Vulnerabilities > Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')

DATE CVE VULNERABILITY TITLE RISK
2018-02-20 CVE-2018-6356 Path Traversal vulnerability in multiple products
Jenkins before 2.107 and Jenkins LTS before 2.89.4 did not properly prevent specifying relative paths that escape a base directory for URLs accessing plugin resource files.
network
low complexity
jenkins oracle CWE-22
6.5
2018-02-19 CVE-2014-3972 Path Traversal vulnerability in Apexis Apm-J601-Ws Firmware
Directory traversal vulnerability in Apexis APM-J601-WS cameras with firmware before 17.35.2.49 allows remote attackers to read arbitrary files via unspecified vectors.
network
low complexity
apexis CWE-22
5.3
2018-02-19 CVE-2017-15712 Path Traversal vulnerability in Apache Oozie
Vulnerability allows a user of Apache Oozie 3.1.3-incubating to 4.3.0 and 5.0.0-beta1 to expose private files on the Oozie server process.
network
low complexity
apache CWE-22
6.5
2018-02-18 CVE-2018-7212 Path Traversal vulnerability in Sinatrarb Sinatra 2.0.0/2.0.1
An issue was discovered in rack-protection/lib/rack/protection/path_traversal.rb in Sinatra 2.x before 2.0.1 on Windows.
network
low complexity
sinatrarb CWE-22
5.3
2018-02-16 CVE-2017-14537 Path Traversal vulnerability in Netfortris Trixbox 2.8.0.4
trixbox 2.8.0.4 has path traversal via the xajaxargs array parameter to /maint/index.php?packages or the lang parameter to /maint/modules/home/index.php.
network
low complexity
netfortris CWE-22
6.5
2018-02-15 CVE-2017-8961 Path Traversal vulnerability in HP Intelligent Management Center 7.3
A directory traversal vulnerability in HPE Intelligent Management Center (IMC) PLAT 7.3 E0504P02 could allow remote code execution.
network
low complexity
hp CWE-22
8.8
2018-02-15 CVE-2017-8947 Path Traversal vulnerability in HP Ucmdb Configuration Manager
A Remote Code Execution vulnerability in HPE UCMDB version v10.10, v10.11, v10.20, v10.21, v10.22, v10.30, v10.31 was found.
network
low complexity
hp CWE-22
critical
9.8
2018-02-15 CVE-2017-12560 Path Traversal vulnerability in HP Intelligent Management Center 7.3
A Remote Denial of Service vulnerability in HPE Intelligent Management Center (iMC) PLAT version iMC Plat 7.3 E0504P2 was found.
network
low complexity
hp CWE-22
6.5
2018-02-15 CVE-2017-12559 Path Traversal vulnerability in HP Intelligent Management Center 7.3
A Remote Denial of Service vulnerability in HPE Intelligent Management Center (iMC) PLAT version iMC Plat 7.3 E0504P2 was found.
network
low complexity
hp CWE-22
6.5
2018-02-08 CVE-2018-0123 Path Traversal vulnerability in Cisco IOS and IOS XE
A Path Traversal vulnerability in the diagnostic shell for Cisco IOS and IOS XE Software could allow an authenticated, local attacker to use certain diagnostic shell commands that can overwrite system files.
local
low complexity
cisco CWE-22
5.5