Vulnerabilities > Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')

DATE CVE VULNERABILITY TITLE RISK
2018-02-22 CVE-2018-7296 Path Traversal vulnerability in Eq-3 Homematic Central Control Unit Ccu2 Firmware 2.29.22
Directory Traversal / Arbitrary File Read in User.getLanguage method in eQ-3 AG Homematic CCU2 2.29.2 and earlier allows remote attackers to read the first line of an arbitrary file on the CCU2's filesystem.
network
low complexity
eq-3 CWE-22
5.3
2018-02-21 CVE-2018-5716 Path Traversal vulnerability in Reprisesoftware Reprise License Manager 11.0
An issue was discovered in Reprise License Manager 11.0.
network
low complexity
reprisesoftware CWE-22
8.1
2018-02-20 CVE-2018-6356 Path Traversal vulnerability in multiple products
Jenkins before 2.107 and Jenkins LTS before 2.89.4 did not properly prevent specifying relative paths that escape a base directory for URLs accessing plugin resource files.
network
low complexity
jenkins oracle CWE-22
6.5
2018-02-19 CVE-2014-3972 Path Traversal vulnerability in Apexis Apm-J601-Ws Firmware
Directory traversal vulnerability in Apexis APM-J601-WS cameras with firmware before 17.35.2.49 allows remote attackers to read arbitrary files via unspecified vectors.
network
low complexity
apexis CWE-22
5.3
2018-02-19 CVE-2017-15712 Path Traversal vulnerability in Apache Oozie
Vulnerability allows a user of Apache Oozie 3.1.3-incubating to 4.3.0 and 5.0.0-beta1 to expose private files on the Oozie server process.
network
low complexity
apache CWE-22
6.5
2018-02-18 CVE-2018-7212 Path Traversal vulnerability in Sinatrarb Sinatra 2.0.0/2.0.1
An issue was discovered in rack-protection/lib/rack/protection/path_traversal.rb in Sinatra 2.x before 2.0.1 on Windows.
network
low complexity
sinatrarb CWE-22
5.3
2018-02-16 CVE-2017-14537 Path Traversal vulnerability in Netfortris Trixbox 2.8.0.4
trixbox 2.8.0.4 has path traversal via the xajaxargs array parameter to /maint/index.php?packages or the lang parameter to /maint/modules/home/index.php.
network
low complexity
netfortris CWE-22
6.5
2018-02-15 CVE-2017-8961 Path Traversal vulnerability in HP Intelligent Management Center 7.3
A directory traversal vulnerability in HPE Intelligent Management Center (IMC) PLAT 7.3 E0504P02 could allow remote code execution.
network
low complexity
hp CWE-22
8.8
2018-02-15 CVE-2017-8947 Path Traversal vulnerability in HP Ucmdb Configuration Manager
A Remote Code Execution vulnerability in HPE UCMDB version v10.10, v10.11, v10.20, v10.21, v10.22, v10.30, v10.31 was found.
network
low complexity
hp CWE-22
critical
9.8
2018-02-15 CVE-2017-12560 Path Traversal vulnerability in HP Intelligent Management Center 7.3
A Remote Denial of Service vulnerability in HPE Intelligent Management Center (iMC) PLAT version iMC Plat 7.3 E0504P2 was found.
network
low complexity
hp CWE-22
6.5