Vulnerabilities > Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')

DATE CVE VULNERABILITY TITLE RISK
2017-07-17 CVE-2017-11348 Path Traversal vulnerability in Octopus Deploy and Octopus Server
In Octopus Deploy 3.x before 3.15.4, an authenticated user with PackagePush permission to upload packages could upload a maliciously crafted NuGet package, potentially overwriting other packages or modifying system files.
network
low complexity
octopus CWE-22
5.7
2017-07-17 CVE-2017-1000062 Path Traversal vulnerability in Kitto Project Kitto 0.5.1
kittoframework kitto 0.5.1 is vulnerable to directory traversal in the router resulting in remote code execution
network
low complexity
kitto-project CWE-22
7.5
2017-07-17 CVE-2017-1000047 Path Traversal vulnerability in Rbenv Project Rbenv
rbenv (all current versions) is vulnerable to Directory Traversal in the specification of Ruby version resulting in arbitrary code execution
network
low complexity
rbenv-project CWE-22
critical
9.8
2017-07-17 CVE-2017-1000028 Path Traversal vulnerability in Oracle Glassfish Server 4.1
Oracle, GlassFish Server Open Source Edition 4.1 is vulnerable to both authenticated and unauthenticated Directory Traversal vulnerability, that can be exploited by issuing a specially crafted HTTP GET request.
network
low complexity
oracle CWE-22
7.5
2017-07-17 CVE-2017-1000026 Path Traversal vulnerability in Progress Mixlib-Archive 0.1.0/0.2.0/0.3.0
Chef Software's mixlib-archive versions 0.3.0 and older are vulnerable to a directory traversal attack allowing attackers to overwrite arbitrary files by using ".." in tar archive entries
network
low complexity
progress CWE-22
7.5
2017-07-17 CVE-2017-1000002 Path Traversal vulnerability in Atutor
ATutor versions 2.2.1 and earlier are vulnerable to a directory traversal and file extension check bypass in the Course component resulting in code execution.
network
low complexity
atutor CWE-22
critical
9.8
2017-07-09 CVE-2017-8003 Path Traversal vulnerability in EMC Data Protection Advisor
EMC Data Protection Advisor prior to 6.4 contains a path traversal vulnerability.
network
low complexity
emc CWE-22
4.9
2017-07-07 CVE-2014-7954 Path Traversal vulnerability in Google Android 4.4.4
Directory traversal vulnerability in the doSendObjectInfo method in frameworks/av/media/mtp/MtpServer.cpp in Android 4.4.4 allows physically proximate attackers with a direct connection to the target Android device to upload files outside of the sdcard via a ..
low complexity
google CWE-22
4.6
2017-07-07 CVE-2015-3297 Path Traversal vulnerability in Etherpad
Directory traversal vulnerability in node/utils/Minify.js in Etherpad 1.1.1 through 1.5.2 allows remote attackers to read arbitrary files by leveraging replacement of backslashes with slashes in the path parameter of HTTP API requests.
network
low complexity
etherpad CWE-22
7.5
2017-07-07 CVE-2017-2245 Path Traversal vulnerability in Getshortcodes Shortcodes Ultimate
Directory traversal vulnerability in Shortcodes Ultimate prior to version 4.10.0 allows remote attackers to read arbitrary files via unspecified vectors.
network
low complexity
getshortcodes CWE-22
5.0