Vulnerabilities > Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')

DATE CVE VULNERABILITY TITLE RISK
2017-06-21 CVE-2017-2829 Path Traversal vulnerability in Foscam C1 Indoor HD Camera Firmware 2.52.2.37
An exploitable directory traversal vulnerability exists in the web management interface used by the Foscam C1 Indoor HD Camera running application firmware 2.52.2.37.
network
low complexity
foscam CWE-22
6.5
2017-06-16 CVE-2017-9097 Path Traversal vulnerability in Hoytech Antiweb
In Anti-Web through 3.8.7, as used on NetBiter FGW200 devices through 3.21.2, WS100 devices through 3.30.5, EC150 devices through 1.40.0, WS200 devices through 3.30.4, EC250 devices through 1.40.0, and other products, an LFI vulnerability allows a remote attacker to read or modify files through a path traversal technique, as demonstrated by reading the password file, or using the template parameter to cgi-bin/write.cgi to write to an arbitrary file.
network
low complexity
hoytech CWE-22
critical
9.1
2017-06-09 CVE-2016-7826 Path Traversal vulnerability in Buffalotech Wnc01Wh Firmware 1.0.0.8
Directory traversal vulnerability in Buffalo WNC01WH devices with firmware version 1.0.0.8 and earlier allows authenticated attackers to read arbitrary files via specially crafted POST requests.
network
low complexity
buffalotech CWE-22
6.5
2017-06-09 CVE-2016-7825 Path Traversal vulnerability in Buffalotech Wnc01Wh Firmware 1.0.0.8
Directory traversal vulnerability in Buffalo WNC01WH devices with firmware version 1.0.0.8 and earlier allows authenticated attackers to read arbitrary files via specially crafted commands.
network
low complexity
buffalotech CWE-22
6.5
2017-06-09 CVE-2016-7802 Path Traversal vulnerability in Cybozu Garoon
Directory traversal vulnerability in Cybozu Garoon 3.0.0 to 4.2.2 allows remote authenticated attackers to read arbitrary files via unspecified vectors.
network
low complexity
cybozu CWE-22
6.5
2017-06-07 CVE-2015-8235 Path Traversal vulnerability in Call-Cc Spiffy
Directory traversal vulnerability in Spiffy before 5.4.
network
low complexity
call-cc CWE-22
7.5
2017-06-07 CVE-2015-7888 Path Traversal vulnerability in Samsung Galaxy S6 Edge Firmware G925Vvru1Aoe2
Directory traversal vulnerability in the WifiHs20UtilityService on the Samsung S6 Edge LRX22G.G925VVRU1AOE2 allows remote attackers to overwrite or create arbitrary files as the system-level user via a ..
network
low complexity
samsung CWE-22
7.5
2017-06-05 CVE-2017-8841 Path Traversal vulnerability in Peplink products
Arbitrary file deletion exists on Peplink Balance 305, 380, 580, 710, 1350, and 2500 devices with firmware before fw-b305hw2_380hw6_580hw2_710hw3_1350hw2_2500-7.0.1-build2093.
network
low complexity
peplink CWE-22
8.1
2017-06-04 CVE-2017-9428 Path Traversal vulnerability in Bigtreecms Bigtree CMS
A directory traversal vulnerability exists in core\admin\ajax\developer\extensions\file-browser.php in BigTree CMS through 4.2.18 on Windows, allowing attackers to read arbitrary files via ..\ sequences in the directory parameter.
network
low complexity
bigtreecms CWE-22
7.5
2017-06-04 CVE-2014-9983 Path Traversal vulnerability in Rarlab RAR
Directory Traversal exists in RAR 4.x and 5.x because an unpack operation follows any symlinks, including symlinks contained in the archive.
local
low complexity
rarlab CWE-22
5.5