Vulnerabilities > Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')

DATE CVE VULNERABILITY TITLE RISK
2017-10-24 CVE-2017-14695 Path Traversal vulnerability in Saltstack Salt
Directory traversal vulnerability in minion id validation in SaltStack Salt before 2016.3.8, 2016.11.x before 2016.11.8, and 2017.7.x before 2017.7.2 allows remote minions with incorrect credentials to authenticate to a master via a crafted minion ID.
network
low complexity
saltstack CWE-22
critical
9.8
2017-10-23 CVE-2014-3744 Path Traversal vulnerability in Nodejs Node.Js
Directory traversal vulnerability in the st module before 0.2.5 for Node.js allows remote attackers to read arbitrary files via a %2e%2e (encoded dot dot) in an unspecified path.
network
low complexity
nodejs CWE-22
7.5
2017-10-23 CVE-2017-9947 Path Traversal vulnerability in Siemens products
A vulnerability has been identified in Siemens APOGEE PXC and TALON TC BACnet Automation Controllers in all versions <V3.5.
network
low complexity
siemens CWE-22
5.3
2017-10-23 CVE-2017-15805 Path Traversal vulnerability in Cisco products
Cisco Small Business SA520 and SA540 devices with firmware 2.1.71 and 2.2.0.7 allow ../ directory traversal in scgi-bin/platform.cgi via the thispage parameter, for reading arbitrary files.
network
low complexity
cisco CWE-22
7.5
2017-10-19 CVE-2017-15647 Path Traversal vulnerability in Fiberhome Routerfiberhome Firmware
On FiberHome routers, Directory Traversal exists in /cgi-bin/webproc via the getpage parameter in conjunction with a crafted var:page value.
network
low complexity
fiberhome CWE-22
7.5
2017-10-19 CVE-2017-10933 Path Traversal vulnerability in ZTE Zxdt22 Sf01 Firmware V2.06.00.00
All versions prior to V2.06.00.00 of ZTE ZXDT22 SF01, an monitoring system of ZTE energy product, are impacted by directory traversal vulnerability that allows remote attackers to read arbitrary files on the system via a full path name after host address.
network
low complexity
zte CWE-22
7.5
2017-10-18 CVE-2017-15359 Path Traversal vulnerability in 3CX 15.5.3554.1
In the 3CX Phone System 15.5.3554.1, the Management Console typically listens to port 5001 and is prone to a directory traversal attack: "/api/RecordingList/DownloadRecord?file=" and "/api/SupportInfo?file=" are the vulnerable parameters.
network
low complexity
3cx CWE-22
6.5
2017-10-17 CVE-2017-8805 Path Traversal vulnerability in Debian Ftpsync 20171016
Debian ftpsync before 20171017 does not use the rsync --safe-links option, which allows remote attackers to conduct directory traversal attacks via a crafted upstream mirror.
network
low complexity
debian CWE-22
critical
9.1
2017-10-16 CVE-2017-9367 Path Traversal vulnerability in Blackberry Workspaces Appliance-X and Workspaces Vapp
A directory traversal vulnerability in the BlackBerry Workspaces Server could potentially allow an attacker to execute or upload arbitrary files, or reveal the content of arbitrary files anywhere on the web server by crafting a URL with a manipulated POST request.
network
low complexity
blackberry CWE-22
critical
9.8
2017-10-16 CVE-2014-3702 Path Traversal vulnerability in Redhat Edeploy
Directory traversal vulnerability in eNovance eDeploy allows remote attackers to create arbitrary directories and files and consequently cause a denial of service (resource consumption) via a ..
network
low complexity
redhat CWE-22
critical
9.1