Vulnerabilities > Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')

DATE CVE VULNERABILITY TITLE RISK
2018-02-15 CVE-2017-8961 Path Traversal vulnerability in HP Intelligent Management Center 7.3
A directory traversal vulnerability in HPE Intelligent Management Center (IMC) PLAT 7.3 E0504P02 could allow remote code execution.
network
low complexity
hp CWE-22
8.8
2018-02-15 CVE-2017-8947 Path Traversal vulnerability in HP Ucmdb Configuration Manager
A Remote Code Execution vulnerability in HPE UCMDB version v10.10, v10.11, v10.20, v10.21, v10.22, v10.30, v10.31 was found.
network
low complexity
hp CWE-22
critical
9.8
2018-02-15 CVE-2017-12560 Path Traversal vulnerability in HP Intelligent Management Center 7.3
A Remote Denial of Service vulnerability in HPE Intelligent Management Center (iMC) PLAT version iMC Plat 7.3 E0504P2 was found.
network
low complexity
hp CWE-22
6.5
2018-02-15 CVE-2017-12559 Path Traversal vulnerability in HP Intelligent Management Center 7.3
A Remote Denial of Service vulnerability in HPE Intelligent Management Center (iMC) PLAT version iMC Plat 7.3 E0504P2 was found.
network
low complexity
hp CWE-22
6.5
2018-02-08 CVE-2018-0123 Path Traversal vulnerability in Cisco IOS and IOS XE
A Path Traversal vulnerability in the diagnostic shell for Cisco IOS and IOS XE Software could allow an authenticated, local attacker to use certain diagnostic shell commands that can overwrite system files.
local
low complexity
cisco CWE-22
5.5
2018-02-06 CVE-2018-1299 Path Traversal vulnerability in Apache Allura
In Apache Allura before 1.8.0, unauthenticated attackers may retrieve arbitrary files through the Allura web application.
network
low complexity
apache CWE-22
7.5
2018-02-05 CVE-2015-4461 Path Traversal vulnerability in Efrontlearning Efront
Absolute path traversal vulnerability in eFront CMS 3.6.15.4 and earlier allows remote Professor users to obtain sensitive information via a full pathname in the other parameter.
network
low complexity
efrontlearning CWE-22
6.5
2018-02-03 CVE-2017-17108 Path Traversal vulnerability in Konakart
Path traversal vulnerability in the administrative panel in KonaKart eCommerce Platform version 8.7 and earlier could allow an attacker to download system files, as well as upload specially crafted JSP files and in turn gain access to the server.
network
low complexity
konakart CWE-22
critical
9.8
2018-02-02 CVE-2017-18038 Path Traversal vulnerability in Atlassian Bitbucket
The repository settings resource in Atlassian Bitbucket Server before version 5.6.0 allows remote attackers to read the first line of arbitrary files via a path traversal vulnerability through the default branch name.
network
low complexity
atlassian CWE-22
5.3
2018-02-02 CVE-2017-18037 Path Traversal vulnerability in Atlassian Bitbucket
The git repository tag rest resource in Atlassian Bitbucket Server from version 3.7.0 before 4.14.11 (the fixed version for 4.14.x), from version 5.0.0 before 5.0.9 (the fixed version for 5.0.x), from version 5.1.0 before 5.1.8 (the fixed version for 5.1.x), from version 5.2.0 before 5.2.6 (the fixed version for 5.2.x), from version 5.3.0 before 5.3.4 (the fixed version for 5.3.x), from version 5.4.0 before 5.4.2 (the fixed version for 5.4.x), from version 5.5.0 before 5.5.1 (the fixed version for 5.5.x) and before 5.6.0 allows remote attackers to read arbitrary files via a path traversal vulnerability through the name of a git tag.
network
low complexity
atlassian CWE-22
6.5