Vulnerabilities > Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')

DATE CVE VULNERABILITY TITLE RISK
2017-09-03 CVE-2017-14120 Path Traversal vulnerability in multiple products
unrar 0.0.1 (aka unrar-free or unrar-gpl) suffers from a directory traversal vulnerability for RAR v2 archives: pathnames of the form ../[filename] are unpacked into the upper directory.
network
low complexity
rarlab debian CWE-22
7.5
2017-08-31 CVE-2014-8676 Path Traversal vulnerability in Soplanning
Directory traversal vulnerability in the file_get_contents function in SOPlanning 1.32 and earlier allows remote attackers to determine the existence of arbitrary files via a ..
network
low complexity
soplanning CWE-22
5.3
2017-08-30 CVE-2017-13780 Path Traversal vulnerability in Eyesofnetwork 5.10
The EyesOfNetwork web interface (aka eonweb) 5.1-0 allows directory traversal attacks for reading arbitrary files via the module/admin_conf/download.php file parameter.
network
low complexity
eyesofnetwork CWE-22
7.5
2017-08-30 CVE-2017-3163 Path Traversal vulnerability in Apache Solr
When using the Index Replication feature, Apache Solr nodes can pull index files from a master/leader node using an HTTP API which accepts a file name.
network
low complexity
apache CWE-22
7.5
2017-08-29 CVE-2017-2258 Path Traversal vulnerability in Cybozu Garoon 4.2.4/4.2.5
Directory traversal vulnerability in Cybozu Garoon 4.2.4 to 4.2.5 allows an attacker to read arbitrary files via Garoon SOAP API "WorkflowHandleApplications".
network
low complexity
cybozu CWE-22
4.3
2017-08-29 CVE-2017-10841 Path Traversal vulnerability in Webcalendar Project Webcalendar 1.2.7
Directory traversal vulnerability in WebCalendar 1.2.7 and earlier allows authenticated attackers to read arbitrary files via unspecified vectors.
network
low complexity
webcalendar-project CWE-22
4.9
2017-08-29 CVE-2017-10834 Path Traversal vulnerability in Nippon-Antenna Scr02Hd Firmware 1.0.3.1000
Directory traversal vulnerability in "Dokodemo eye Smart HD" SCR02HD Firmware 1.0.3.1000 and earlier allows authenticated attackers to read arbitrary files via unspecified vectors.
network
low complexity
nippon-antenna CWE-22
6.5
2017-08-28 CVE-2014-8163 Path Traversal vulnerability in Redhat Satellite 5.0
Directory traversal vulnerability in the XMLRPC interface in Red Hat Satellite 5.
network
low complexity
redhat CWE-22
6.5
2017-08-28 CVE-2015-1876 Path Traversal vulnerability in Estrongs ES File Explorer 3.2.4.1
Directory traversal vulnerability in ES File Explorer 3.2.4.1.
network
low complexity
estrongs CWE-22
7.5
2017-08-28 CVE-2015-1386 Path Traversal vulnerability in Unshield Project Unshield 1.01
Directory traversal vulnerability in unshield 1.0-1.
network
low complexity
unshield-project CWE-22
7.5