Vulnerabilities > Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')

DATE CVE VULNERABILITY TITLE RISK
2012-02-02 CVE-2012-0981 Path Traversal vulnerability in Kybernetika PHPshowtime 2.0
Directory traversal vulnerability in phpShowtime 2.0 allows remote attackers to list arbitrary directories and image files via a ..
network
low complexity
kybernetika CWE-22
5.0
2012-01-20 CVE-2012-0907 Path Traversal vulnerability in Neoaxis web Player 1.1/1.2/1.3
Directory traversal vulnerability in the web player in NeoAxis NeoAxis web player 1.4 and earlier allows user-assisted remote attackers to write arbitrary files via a ..
network
neoaxis CWE-22
5.8
2012-01-20 CVE-2012-0898 Path Traversal vulnerability in Camaleo Myeasybackup 1.0.8.1
Directory traversal vulnerability in meb_download.php in the myEASYbackup plugin 1.0.8.1 for WordPress allows remote attackers to read arbitrary files via a ..
network
low complexity
camaleo wordpress CWE-22
5.0
2012-01-20 CVE-2012-0896 Path Traversal vulnerability in multiple products
Absolute path traversal vulnerability in download.php in the Count Per Day module before 3.1.1 for WordPress allows remote attackers to read arbitrary files via the f parameter.
5.0
2012-01-19 CVE-2011-4135 Path Traversal vulnerability in Flexerasoftware Flexnet Publisher 11.10
Multiple directory traversal vulnerabilities in lmgrd in Flexera FlexNet Publisher 11.10 (aka FlexNet License Server Manager) allow remote attackers to execute arbitrary code via vectors related to save, rename, and load operations on log files.
network
low complexity
flexerasoftware CWE-22
critical
10.0
2012-01-19 CVE-2011-1389 Path Traversal vulnerability in IBM products
Multiple directory traversal vulnerabilities in the vendor daemon in Rational Common Licensing in Telelogic License Server 2.0, Rational License Server 7.x, and ibmratl in IBM Rational License Key Server (RLKS) 8.0 through 8.1.2 allow remote attackers to execute arbitrary code via vectors related to save, rename, and load operations on log files.
network
low complexity
ibm CWE-22
critical
10.0
2012-01-13 CVE-2012-0697 Path Traversal vulnerability in HP Storageworks P2000 G3 MSA
HP StorageWorks P2000 G3 MSA array systems have a default account, which makes it easier for remote attackers to perform administrative tasks via unspecified vectors, a different vulnerability than CVE-2011-4788.
network
low complexity
hp CWE-22
critical
10.0
2012-01-13 CVE-2011-4788 Path Traversal vulnerability in HP products
Absolute path traversal vulnerability in the web interface on HP StorageWorks P2000 G3 MSA array systems allows remote attackers to read arbitrary files via a pathname in the URI.
network
low complexity
hp CWE-22
7.8
2012-01-08 CVE-2011-4532 Path Traversal vulnerability in Siemens Automation License Manager 5.1
Absolute path traversal vulnerability in the ALMListView.ALMListCtrl ActiveX control in almaxcx.dll in the graphical user interface in Siemens Automation License Manager (ALM) 2.0 through 5.1+SP1+Upd2 allows remote attackers to overwrite arbitrary files via the Save method.
network
low complexity
siemens CWE-22
5.0
2012-01-03 CVE-2011-4643 Path Traversal vulnerability in Splunk
Multiple directory traversal vulnerabilities in Splunk 4.x before 4.2.5 allow remote authenticated users to read arbitrary files via a ..
network
low complexity
splunk CWE-22
4.0