vulnerability in gem installation that can result in the gem could write to arbitrary filesystem locations during installation.
local
low complexity
rubygems CWE-22
5.5
2018-03-09 CVE-2017-17223 Path Traversal vulnerability in Huawei products
Huawei eSpace 7910 V200R003C30; eSpace 7950 V200R003C30; eSpace 8950 V200R003C00; V200R003C30 have a directory traversal vulnerability.
network
low complexity
huawei CWE-22
8.8
2018-03-09 CVE-2018-0525 Path Traversal vulnerability in Jubat Jubatus
Directory traversal vulnerability in Jubatus 1.0.2 and earlier allows remote attackers to read arbitrary files via unspecified vectors.
network
low complexity
jubat CWE-22
5.3
2018-03-06 CVE-2018-6810 Path Traversal vulnerability in Citrix products
Directory traversal vulnerability in NetScaler ADC 10.5, 11.0, 11.1, and 12.0, and NetScaler Gateway 10.5, 11.0, 11.1, and 12.0 allows remote attackers to traverse the directory on the target system via a crafted request.
network
low complexity
citrix CWE-22
7.5