Vulnerabilities > Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')

DATE CVE VULNERABILITY TITLE RISK
2017-03-29 CVE-2017-7258 Path Traversal vulnerability in Auromeera Emli 1.0
HTTP Exploit in eMLi Portal in AuroMeera Technometrix Pvt.
network
low complexity
auromeera CWE-22
7.5
2017-03-27 CVE-2015-8309 Path Traversal vulnerability in Fomori Cherrymusic 0.35.2
Directory traversal vulnerability in Cherry Music before 0.36.0 allows remote authenticated users to read arbitrary files via the "value" parameter to "download."
network
low complexity
fomori CWE-22
4.3
2017-03-24 CVE-2017-7240 Path Traversal vulnerability in Miele Professional Pst10 Webserver
An issue was discovered on Miele Professional PST10 devices.
network
low complexity
miele-professional CWE-22
7.5
2017-03-24 CVE-2017-5869 Path Traversal vulnerability in Nuxeo
Directory traversal vulnerability in the file import feature in Nuxeo Platform 6.0, 7.1, 7.2, and 7.3 allows remote authenticated users to upload and execute arbitrary JSP code via a ..
network
low complexity
nuxeo CWE-22
8.8
2017-03-23 CVE-2016-10048 Path Traversal vulnerability in multiple products
Directory traversal vulnerability in magick/module.c in ImageMagick 6.9.4-7 allows remote attackers to load arbitrary modules via unspecified vectors.
network
low complexity
imagemagick opensuse-project CWE-22
7.5
2017-03-22 CVE-2017-3851 Path Traversal vulnerability in Cisco IOX 1.1.0/1.1(0)
A Directory Traversal vulnerability in the web framework code of the Cisco application-hosting framework (CAF) component of the Cisco IOx application environment could allow an unauthenticated, remote attacker to read any file from the CAF in the virtual instance running on the affected device.
network
low complexity
cisco CWE-22
7.5
2017-03-20 CVE-2017-6805 Path Traversal vulnerability in Mobatek Mobaxterm 9.4
Directory traversal vulnerability in the TFTP server in MobaXterm Personal Edition 9.4 allows remote attackers to read arbitrary files via a ..
network
low complexity
mobatek CWE-22
5.3
2017-03-17 CVE-2014-8704 Path Traversal vulnerability in Wondercms 2014
Directory traversal vulnerability in index.php in Wonder CMS 2014 allows remote attackers to include and execute arbitrary local files via a crafted theme.
network
low complexity
wondercms CWE-22
critical
9.8
2017-03-16 CVE-2017-6510 Path Traversal vulnerability in Efssoft Easy File Sharing FTP Server 3.6
Easy File Sharing FTP Server version 3.6 is vulnerable to a directory traversal vulnerability which allows an attacker to list and download any file from any folder outside the FTP root Directory.
network
low complexity
efssoft CWE-22
7.5
2017-03-14 CVE-2013-7462 Path Traversal vulnerability in Mcafee Saas Control Console Platform 6.15
A directory traversal vulnerability in the web application in McAfee (now Intel Security) SaaS Control Console (SCC) Platform 6.14 before patch 1070, and 6.15 before patch 1076 allows unauthenticated users to view contents of arbitrary system files that did not have file system level read access restrictions via a null-byte injection exploit.
network
low complexity
mcafee CWE-22
7.5