Vulnerabilities > Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')

DATE CVE VULNERABILITY TITLE RISK
2007-09-18 CVE-2007-4957 Path Traversal vulnerability in Chupix CMS 0.2.3
Multiple directory traversal vulnerabilities in download.php in Chupix CMS 0.2.3 allow remote attackers to read or overwrite arbitrary files via a ..
network
low complexity
chupix CWE-22
7.5
2007-09-17 CVE-2007-4908 Path Traversal vulnerability in Auracms
Directory traversal vulnerability in index.php in AuraCMS 2.1 and earlier allows remote attackers to include and execute arbitrary local files via a ..
network
low complexity
auracms CWE-22
7.5
2007-09-17 CVE-2007-4902 Path Traversal vulnerability in Ultra Shareware Ultra Crypto Component 2.0.2007.801
Absolute path traversal vulnerability in a certain ActiveX control in CryptoX.dll 2.0 and earlier in the Ultra Crypto Component allows remote attackers to write to arbitrary files via a full pathname in the argument to the SaveToFile method.
network
low complexity
ultra-shareware CWE-22
6.4
2007-09-14 CVE-2007-4895 Path Traversal vulnerability in Sisfo Kampus Sisfo Kampus 2006
Directory traversal vulnerability in dwoprn.php in Sisfo Kampus 2006 (Semarang 3) allows remote attackers to read arbitrary files via the f parameter.
network
low complexity
sisfo-kampus CWE-22
5.0
2007-09-14 CVE-2007-4890 Path Traversal vulnerability in Microsoft Visual Studio 6.0
Absolute directory traversal vulnerability in a certain ActiveX control in the VB To VSI Support Library (VBTOVSI.DLL) 1.0.0.0 in Microsoft Visual Studio 6.0 allows remote attackers to create or overwrite arbitrary files via a full pathname in the argument to the SaveAs method.
network
microsoft CWE-22
5.8
2007-09-12 CVE-2007-4843 Path Traversal vulnerability in X-Diesel Unreal Commander 0.92Build565/0.92Build573
Directory traversal vulnerability in X-Diesel Unreal Commander 0.92 build 565 and 573 allows remote FTP servers to create or overwrite arbitrary files via a ..
network
x-diesel CWE-22
5.8
2007-09-12 CVE-2007-4842 Path Traversal vulnerability in Enriva Development Magellan Explorer
Directory traversal vulnerability in Enriva Development Magellan Explorer 3.32 build 2305 and earlier allows remote FTP servers to create or overwrite arbitrary files via a ..
network
enriva-development CWE-22
critical
9.3
2007-09-12 CVE-2007-4825 Path Traversal vulnerability in PHP
Directory traversal vulnerability in PHP 5.2.4 and earlier allows attackers to bypass open_basedir restrictions and possibly execute arbitrary code via a ..
network
low complexity
php CWE-22
7.5
2007-09-11 CVE-2007-4820 Path Traversal vulnerability in Sisfo Kampus Sisfo Kampus 2006
Absolute path traversal vulnerability in blanko.preview.php in Sisfo Kampus 2006 allows remote attackers to read arbitrary local files, and possibly execute local PHP scripts, via the nmf parameter.
network
low complexity
sisfo-kampus CWE-22
7.5
2007-09-11 CVE-2007-4805 Path Traversal vulnerability in Fuzzylime 3.0
Directory traversal vulnerability in getgalldata.php in fuzzylime (cms) 3.0 and earlier allows remote attackers to include arbitrary local files via a ..
network
low complexity
fuzzylime CWE-22
7.5