Vulnerabilities > Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')

DATE CVE VULNERABILITY TITLE RISK
2017-01-23 CVE-2016-6600 Path Traversal vulnerability in Zohocorp Webnms Framework 5.2
Directory traversal vulnerability in the file upload functionality in ZOHO WebNMS Framework 5.2 and 5.2 SP1 allows remote attackers to upload and execute arbitrary JSP files via a ..
network
low complexity
zohocorp CWE-22
critical
9.8
2017-01-23 CVE-2016-6517 Path Traversal vulnerability in Liferay 5.1.0
Directory traversal vulnerability in Liferay 5.1.0 allows remote attackers to have unspecified impact via a %2E%2E (encoded dot dot) in the minifierBundleDir parameter to barebone.jsp.
network
low complexity
liferay CWE-22
critical
9.8
2017-01-23 CVE-2017-5539 Path Traversal vulnerability in B2Evolution 6.8.4
The patch for directory traversal (CVE-2017-5480) in b2evolution version 6.8.4-stable has a bypass vulnerability.
network
low complexity
b2evolution CWE-22
critical
9.1
2017-01-20 CVE-2017-5541 Path Traversal vulnerability in Getsymphony Symphony
Directory traversal vulnerability in template/usererror.missing_extension.php in Symphony CMS before 2.6.10 allows remote attackers to rename arbitrary files via a ..
network
low complexity
getsymphony CWE-22
5.3
2017-01-19 CVE-2016-5725 Path Traversal vulnerability in Jcraft Jsch
Directory traversal vulnerability in JCraft JSch before 0.1.54 on Windows, when the mode is ChannelSftp.OVERWRITE, allows remote SFTP servers to write to arbitrary files via a ..\ (dot dot backslash) in a response to a recursive GET command.
network
high complexity
jcraft CWE-22
5.9
2017-01-18 CVE-2016-6896 Path Traversal vulnerability in Wordpress 4.5.3
Directory traversal vulnerability in the wp_ajax_update_plugin function in wp-admin/includes/ajax-actions.php in WordPress 4.5.3 allows remote authenticated users to cause a denial of service or read certain text files via a ..
network
low complexity
wordpress CWE-22
7.1
2017-01-18 CVE-2016-7982 Path Traversal vulnerability in Spip
Directory traversal vulnerability in ecrire/exec/valider_xml.php in SPIP 3.1.2 and earlier allows remote attackers to enumerate the files on the system via the var_url parameter in a valider_xml action.
network
low complexity
spip CWE-22
7.5
2017-01-18 CVE-2016-2087 Path Traversal vulnerability in Hexchat Project Hexchat 2.11.0
Directory traversal vulnerability in the client in HexChat 2.11.0 allows remote IRC servers to read or modify arbitrary files via a ..
network
high complexity
hexchat-project CWE-22
7.4
2017-01-15 CVE-2017-5480 Path Traversal vulnerability in B2Evolution
Directory traversal vulnerability in inc/files/files.ctrl.php in b2evolution through 6.8.3 allows remote authenticated users to read or delete arbitrary files by leveraging back-office access to provide a ..
network
low complexity
b2evolution CWE-22
8.1
2017-01-14 CVE-2016-8207 Path Traversal vulnerability in Brocade Network Advisor 11.0.0.0/11.0.2.0
A Directory Traversal vulnerability in CliMonitorReportServlet in the Brocade Network Advisor versions released prior to and including 14.0.2 could allow remote attackers to read arbitrary files including files with sensitive user information.
network
low complexity
brocade CWE-22
7.5