Search
Total
4706 CVE
| CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
|---|---|---|---|---|---|
| CVE-2018-18831 | 1 Mingsoft | 1 Mcms | 2018-12-11 | 5.0 MEDIUM | 7.5 HIGH |
| An issue was discovered in com\mingsoft\cms\action\GeneraterAction.java in MCMS 4.6.5. An attacker can write a .jsp file (in the position parameter) to an arbitrary directory via a ../ Directory Traversal in the url parameter. | |||||
| CVE-2018-18936 | 1 Popojicms | 1 Popojicms | 2018-12-11 | 6.4 MEDIUM | 7.5 HIGH |
| An issue was discovered in PopojiCMS v2.0.1. admin_library.php allows remote attackers to delete arbitrary files via directory traversal in the po-admin/route.php?mod=library&act=delete id parameter. | |||||
| CVE-2018-18869 | 1 Phome | 1 Empirecms | 2018-12-10 | 7.5 HIGH | 9.8 CRITICAL |
| EmpireCMS V7.5 allows remote attackers to upload and execute arbitrary code via ..%2F directory traversal in a .php filename in the upload/e/admin/ecmscom.php path parameter. | |||||
| CVE-2018-18950 | 1 Kindeditor | 1 Kindeditor | 2018-12-10 | 5.0 MEDIUM | 7.5 HIGH |
| KindEditor through 4.1.11 has a path traversal vulnerability in php/upload_json.php. Anyone can browse a file or directory in the kindeditor/attached/ folder via the path parameter without authentication. | |||||
| CVE-2016-2389 | 1 Sap | 1 Netweaver | 2018-12-10 | 7.8 HIGH | 7.5 HIGH |
| Directory traversal vulnerability in the GetFileList function in the SAP Manufacturing Integration and Intelligence (xMII) component 15.0 for SAP NetWeaver 7.4 allows remote attackers to read arbitrary files via a .. (dot dot) in the Path parameter to /Catalog, aka SAP Security Note 2230978. | |||||
| CVE-2014-8659 | 1 Sap | 1 Environment Health And Safety | 2018-12-10 | 5.0 MEDIUM | N/A |
| Directory traversal vulnerability in SAP Environment, Health, and Safety allows remote attackers to read arbitrary files via unspecified vectors. | |||||
| CVE-2013-6821 | 1 Sap | 1 Netweaver | 2018-12-10 | 5.0 MEDIUM | N/A |
| Directory traversal vulnerability in the Exportability Check Service in SAP NetWeaver allows remote attackers to read arbitrary files via unspecified vectors. | |||||
| CVE-2018-15745 | 1 Argussurveillance | 1 Dvr | 2018-12-07 | 5.0 MEDIUM | 7.5 HIGH |
| Argus Surveillance DVR 4.0.0.0 devices allow Unauthenticated Directory Traversal, leading to File Disclosure via a ..%2F in the WEBACCOUNT.CGI RESULTPAGE parameter. | |||||
| CVE-2018-18552 | 1 Serverscheck | 1 Monitoring Software | 2018-12-06 | 5.0 MEDIUM | 6.5 MEDIUM |
| ServersCheck Monitoring Software through 14.3.3 allows local users to cause a denial of service (menu functionality loss) by creating an LNK file that points to a second LNK file, if this second LNK file is associated with a Start menu. Ultimately, this behavior comes from a Directory Traversal bug (via the sensor_details.html id parameter) that allows creating empty files in arbitrary directories. | |||||
| CVE-2012-6324 | 1 Vmware | 1 Vcenter Server Appliance | 2018-12-06 | 4.0 MEDIUM | N/A |
| Directory traversal vulnerability in VMware vCenter Server Appliance (vCSA) 5.0 before Update 2 and 5.1 before Patch 1 allows remote authenticated users to read arbitrary files via unspecified vectors. | |||||
| CVE-2016-10733 | 1 Projectsend | 1 Projectsend | 2018-12-06 | 7.5 HIGH | 9.8 CRITICAL |
| ProjectSend (formerly cFTP) r582 allows directory traversal via file=../ in the process-zip-download.php query string. | |||||
| CVE-2013-2085 | 1 Owncloud | 1 Owncloud | 2018-12-06 | 4.0 MEDIUM | N/A |
| Directory traversal vulnerability in apps/files_trashbin/index.php in ownCloud Server before 5.0.6 allows remote authenticated users to access arbitrary files via a .. (dot dot) in the dir parameter. | |||||
