Vulnerabilities > Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')

DATE CVE VULNERABILITY TITLE RISK
2017-01-30 CVE-2016-10184 Path Traversal vulnerability in Dlink Dwr-932B Firmware 02.02Eu
An issue was discovered on the D-Link DWR-932B router.
network
low complexity
dlink CWE-22
7.5
2017-01-30 CVE-2016-10183 Path Traversal vulnerability in Dlink Dwr-932B Firmware 02.02Eu
An issue was discovered on the D-Link DWR-932B router.
network
low complexity
dlink CWE-22
7.5
2017-01-27 CVE-2016-7569 Path Traversal vulnerability in Docker2Aci Project Docker2Aci
Directory traversal vulnerability in docker2aci before 0.13.0 allows remote attackers to write to arbitrary files via a ..
local
low complexity
docker2aci-project CWE-22
5.5
2017-01-23 CVE-2016-6601 Path Traversal vulnerability in Zohocorp Webnms Framework 5.2
Directory traversal vulnerability in the file download functionality in ZOHO WebNMS Framework 5.2 and 5.2 SP1 allows remote attackers to read arbitrary files via a ..
network
low complexity
zohocorp CWE-22
7.5
2017-01-23 CVE-2016-6600 Path Traversal vulnerability in Zohocorp Webnms Framework 5.2
Directory traversal vulnerability in the file upload functionality in ZOHO WebNMS Framework 5.2 and 5.2 SP1 allows remote attackers to upload and execute arbitrary JSP files via a ..
network
low complexity
zohocorp CWE-22
critical
9.8
2017-01-23 CVE-2016-6517 Path Traversal vulnerability in Liferay 5.1.0
Directory traversal vulnerability in Liferay 5.1.0 allows remote attackers to have unspecified impact via a %2E%2E (encoded dot dot) in the minifierBundleDir parameter to barebone.jsp.
network
low complexity
liferay CWE-22
critical
9.8
2017-01-23 CVE-2017-5539 Path Traversal vulnerability in B2Evolution 6.8.4
The patch for directory traversal (CVE-2017-5480) in b2evolution version 6.8.4-stable has a bypass vulnerability.
network
low complexity
b2evolution CWE-22
critical
9.1
2017-01-20 CVE-2017-5541 Path Traversal vulnerability in Getsymphony Symphony
Directory traversal vulnerability in template/usererror.missing_extension.php in Symphony CMS before 2.6.10 allows remote attackers to rename arbitrary files via a ..
network
low complexity
getsymphony CWE-22
5.3
2017-01-19 CVE-2016-5725 Path Traversal vulnerability in Jcraft Jsch
Directory traversal vulnerability in JCraft JSch before 0.1.54 on Windows, when the mode is ChannelSftp.OVERWRITE, allows remote SFTP servers to write to arbitrary files via a ..\ (dot dot backslash) in a response to a recursive GET command.
network
high complexity
jcraft CWE-22
5.9
2017-01-18 CVE-2016-6896 Path Traversal vulnerability in Wordpress 4.5.3
Directory traversal vulnerability in the wp_ajax_update_plugin function in wp-admin/includes/ajax-actions.php in WordPress 4.5.3 allows remote authenticated users to cause a denial of service or read certain text files via a ..
network
low complexity
wordpress CWE-22
7.1