Vulnerabilities > Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')

DATE CVE VULNERABILITY TITLE RISK
2018-02-26 CVE-2017-16814 Path Traversal vulnerability in Foxitsoftware Mobilepdf
A Directory Traversal issue was discovered in the Foxit MobilePDF app before 6.1 for iOS.
local
low complexity
foxitsoftware CWE-22
5.5
2018-02-26 CVE-2018-7486 Path Traversal vulnerability in Blueriver Muracms
Blue River Mura CMS before v7.0.7029 supports inline function calls with an [m] tag and [/m] end tag, without proper restrictions on file types or pathnames, which allows remote attackers to execute arbitrary code via an [m]$.dspinclude("../pathname/executable.jpeg")[/m] approach, where executable.jpeg contains ColdFusion Markup Language code.
network
low complexity
blueriver CWE-22
7.2
2018-02-24 CVE-2018-7434 Path Traversal vulnerability in Zzcms 8.2
zzcms 8.2 allows remote attackers to discover the full path via a direct request to 3/qq_connect2.0/API/class/ErrorCase.class.php or 3/ucenter_api/code/friend.php.
network
low complexity
zzcms CWE-22
5.3
2018-02-23 CVE-2018-7442 Path Traversal vulnerability in Leptonica
An issue was discovered in Leptonica through 1.75.3.
network
low complexity
leptonica CWE-22
critical
9.1
2018-02-23 CVE-2017-18196 Path Traversal vulnerability in Leptonica 1.74.4
Leptonica 1.74.4 constructs unintended pathnames (containing duplicated path components) when operating on files in /tmp subdirectories, which might allow local users to bypass intended file restrictions by leveraging access to a directory located deeper within the /tmp directory tree, as demonstrated by /tmp/ANY/PATH/ANY/PATH/input.tif.
local
low complexity
leptonica CWE-22
3.3
2018-02-22 CVE-2018-7300 Path Traversal vulnerability in Eq-3 Homematic Ccu2 Firmware
Directory Traversal / Arbitrary File Write / Remote Code Execution in the User.setLanguage method in eQ-3 AG Homematic CCU2 2.29.2 and earlier allows remote attackers to write arbitrary files to the device's filesystem.
network
low complexity
eq-3 CWE-22
critical
9.8
2018-02-22 CVE-2018-7296 Path Traversal vulnerability in Eq-3 Homematic Central Control Unit Ccu2 Firmware 2.29.22
Directory Traversal / Arbitrary File Read in User.getLanguage method in eQ-3 AG Homematic CCU2 2.29.2 and earlier allows remote attackers to read the first line of an arbitrary file on the CCU2's filesystem.
network
low complexity
eq-3 CWE-22
5.3
2018-02-21 CVE-2018-5716 Path Traversal vulnerability in Reprisesoftware Reprise License Manager 11.0
An issue was discovered in Reprise License Manager 11.0.
network
low complexity
reprisesoftware CWE-22
8.1
2018-02-20 CVE-2018-6356 Path Traversal vulnerability in multiple products
Jenkins before 2.107 and Jenkins LTS before 2.89.4 did not properly prevent specifying relative paths that escape a base directory for URLs accessing plugin resource files.
network
low complexity
jenkins oracle CWE-22
6.5
2018-02-19 CVE-2014-3972 Path Traversal vulnerability in Apexis Apm-J601-Ws Firmware
Directory traversal vulnerability in Apexis APM-J601-WS cameras with firmware before 17.35.2.49 allows remote attackers to read arbitrary files via unspecified vectors.
network
low complexity
apexis CWE-22
5.3