| CVE-2018-17444 | 1 Citrix | 2 Netscaler Sd-wan, Sd-wan | 2018-12-04 | 5.0 MEDIUM | 7.5 HIGH |
| A Directory Traversal issue was discovered in Citrix SD-WAN 10.1.0 and NetScaler SD-WAN 9.3.x before 9.3.6 and 10.0.x before 10.0.4. | |||||
| CVE-2018-8889 | 1 Blackberry | 1 Enterprise Mobility Server | 2018-12-04 | 4.7 MEDIUM | 4.7 MEDIUM |
| A directory traversal vulnerability in the Connect Service of the BlackBerry Enterprise Mobility Server (BEMS) 2.8.17.29 and earlier could allow an attacker to retrieve arbitrary files in the context of a BEMS administrator account. | |||||
| CVE-2018-18703 | 1 Phptpoint | 1 Mailing Server Using File Handling | 2018-12-04 | 5.0 MEDIUM | 7.5 HIGH |
| PhpTpoint Mailing Server Using File Handling 1.0 suffers from multiple Arbitrary File Read vulnerabilities in different sections that allow an attacker to read sensitive files on the system via directory traversal, bypassing the login page, as demonstrated by the Mailserver_filesystem/home.php coninb, consent, contrsh, condrft, or conspam parameter. | |||||
| CVE-2012-4834 | 1 Ibm | 1 Websphere Portal | 2018-12-04 | 5.0 MEDIUM | N/A |
| Directory traversal vulnerability in LayerLoader.jsp in the theme component in IBM WebSphere Portal 7.0.0.1 and 7.0.0.2 before CF19 and 8.0 before CF03 allows remote attackers to read arbitrary files via a crafted URI. | |||||
| CVE-2018-18890 | 1 1234n | 1 Minicms | 2018-12-03 | 5.0 MEDIUM | 5.3 MEDIUM |
| MiniCMS 1.10 allows full path disclosure via /mc-admin/post.php?state=delete&delete= with an invalid filename. | |||||
| CVE-2018-15540 | 1 Agentejo | 1 Cockpit | 2018-11-30 | 7.5 HIGH | 9.8 CRITICAL |
| Agentejo Cockpit performs actions on files without appropriate validation and therefore allows an attacker to traverse the file system to unintended locations and/or access arbitrary files, aka /media/api Directory Traversal. | |||||
| CVE-2018-1000079 | 1 Rubygems | 1 Rubygems | 2018-11-30 | 4.3 MEDIUM | 5.5 MEDIUM |
| RubyGems version Ruby 2.2 series: 2.2.9 and earlier, Ruby 2.3 series: 2.3.6 and earlier, Ruby 2.4 series: 2.4.3 and earlier, Ruby 2.5 series: 2.5.0 and earlier, prior to trunk revision 62422 contains a Directory Traversal vulnerability in gem installation that can result in the gem could write to arbitrary filesystem locations during installation. This attack appear to be exploitable via the victim must install a malicious gem. This vulnerability appears to have been fixed in 2.7.6. | |||||
| CVE-2018-18257 | 1 Bagesoft | 1 Bagecms | 2018-11-29 | 6.4 MEDIUM | 7.5 HIGH |
| An issue was discovered in BageCMS 3.1.3. An attacker can delete any files and folders on the web server via an index.php?r=admini/template/batch&command=deleteFile&fileName= or index.php?r=admini/template/batch&command=deleteFolder&folderName=../ directory traversal URI. | |||||
| CVE-2018-18323 | 1 Centos-webpanel | 1 Centos Web Panel | 2018-11-29 | 5.0 MEDIUM | 7.5 HIGH |
| CentOS-WebPanel.com (aka CWP) CentOS Web Panel 0.9.8.480 has Local File Inclusion via directory traversal with an admin/index.php?module=file_editor&file=/../ URI. | |||||
| CVE-2018-16457 | 1 Open Source Real-estate Script Project | 1 Open Source Real-estate Script | 2018-11-29 | 5.0 MEDIUM | 5.3 MEDIUM |
| PHP Scripts Mall Open Source Real-estate Script 3.6.2 allows remote attackers to list the wp-content/themes/template_dp_dec2015/img directory. | |||||
| CVE-2018-18434 | 1 Litemall Project | 1 Litemall | 2018-11-29 | 5.0 MEDIUM | 7.5 HIGH |
| An issue was discovered in litemall 0.9.0. Arbitrary file download is possible via ../ directory traversal in linlinjava/litemall/wx/web/WxStorageController.java in the litemall-wx-api component. | |||||
