Vulnerabilities > Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
DATE | CVE | VULNERABILITY TITLE | RISK |
---|---|---|---|
2017-07-17 | CVE-2017-1000028 | Path Traversal vulnerability in Oracle Glassfish Server 4.1 Oracle, GlassFish Server Open Source Edition 4.1 is vulnerable to both authenticated and unauthenticated Directory Traversal vulnerability, that can be exploited by issuing a specially crafted HTTP GET request. | 7.5 |
2017-07-17 | CVE-2017-1000026 | Path Traversal vulnerability in Progress Mixlib-Archive 0.1.0/0.2.0/0.3.0 Chef Software's mixlib-archive versions 0.3.0 and older are vulnerable to a directory traversal attack allowing attackers to overwrite arbitrary files by using ".." in tar archive entries | 7.5 |
2017-07-17 | CVE-2017-1000002 | Path Traversal vulnerability in Atutor ATutor versions 2.2.1 and earlier are vulnerable to a directory traversal and file extension check bypass in the Course component resulting in code execution. | 9.8 |
2017-07-09 | CVE-2017-8003 | Path Traversal vulnerability in EMC Data Protection Advisor EMC Data Protection Advisor prior to 6.4 contains a path traversal vulnerability. | 4.9 |
2017-07-07 | CVE-2014-7954 | Path Traversal vulnerability in Google Android 4.4.4 Directory traversal vulnerability in the doSendObjectInfo method in frameworks/av/media/mtp/MtpServer.cpp in Android 4.4.4 allows physically proximate attackers with a direct connection to the target Android device to upload files outside of the sdcard via a .. | 4.6 |
2017-07-07 | CVE-2015-3297 | Path Traversal vulnerability in Etherpad Directory traversal vulnerability in node/utils/Minify.js in Etherpad 1.1.1 through 1.5.2 allows remote attackers to read arbitrary files by leveraging replacement of backslashes with slashes in the path parameter of HTTP API requests. | 7.5 |
2017-07-07 | CVE-2017-2245 | Path Traversal vulnerability in Getshortcodes Shortcodes Ultimate Directory traversal vulnerability in Shortcodes Ultimate prior to version 4.10.0 allows remote attackers to read arbitrary files via unspecified vectors. | 5.0 |
2017-07-07 | CVE-2017-10974 | Path Traversal vulnerability in Yaws 1.91 Yaws 1.91 allows Unauthenticated Remote File Disclosure via HTTP Directory Traversal with /%5C../ to port 8080. | 7.5 |
2017-07-04 | CVE-2017-6704 | Path Traversal vulnerability in Cisco Prime Collaboration Provisioning 12.1 A vulnerability in the web application in the Cisco Prime Collaboration Provisioning tool could allow an authenticated, remote attacker to perform arbitrary file downloads that could allow the attacker to read files from the underlying filesystem. | 6.5 |
2017-06-27 | CVE-2015-7780 | Path Traversal vulnerability in Zohocorp Manageengine Firewall Analyzer 7.2/7.4/7.6 Directory traversal vulnerability in ManageEngine Firewall Analyzer before 8.0. | 6.5 |