Vulnerabilities > Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')

DATE CVE VULNERABILITY TITLE RISK
2014-05-07 CVE-2014-0130 Path Traversal vulnerability in multiple products
Directory traversal vulnerability in actionpack/lib/abstract_controller/base.rb in the implicit-render implementation in Ruby on Rails before 3.2.18, 4.0.x before 4.0.5, and 4.1.x before 4.1.1, when certain route globbing configurations are enabled, allows remote attackers to read arbitrary files via a crafted request.
network
low complexity
redhat rubyonrails CWE-22
7.5
2014-04-25 CVE-2014-0780 Path Traversal vulnerability in Indusoft web Studio 7.1
Directory traversal vulnerability in NTWebServer in InduSoft Web Studio 7.1 before SP2 Patch 4 allows remote attackers to read administrative passwords in APP files, and consequently execute arbitrary code, via unspecified web requests.
network
low complexity
indusoft CWE-22
critical
9.8
2010-08-11 CVE-2010-2861 Path Traversal vulnerability in Adobe Coldfusion
Multiple directory traversal vulnerabilities in the administrator console in Adobe ColdFusion 9.0.1 and earlier allow remote attackers to read arbitrary files via the locale parameter to (1) CFIDE/administrator/settings/mappings.cfm, (2) logging/settings.cfm, (3) datasources/index.cfm, (4) j2eepackaging/editarchive.cfm, and (5) enter.cfm in CFIDE/administrator/.
network
low complexity
adobe CWE-22
critical
9.8
2010-02-02 CVE-2010-0467 Path Traversal vulnerability in Chillcreations COM Ccnewsletter 1.0.5
Directory traversal vulnerability in the ccNewsletter (com_ccnewsletter) component 1.0.5 for Joomla! allows remote attackers to read arbitrary files via a ..
network
low complexity
chillcreations CWE-22
5.8
2010-02-02 CVE-2009-4013 Path Traversal vulnerability in multiple products
Multiple directory traversal vulnerabilities in Lintian 1.23.x through 1.23.28, 1.24.x through 1.24.2.1, and 2.x before 2.3.2 allow remote attackers to overwrite arbitrary files or obtain sensitive information via vectors involving (1) control field names, (2) control field values, and (3) control files of patch systems.
network
low complexity
debian canonical CWE-22
critical
9.8
2010-01-09 CVE-2010-0013 Path Traversal vulnerability in multiple products
Directory traversal vulnerability in slp.c in the MSN protocol plugin in libpurple in Pidgin 2.6.4 and Adium 1.3.8 allows remote attackers to read arbitrary files via a ..
7.5
2010-01-08 CVE-2010-0012 Path Traversal vulnerability in multiple products
Directory traversal vulnerability in libtransmission/metainfo.c in Transmission 1.22, 1.34, 1.75, and 1.76 allows remote attackers to overwrite arbitrary files via a ..
network
low complexity
transmissionbt debian opensuse CWE-22
8.8
2010-01-06 CVE-2009-4581 Path Traversal vulnerability in Roseonlinecms
Directory traversal vulnerability in modules/admincp.php in RoseOnlineCMS 3 B1 and earlier, when magic_quotes_gpc is disabled, allows remote attackers to include and execute arbitrary local files via directory traversal sequences in the admin parameter.
network
low complexity
roseonlinecms CWE-22
critical
9.8
2009-12-29 CVE-2009-4449 Path Traversal vulnerability in Mybboard Mybb 1.4.10
Directory traversal vulnerability in MyBB (aka MyBulletinBoard) 1.4.10, and possibly earlier versions, when changing the user avatar from the gallery, allows remote authenticated users to determine the existence of files via directory traversal sequences in the avatar and possibly the gallery parameters, related to (1) admin/modules/user/users.php and (2) usercp.php.
network
low complexity
mybboard CWE-22
6.5
2009-12-03 CVE-2009-4194 Path Traversal vulnerability in Kmint21 Golden FTP Server 4.30/4.50
Directory traversal vulnerability in Golden FTP Server 4.30 Free and Professional, 4.50, and possibly other versions allows remote authenticated users to delete arbitrary files via a ..
network
low complexity
kmint21 CWE-22
8.1