Vulnerabilities > Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')

DATE CVE VULNERABILITY TITLE RISK
2016-12-29 CVE-2016-7087 Path Traversal vulnerability in VMWare Horizon View
Directory traversal vulnerability in the Connection Server in VMware Horizon View 5.x before 5.3.7, 6.x before 6.2.3, and 7.x before 7.0.1 allows remote attackers to obtain sensitive information via unspecified vectors.
network
low complexity
vmware microsoft CWE-22
5.0
2016-12-24 CVE-2016-10039 Path Traversal vulnerability in Modx Revolution
Directory traversal in /connectors/index.php in MODX Revolution before 2.5.2-pl allows remote attackers to perform local file inclusion/traversal/manipulation via a crafted dir parameter, related to browser/directory/getfiles.
network
low complexity
modx CWE-22
7.5
2016-12-24 CVE-2016-10038 Path Traversal vulnerability in Modx Revolution
Directory traversal in /connectors/index.php in MODX Revolution before 2.5.2-pl allows remote attackers to perform local file inclusion/traversal/manipulation via a crafted dir parameter, related to browser/directory/remove.
network
low complexity
modx CWE-22
7.5
2016-12-24 CVE-2016-10037 Path Traversal vulnerability in Modx Revolution
Directory traversal in /connectors/index.php in MODX Revolution before 2.5.2-pl allows remote attackers to perform local file inclusion/traversal/manipulation via a crafted id (aka dir) parameter, related to browser/directory/getlist.
network
low complexity
modx CWE-22
7.5
2016-12-17 CVE-2016-9950 Path Traversal vulnerability in multiple products
An issue was discovered in Apport before 2.20.4.
network
apport-project canonical CWE-22
critical
9.3
2016-12-16 CVE-2016-8827 Path Traversal vulnerability in Nvidia Geforce Experience
NVIDIA GeForce Experience 3.x before GFE 3.1.0.52 contains a vulnerability in NVIDIA Web Helper.exe where a local web API endpoint, /VisualOPS/v.1.0./, lacks proper access control and parameter validation, allowing for information disclosure via a directory traversal attack.
network
low complexity
nvidia CWE-22
5.0
2016-12-14 CVE-2016-9210 Path Traversal vulnerability in Cisco Unified Communications Manager 11.5(1.11007.2)
A vulnerability in the Cisco Unified Reporting upload tool accessed via the Cisco Unified Communications Manager could allow an unauthenticated, remote attacker to modify arbitrary files on the file system.
network
low complexity
cisco CWE-22
5.0
2016-12-14 CVE-2016-9208 Path Traversal vulnerability in Cisco Emergency Responder 11.5(2.10000.5)
A vulnerability in the File Management Utility, the Download File form, and the Serviceability application of Cisco Emergency Responder could allow an authenticated, remote attacker to access files in arbitrary locations on the file system of an affected device.
network
low complexity
cisco CWE-22
4.0
2016-12-14 CVE-2016-9199 Path Traversal vulnerability in Cisco IOX 1.1.0
A vulnerability in the Cisco application-hosting framework (CAF) of Cisco IOx could allow an authenticated, remote attacker to read arbitrary files on a targeted system.
network
low complexity
cisco CWE-22
6.8
2016-12-11 CVE-2016-6614 Path Traversal vulnerability in PHPmyadmin
An issue was discovered in phpMyAdmin involving the %u username replacement functionality of the SaveDir and UploadDir features.
network
phpmyadmin CWE-22
4.3