Vulnerabilities > Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')

DATE CVE VULNERABILITY TITLE RISK
2017-04-10 CVE-2016-4320 Path Traversal vulnerability in Atlassian Bitbucket
Atlassian Bitbucket Server before 4.7.1 allows remote attackers to read the first line of an arbitrary file via a directory traversal attack on the pull requests resource.
network
low complexity
atlassian CWE-22
4.3
2017-04-10 CVE-2015-7270 Path Traversal vulnerability in Dell Integrated Remote Access Controller Firmware 1.99/2.20.20.20
Dell Integrated Remote Access Controller (iDRAC) 6 before 2.80 and 7/8 before 2.21.21.21 allows directory traversal.
local
low complexity
dell CWE-22
7.8
2017-04-07 CVE-2017-7577 Path Traversal vulnerability in Xiongmaitech Uc-Httpd
XiongMai uc-httpd has directory traversal allowing the reading of arbitrary files via a "GET ../" HTTP request.
network
low complexity
xiongmaitech CWE-22
critical
9.8
2017-04-06 CVE-2017-7565 Path Traversal vulnerability in Splunk Hadoop Connect
Splunk Hadoop Connect App has a path traversal vulnerability that allows remote authenticated users to execute arbitrary code, aka ERP-2041.
network
low complexity
splunk CWE-22
8.8
2017-04-05 CVE-2017-7358 Path Traversal vulnerability in multiple products
In LightDM through 1.22.0, a directory traversal issue in debian/guest-account.sh allows local attackers to own arbitrary directory path locations and escalate privileges to root when the guest user logs out.
local
low complexity
lightdm-project canonical CWE-22
7.3
2017-03-29 CVE-2017-4980 Path Traversal vulnerability in EMC Isilon Onefs
EMC Isilon OneFS is affected by a path traversal vulnerability that may potentially be exploited by attackers to compromise the affected system.
network
low complexity
emc CWE-22
7.5
2017-03-29 CVE-2017-7258 Path Traversal vulnerability in Auromeera Emli 1.0
HTTP Exploit in eMLi Portal in AuroMeera Technometrix Pvt.
network
low complexity
auromeera CWE-22
7.5
2017-03-27 CVE-2015-8309 Path Traversal vulnerability in Fomori Cherrymusic 0.35.2
Directory traversal vulnerability in Cherry Music before 0.36.0 allows remote authenticated users to read arbitrary files via the "value" parameter to "download."
network
low complexity
fomori CWE-22
4.3
2017-03-24 CVE-2017-7240 Path Traversal vulnerability in Miele Professional Pst10 Webserver
An issue was discovered on Miele Professional PST10 devices.
network
low complexity
miele-professional CWE-22
7.5
2017-03-24 CVE-2017-5869 Path Traversal vulnerability in Nuxeo
Directory traversal vulnerability in the file import feature in Nuxeo Platform 6.0, 7.1, 7.2, and 7.3 allows remote authenticated users to upload and execute arbitrary JSP code via a ..
network
low complexity
nuxeo CWE-22
8.8