Vulnerabilities > Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')

DATE CVE VULNERABILITY TITLE RISK
2017-05-23 CVE-2015-5609 Path Traversal vulnerability in Image-Export Project Image-Export 1.1
Absolute path traversal vulnerability in the Image Export plugin 1.1 for WordPress allows remote attackers to read and delete arbitrary files via a full pathname in the file parameter to download.php.
network
low complexity
image-export-project CWE-22
critical
9.1
2017-05-23 CVE-2015-5469 Path Traversal vulnerability in MDC Youtube Downloader Project MDC Youtube Downloader 2.1.0
Absolute path traversal vulnerability in the MDC YouTube Downloader plugin 2.1.0 for WordPress allows remote attackers to read arbitrary files via a full pathname in the file parameter to includes/download.php.
network
low complexity
mdc-youtube-downloader-project CWE-22
7.5
2017-05-23 CVE-2015-5468 Path Traversal vulnerability in Wpshopstyling WP E-Commerce Shop Styling 2.5
Directory traversal vulnerability in the WP e-Commerce Shop Styling plugin before 2.6 for WordPress allows remote attackers to read arbitrary files via a ..
network
low complexity
wpshopstyling CWE-22
7.5
2017-05-23 CVE-2015-4704 Path Traversal vulnerability in Download ZIP Attachments Project Download ZIP Attachments 1.0
Directory traversal vulnerability in the Download Zip Attachments plugin 1.0 for WordPress allows remote attackers to read arbitrary files via a ..
network
low complexity
download-zip-attachments-project CWE-22
7.5
2017-05-22 CVE-2017-6636 Path Traversal vulnerability in Cisco Prime Collaboration Provisioning
A vulnerability in the web interface of Cisco Prime Collaboration Provisioning Software (prior to Release 11.1) could allow an authenticated, remote attacker to view any file on an affected system.
network
low complexity
cisco CWE-22
6.5
2017-05-21 CVE-2017-9024 Path Traversal vulnerability in Secure-Bytes Secure Cisco Auditor 3.0
Secure Bytes Cisco Configuration Manager, as bundled in Secure Bytes Secure Cisco Auditor (SCA) 3.0, has a Directory Traversal issue in its TFTP Server, allowing attackers to read arbitrary files via ../ sequences in a pathname.
network
low complexity
secure-bytes CWE-22
7.5
2017-05-18 CVE-2017-3980 Path Traversal vulnerability in Mcafee Epolicy Orchestrator
A directory traversal vulnerability in the ePO Extension in McAfee ePolicy Orchestrator (ePO) 5.9.0, 5.3.2, and 5.1.3 and earlier allows remote authenticated users to execute a command of their choice via an authenticated ePO session.
network
low complexity
mcafee CWE-22
7.2
2017-05-18 CVE-2017-9067 Path Traversal vulnerability in multiple products
In MODX Revolution before 2.5.7, when PHP 5.3.3 is used, an attacker is able to include and execute arbitrary files on the web server due to insufficient validation of the action parameter to setup/index.php, aka directory traversal.
local
high complexity
modx php CWE-22
7.0
2017-05-18 CVE-2017-7433 Path Traversal vulnerability in Micro Focus Vibe
An absolute path traversal vulnerability (CWE-36) in Micro Focus Vibe 4.0.2 and earlier allows a remote authenticated attacker to download arbitrary files from the server by submitting a specially crafted request to the viewFile endpoint.
network
low complexity
micro-focus CWE-22
6.5
2017-05-17 CVE-2017-9031 Path Traversal vulnerability in Deluge-Torrent Deluge
The WebUI component in Deluge before 1.3.15 contains a directory traversal vulnerability involving a request in which the name of the render file is not associated with any template file.
network
low complexity
deluge-torrent CWE-22
critical
9.8