Vulnerabilities > Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')

DATE CVE VULNERABILITY TITLE RISK
2017-12-01 CVE-2017-15607 Path Traversal vulnerability in Inedo Otter
Inedo Otter before 1.7.4 has directory traversal in filesystem-based rafts via vectors involving '/' characters or initial '.' characters, aka OT-181.
network
low complexity
inedo CWE-22
critical
9.8
2017-11-30 CVE-2017-14196 Path Traversal vulnerability in Squiz Matrix
An issue was discovered in Squiz Matrix from 5.3 through to 5.3.6.1 and 5.4.1.3.
network
low complexity
squiz CWE-22
7.5
2017-11-29 CVE-2017-17058 Path Traversal vulnerability in Automattic Woocommerce
The WooCommerce plugin through 3.x for WordPress has a Directory Traversal Vulnerability via a /wp-content/plugins/woocommerce/templates/emails/plain/ URI, which accesses a parent directory.
network
low complexity
automattic CWE-22
7.5
2017-11-28 CVE-2017-17042 Path Traversal vulnerability in Yardoc Yard
lib/yard/core_ext/file.rb in the server in YARD before 0.9.11 does not block relative paths with an initial ../ sequence, which allows attackers to conduct directory traversal attacks and read arbitrary files.
network
low complexity
yardoc CWE-22
7.5
2017-11-27 CVE-2017-16959 Path Traversal vulnerability in Tp-Link products
The locale feature in cgi-bin/luci on TP-Link TL-WVR, TL-WAR, TL-ER, and TL-R devices allows remote authenticated users to test for the existence of arbitrary files by making an operation=write;locale=%0d request, and then making an operation=read request with a crafted Accept-Language HTTP header, related to the set_sysinfo and get_sysinfo functions in /usr/lib/lua/luci/controller/locale.lua in uhttpd.
network
low complexity
tp-link CWE-22
6.5
2017-11-24 CVE-2017-16936 Path Traversal vulnerability in Tenda Ac15 Firmware, Ac18 Firmware and AC9 Firmware
Directory Traversal vulnerability in app_data_center on Shenzhen Tenda Ac9 US_AC9V1.0BR_V15.03.05.14_multi_TD01, Ac9 ac9_kf_V15.03.05.19(6318_)_cn, Ac15 US_AC15V1.0BR_V15.03.05.18_multi_TD01, Ac15 US_AC15V1.0BR_V15.03.05.19_multi_TD01, Ac18 US_AC18V1.0BR_V15.03.05.05_multi_TD01, and Ac18 ac18_kf_V15.03.05.19(6318_)_cn devices allows remote unauthenticated attackers to read arbitrary files via a cgi-bin/luci/request?op=1&path= URI that uses directory traversal sequences after a /usb/ substring.
low complexity
tenda CWE-22
6.5
2017-11-22 CVE-2017-8189 Path Traversal vulnerability in Huawei Fusionsphere Openstack V100R006C00Spc102(Nfv)
FusionSphere OpenStack V100R006C00SPC102(NFV)has a path traversal vulnerability.
local
low complexity
huawei CWE-22
6.0
2017-11-22 CVE-2017-2706 Path Traversal vulnerability in Huawei Mate 9 Firmware
Mate 9 smartphones with software MHA-AL00AC00B125 have a directory traversal vulnerability in Push module.
local
low complexity
huawei CWE-22
7.1
2017-11-22 CVE-2017-2695 Path Traversal vulnerability in Huawei Tit-Al00 Firmware C583B211
TIT-AL00C583B211 has a directory traversal vulnerability which allows an attacker to obtain the files in email application.
local
low complexity
huawei CWE-22
5.5
2017-11-22 CVE-2017-2693 Path Traversal vulnerability in Huawei products
ALE-L02C635B140 and earlier versions,ALE-L02C636B140 and earlier versions,ALE-L21C10B150 and earlier versions,ALE-L21C185B200 and earlier versions,ALE-L21C432B214 and earlier versions,ALE-L21C464B150 and earlier versions,ALE-L21C636B200 and earlier versions,ALE-L23C605B190 and earlier versions,ALE-TL00C01B250 and earlier versions,ALE-UL00C00B250 and earlier versions,MT7-L09C605B325 and earlier versions,MT7-L09C900B339 and earlier versions,MT7-TL10C900B339 and earlier versions,CRR-CL00C92B172 and earlier versions,CRR-L09C432B180 and earlier versions,CRR-TL00C01B172 and earlier versions,CRR-UL00C00B172 and earlier versions,CRR-UL20C432B171 and earlier versions,GRA-CL00C92B230 and earlier versions,GRA-L09C432B222 and earlier versions,GRA-TL00C01B230SP01 and earlier versions,GRA-UL00C00B230 and earlier versions,GRA-UL00C10B201 and earlier versions,GRA-UL00C432B220 and earlier versions,H60-L04C10B523 and earlier versions,H60-L04C185B523 and earlier versions,H60-L04C636B527 and earlier versions,H60-L04C900B530 and earlier versions,PLK-AL10C00B220 and earlier versions,PLK-AL10C92B220 and earlier versions,PLK-CL00C92B220 and earlier versions,PLK-L01C10B140 and earlier versions,PLK-L01C185B130 and earlier versions,PLK-L01C432B187 and earlier versions,PLK-L01C432B190 and earlier versions,PLK-L01C432B190 and earlier versions,PLK-L01C636B130 and earlier versions,PLK-TL00C01B220 and earlier versions,PLK-TL01HC01B220 and earlier versions,PLK-UL00C17B220 and earlier versions,ATH-AL00C00B210 and earlier versions,ATH-AL00C92B200 and earlier versions,ATH-CL00C92B210 and earlier versions,ATH-TL00C01B210 and earlier versions,ATH-TL00HC01B210 and earlier versions,ATH-UL00C00B210 and earlier versions,RIO-AL00C00B220 and earlier versions,RIO-CL00C92B220 and earlier versions,RIO-TL00C01B220 and earlier versions,RIO-UL00C00B220 and earlier versions have a path traversal vulnerability.
local
low complexity
huawei CWE-22
7.8