Vulnerabilities > Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')

DATE CVE VULNERABILITY TITLE RISK
2017-07-17 CVE-2017-1000002 Path Traversal vulnerability in Atutor
ATutor versions 2.2.1 and earlier are vulnerable to a directory traversal and file extension check bypass in the Course component resulting in code execution.
network
low complexity
atutor CWE-22
7.5
2017-07-09 CVE-2017-8003 Path Traversal vulnerability in EMC Data Protection Advisor
EMC Data Protection Advisor prior to 6.4 contains a path traversal vulnerability.
network
low complexity
emc CWE-22
6.8
2017-07-07 CVE-2014-7954 Path Traversal vulnerability in Google Android 4.4.4
Directory traversal vulnerability in the doSendObjectInfo method in frameworks/av/media/mtp/MtpServer.cpp in Android 4.4.4 allows physically proximate attackers with a direct connection to the target Android device to upload files outside of the sdcard via a ..
local
low complexity
google CWE-22
2.1
2017-07-07 CVE-2015-3297 Path Traversal vulnerability in Etherpad
Directory traversal vulnerability in node/utils/Minify.js in Etherpad 1.1.1 through 1.5.2 allows remote attackers to read arbitrary files by leveraging replacement of backslashes with slashes in the path parameter of HTTP API requests.
network
low complexity
etherpad CWE-22
5.0
2017-07-07 CVE-2017-2245 Path Traversal vulnerability in Getshortcodes Shortcodes Ultimate
Directory traversal vulnerability in Shortcodes Ultimate prior to version 4.10.0 allows remote attackers to read arbitrary files via unspecified vectors.
network
low complexity
getshortcodes CWE-22
4.0
2017-07-07 CVE-2017-10974 Path Traversal vulnerability in Yaws 1.91
Yaws 1.91 allows Unauthenticated Remote File Disclosure via HTTP Directory Traversal with /%5C../ to port 8080.
network
low complexity
yaws CWE-22
5.0
2017-07-04 CVE-2017-6704 Path Traversal vulnerability in Cisco Prime Collaboration Provisioning 12.1
A vulnerability in the web application in the Cisco Prime Collaboration Provisioning tool could allow an authenticated, remote attacker to perform arbitrary file downloads that could allow the attacker to read files from the underlying filesystem.
network
low complexity
cisco CWE-22
4.0
2017-06-27 CVE-2015-7780 Path Traversal vulnerability in Zohocorp Manageengine Firewall Analyzer 7.2/7.4/7.6
Directory traversal vulnerability in ManageEngine Firewall Analyzer before 8.0.
network
low complexity
zohocorp CWE-22
4.0
2017-06-24 CVE-2017-9846 Path Traversal vulnerability in Magicwinmail Winmail Server 6.1
Winmail Server 6.1 allows remote code execution by authenticated users who leverage directory traversal in a netdisk.php move_folder_file call to move a .php file from the FTP folder into a web folder.
network
low complexity
magicwinmail CWE-22
6.5
2017-06-24 CVE-2017-9833 Path Traversal vulnerability in BOA 0.94.14.21
/cgi-bin/wapopen in Boa 0.94.14rc21 allows the injection of "../.." using the FILECAMERA variable (sent by GET) to read files with root privileges.
network
low complexity
boa CWE-22
7.5