Vulnerabilities > Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')

DATE CVE VULNERABILITY TITLE RISK
2014-03-11 CVE-2013-4413 Path Traversal vulnerability in Schneems Wicked
Directory traversal vulnerability in controller/concerns/render_redirect.rb in the Wicked gem before 1.0.1 for Ruby allows remote attackers to read arbitrary files via a %2E%2E%2F (encoded dot dot slash) in the step.
network
low complexity
schneems ruby-lang CWE-22
5.0
2014-03-09 CVE-2014-2314 Path Traversal vulnerability in Atlassian Jira
Directory traversal vulnerability in the Issue Collector plugin in Atlassian JIRA before 6.0.4 allows remote attackers to create arbitrary files via unspecified vectors.
4.3
2014-03-09 CVE-2014-2313 Path Traversal vulnerability in Atlassian Jira
Directory traversal vulnerability in the Importers plugin in Atlassian JIRA before 6.0.5 allows remote attackers to create arbitrary files via unspecified vectors.
4.3
2014-03-06 CVE-2014-1907 Path Traversal vulnerability in Videowhisper Live Streaming Integration Plugin
Multiple directory traversal vulnerabilities in the VideoWhisper Live Streaming Integration plugin before 4.29.5 for WordPress allow remote attackers to (1) read arbitrary files via a ..
network
low complexity
videowhisper wordpress CWE-22
6.4
2014-03-06 CVE-2013-6720 Path Traversal vulnerability in IBM Tealeaf CX
Directory traversal vulnerability in download.php in the Passive Capture Application (PCA) web console in IBM Tealeaf CX 7.x, 8.x through 8.6, 8.7 before FP2, and 8.8 before FP2 allows remote authenticated users to bypass intended access restrictions via a ..
network
low complexity
ibm CWE-22
5.5
2014-03-06 CVE-2013-6304 Path Traversal vulnerability in IBM Algo ONE and Algo Risk Application
Multiple directory traversal vulnerabilities in Algo Risk Application (ARA) 2.4.0.1 through 4.9.1 in IBM Algo One allow remote authenticated users to bypass intended access restrictions via a crafted pathname for a (1) configuration or (2) JAR file.
network
low complexity
ibm CWE-22
4.0
2014-03-06 CVE-2013-3706 Path Traversal vulnerability in Novell Zenworks Configuration Management 11.2
Directory traversal vulnerability in the PreBoot service in Novell ZENworks Configuration Management (ZCM) 11.2 allows remote attackers to read arbitrary files via a ..
network
low complexity
novell CWE-22
5.0
2014-03-05 CVE-2013-6303 Path Traversal vulnerability in IBM Algo ONE
Directory traversal vulnerability in IBM Algo One, as used in MetaData Management Tools in UDS 4.7.0 through 5.0.0, ACSWeb in Algo Security Access Control Management 4.7.0 through 4.9.0, and ACSWeb in AlgoWebApps 5.0.0, allows remote authenticated users to read arbitrary files via unspecified vectors.
network
low complexity
ibm CWE-22
4.0
2014-03-03 CVE-2011-4696 Path Traversal vulnerability in EYE Eye-Fi Helper
Directory traversal vulnerability in Eye-Fi Helper before 3.4.23 allows man-in-the-middle attackers to create arbitrary files via a ..
4.3
2014-03-02 CVE-2013-4054 Path Traversal vulnerability in IBM Websphere MQ 7.5/7.5.0.1/7.5.0.2
Directory traversal vulnerability in WMQ Telemetry in IBM WebSphere MQ 7.5 before 7.5.0.3 allows remote attackers to read arbitrary files via a crafted URI.
network
ibm CWE-22
4.3