Vulnerabilities > Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
DATE | CVE | VULNERABILITY TITLE | RISK |
---|---|---|---|
2017-12-01 | CVE-2017-10861 | Path Traversal vulnerability in Qualitysoft QND Advance/Standard Directory traversal vulnerability in QND Advance/Standard allows an attacker to read arbitrary files via a specially crafted command. | 9.1 |
2017-12-01 | CVE-2017-15607 | Path Traversal vulnerability in Inedo Otter Inedo Otter before 1.7.4 has directory traversal in filesystem-based rafts via vectors involving '/' characters or initial '.' characters, aka OT-181. | 9.8 |
2017-11-30 | CVE-2017-14196 | Path Traversal vulnerability in Squiz Matrix An issue was discovered in Squiz Matrix from 5.3 through to 5.3.6.1 and 5.4.1.3. | 7.5 |
2017-11-29 | CVE-2017-17058 | Path Traversal vulnerability in Automattic Woocommerce The WooCommerce plugin through 3.x for WordPress has a Directory Traversal Vulnerability via a /wp-content/plugins/woocommerce/templates/emails/plain/ URI, which accesses a parent directory. | 7.5 |
2017-11-28 | CVE-2017-17042 | Path Traversal vulnerability in Yardoc Yard lib/yard/core_ext/file.rb in the server in YARD before 0.9.11 does not block relative paths with an initial ../ sequence, which allows attackers to conduct directory traversal attacks and read arbitrary files. | 7.5 |
2017-11-27 | CVE-2017-16959 | Path Traversal vulnerability in Tp-Link products The locale feature in cgi-bin/luci on TP-Link TL-WVR, TL-WAR, TL-ER, and TL-R devices allows remote authenticated users to test for the existence of arbitrary files by making an operation=write;locale=%0d request, and then making an operation=read request with a crafted Accept-Language HTTP header, related to the set_sysinfo and get_sysinfo functions in /usr/lib/lua/luci/controller/locale.lua in uhttpd. | 6.5 |
2017-11-24 | CVE-2017-16936 | Path Traversal vulnerability in Tenda Ac15 Firmware, Ac18 Firmware and AC9 Firmware Directory Traversal vulnerability in app_data_center on Shenzhen Tenda Ac9 US_AC9V1.0BR_V15.03.05.14_multi_TD01, Ac9 ac9_kf_V15.03.05.19(6318_)_cn, Ac15 US_AC15V1.0BR_V15.03.05.18_multi_TD01, Ac15 US_AC15V1.0BR_V15.03.05.19_multi_TD01, Ac18 US_AC18V1.0BR_V15.03.05.05_multi_TD01, and Ac18 ac18_kf_V15.03.05.19(6318_)_cn devices allows remote unauthenticated attackers to read arbitrary files via a cgi-bin/luci/request?op=1&path= URI that uses directory traversal sequences after a /usb/ substring. | 6.5 |
2017-11-22 | CVE-2017-8189 | Path Traversal vulnerability in Huawei Fusionsphere Openstack V100R006C00Spc102(Nfv) FusionSphere OpenStack V100R006C00SPC102(NFV)has a path traversal vulnerability. | 6.0 |
2017-11-22 | CVE-2017-2706 | Path Traversal vulnerability in Huawei Mate 9 Firmware Mate 9 smartphones with software MHA-AL00AC00B125 have a directory traversal vulnerability in Push module. | 7.1 |
2017-11-22 | CVE-2017-2695 | Path Traversal vulnerability in Huawei Tit-Al00 Firmware C583B211 TIT-AL00C583B211 has a directory traversal vulnerability which allows an attacker to obtain the files in email application. | 5.5 |