Vulnerabilities > Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')

DATE CVE VULNERABILITY TITLE RISK
2009-01-27 CVE-2009-0290 Path Traversal vulnerability in SIR Gnuboard 4.31.03
Directory traversal vulnerability in common.php in SIR GNUBoard 4.31.03 allows remote attackers to include and execute arbitrary local files via a ..
network
sir CWE-22
6.8
2009-01-27 CVE-2009-0286 Path Traversal vulnerability in Opengoo 1.1
Directory traversal vulnerability in upgrade/index.php in OpenGoo 1.1, when register_globals is enabled and magic_quotes_gpc is disabled, allows remote attackers to read arbitrary files via a ..
network
high complexity
opengoo CWE-22
2.6
2009-01-26 CVE-2008-5968 Path Traversal vulnerability in PHPicalendar
Directory traversal vulnerability in print.php in PHP iCalendar 2.24 and earlier allows remote attackers to include and execute arbitrary local files via a ..
network
low complexity
phpicalendar CWE-22
7.5
2009-01-26 CVE-2008-5965 Path Traversal vulnerability in Lokicms
Directory traversal vulnerability in index.php in LokiCMS 0.3.4 and earlier, when magic_quotes_gpc is disabled, allows remote attackers to check for the existence of arbitrary files via a ..
network
low complexity
lokicms CWE-22
5.0
2009-01-26 CVE-2009-0271 Path Traversal vulnerability in Fujitsu Systemcastwizard Lite
Directory traversal vulnerability in the TFTP service in Fujitsu SystemcastWizard Lite 2.0A, 2.0, 1.9, and earlier allows remote attackers to read arbitrary files via directory traversal sequences in unspecified vectors.
network
low complexity
fujitsu CWE-22
5.0
2009-01-23 CVE-2008-5962 Path Traversal vulnerability in Gravity-Gtd 0.2/0.3/0.4
Directory traversal vulnerability in library/setup/rpc.php in Gravity Getting Things Done (GTD) 0.4.5 and earlier allows remote attackers to include and execute arbitrary local files via a ..
6.8
2009-01-23 CVE-2008-5953 Path Traversal vulnerability in KTP Computer Customer Database KTP Computer Customer Database NIL
Directory traversal vulnerability in KTP Computer Customer Database (KTPCCD) CMS, when magic_quotes_gpc is disabled, allows remote attackers to include and execute arbitrary local files via a ..
network
low complexity
ktp-computer-customer-database CWE-22
7.5
2009-01-23 CVE-2008-5948 Path Traversal vulnerability in Bncwi 1.03
Directory traversal vulnerability in index.php in BNCwi 1.04 and earlier allows remote attackers to include and execute arbitrary local files via a ..
network
low complexity
bncwi CWE-22
7.5
2009-01-22 CVE-2008-5943 Path Traversal vulnerability in Navboard 16
Multiple directory traversal vulnerabilities in NavBoard 16 (2.6.0) allow remote attackers to include and execute arbitrary local files via a ..
network
low complexity
navboard CWE-22
7.5
2009-01-21 CVE-2009-0244 Path Traversal vulnerability in Microsoft Windows Mobile 5.0/6.0
Directory traversal vulnerability in the OBEX FTP Service in the Microsoft Bluetooth stack in Windows Mobile 6 Professional, and probably Windows Mobile 5.0 for Pocket PC and 5.0 for Pocket PC Phone Edition, allows remote authenticated users to list arbitrary directories, and create or read arbitrary files, via a ..
network
low complexity
microsoft CWE-22
8.8