Vulnerabilities > Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')

DATE CVE VULNERABILITY TITLE RISK
2012-02-23 CVE-2012-1289 Path Traversal vulnerability in SAP Netweaver 7.0
Multiple directory traversal vulnerabilities in SAP NetWeaver 7.0 allow remote authenticated users to read arbitrary files via a ..
network
low complexity
sap CWE-22
4.0
2012-02-21 CVE-2012-1221 Path Traversal vulnerability in Rabidhamster R2/ and R2/Extreme
Directory traversal vulnerability in the telnet server in RabidHamster R2/Extreme 1.65 and earlier allows remote attackers to read arbitrary files via a ..
network
low complexity
rabidhamster CWE-22
5.0
2012-02-18 CVE-2012-1196 Path Traversal vulnerability in Landesk Lenovo Thinkmanagement Console 9.0.3
Directory traversal vulnerability in the VulCore web service (WSVulnerabilityCore/VulCore.asmx) in Lenovo ThinkManagement Console 9.0.3 allows remote attackers to delete arbitrary files via a ..
network
low complexity
landesk CWE-22
5.0
2012-02-13 CVE-2012-1050 Path Traversal vulnerability in Mathopd 1.4/1.5
Directory traversal vulnerability in Mathopd 1.4.x and 1.5.x before 1.5p7, when configured with the * construct for mass virtual hosting, allows remote attackers to read arbitrary files via a crafted Host header.
network
mathopd CWE-22
4.3
2012-02-12 CVE-2012-1047 Path Traversal vulnerability in Cyberoam Central Console 2.00.2
Directory traversal vulnerability in the WWWHELP Service (js/html/wwhelp.htm) in Cyberoam Central Console (CCC) 2.00.2 allows remote attackers to include and execute arbitrary local files via a ..
network
low complexity
cyberoam CWE-22
7.5
2012-02-08 CVE-2012-1025 Path Traversal vulnerability in Dream-Multimedia-Tv Enigma2 Webinterface
Absolute path traversal vulnerability in file in Enigma2 Webinterface 1.6.0 through 1.6.8, 1.6rc3, and 1.7.0 allows remote attackers to read arbitrary files via a full pathname in the file parameter.
network
low complexity
dream-multimedia-tv CWE-22
5.0
2012-02-08 CVE-2012-1024 Path Traversal vulnerability in Dream-Multimedia-Tv Enigma2 Webinterface 1.5
Directory traversal vulnerability in file in Enigma2 Webinterface 1.5rc1 and 1.5beta4 allows remote attackers to read arbitrary files via a ..
network
low complexity
dream-multimedia-tv CWE-22
5.0
2012-02-07 CVE-2012-0991 Path Traversal vulnerability in Openemr 4.1.0
Multiple directory traversal vulnerabilities in OpenEMR 4.1.0 allow remote authenticated users to read arbitrary files via a ..
network
openemr CWE-22
3.5
2012-02-03 CVE-2011-4878 Path Traversal vulnerability in Siemens products
Directory traversal vulnerability in miniweb.exe in the HMI web server in Siemens WinCC flexible 2004, 2005, 2007, and 2008 before SP3; WinCC V11 (aka TIA portal) before SP2 Update 1; the TP, OP, MP, Comfort Panels, and Mobile Panels SIMATIC HMI panels; WinCC V11 Runtime Advanced; and WinCC flexible Runtime allows remote attackers to read arbitrary files via a ..%5c (dot dot backslash) in a URI.
network
low complexity
siemens CWE-22
7.8
2012-02-03 CVE-2011-4876 Path Traversal vulnerability in Siemens products
Directory traversal vulnerability in HmiLoad in the runtime loader in Siemens WinCC flexible 2004, 2005, 2007, and 2008; WinCC V11 (aka TIA portal); the TP, OP, MP, Comfort Panels, and Mobile Panels SIMATIC HMI panels; WinCC V11 Runtime Advanced; and WinCC flexible Runtime, when Transfer Mode is enabled, allows remote attackers to execute, read, create, modify, or delete arbitrary files via a ..
network
siemens CWE-22
critical
9.3