| CVE-2018-17797 | 1 Zzcms | 1 Zzcms | 2018-11-28 | 5.5 MEDIUM | 6.5 MEDIUM |
| An issue was discovered in zzcms 8.3. user/zssave.php allows remote attackers to delete arbitrary files via directory traversal sequences in the oldimg parameter in an action=modify request. This can be leveraged for database access by deleting install.lock. | |||||
| CVE-2018-17828 | 1 Zziplib Project | 1 Zziplib | 2018-11-28 | 5.8 MEDIUM | 5.5 MEDIUM |
| Directory traversal vulnerability in ZZIPlib 0.13.69 allows attackers to overwrite arbitrary files via a .. (dot dot) in a zip file, because of the function unzzip_cat in the bins/unzzipcat-mem.c file. | |||||
| CVE-2018-17838 | 1 Jtbc | 1 Jtbc Php | 2018-11-28 | 5.0 MEDIUM | 7.5 HIGH |
| An issue was discovered in JTBC(PHP) 3.0.1.6. Arbitrary file read operations are possible via a /console/#/console/file/manage.php?type=list&path=c:/ substring. | |||||
| CVE-2018-17297 | 1 Hutool | 1 Hutool | 2018-11-26 | 6.4 MEDIUM | 7.5 HIGH |
| The unzip function in ZipUtil.java in Hutool before 4.1.12 allows remote attackers to overwrite arbitrary files via directory traversal sequences in a filename within a ZIP archive. | |||||
| CVE-2018-16299 | 1 Localize My Post Project | 1 Localize My Post | 2018-11-23 | 5.0 MEDIUM | 7.5 HIGH |
| The Localize My Post plugin 1.0 for WordPress allows Directory Traversal via the ajax/include.php file parameter. | |||||
| CVE-2018-16968 | 1 Citrix | 1 Sharefile Storagezones Controller | 2018-11-23 | 3.5 LOW | 3.1 LOW |
| Citrix ShareFile StorageZones Controller before 5.4.2 allows Directory Traversal. | |||||
| CVE-2018-11762 | 1 Apache | 1 Tika | 2018-11-20 | 5.8 MEDIUM | 5.9 MEDIUM |
| In Apache Tika 0.9 to 1.18, in a rare edge case where a user does not specify an extract directory on the commandline (--extract-dir=) and the input file has an embedded file with an absolute path, such as "C:/evil.bat", tika-app would overwrite that file. | |||||
| CVE-2018-9074 | 1 Lenovo | 22 Iomega Ez Media \& Backup Center, Iomega Storcenter Ix2, Iomega Storcenter Ix2-dl and 19 more | 2018-11-20 | 6.8 MEDIUM | 6.5 MEDIUM |
| For some Iomega, Lenovo, LenovoEMC NAS devices versions 4.1.402.34662 and earlier, the file upload functionality of the Content Explorer application is vulnerable to path traversal. As a result, users can upload files anywhere on the device's operating system as the root user. | |||||
| CVE-2018-17553 | 1 Naviwebs | 1 Navigate Cms | 2018-11-19 | 6.5 MEDIUM | 8.8 HIGH |
| An "Unrestricted Upload of File with Dangerous Type" issue with directory traversal in navigate_upload.php in Naviwebs Navigate CMS 2.8 allows authenticated attackers to achieve remote code execution via a POST request with engine=picnik and id=../../../navigate_info.php. | |||||
| CVE-2018-16819 | 1 Monstra | 1 Monstra | 2018-11-19 | 5.5 MEDIUM | 4.9 MEDIUM |
| admin/index.php in Monstra CMS 3.0.4 allows arbitrary file deletion via id=filesmanager&path=uploads/.......//./.......//./&delete_file= requests. | |||||
| CVE-2018-17125 | 1 Chshcms | 1 Cscms | 2018-11-19 | 6.4 MEDIUM | 7.5 HIGH |
| CScms 4.1 allows arbitrary directory deletion via a dir=..\\ substring to plugins\sys\admin\Plugins.php. | |||||
| CVE-2018-16549 | 1 Php File Browser Script Project | 1 Php File Browser Script | 2018-11-16 | 5.0 MEDIUM | 5.3 MEDIUM |
| HScripts PHP File Browser Script v1.0 allows Directory Traversal via the index.php path parameter. | |||||
| CVE-2018-16831 | 1 Smarty | 1 Smarty | 2018-11-16 | 7.1 HIGH | 5.9 MEDIUM |
| Smarty before 3.1.33-dev-4 allows attackers to bypass the trusted_dir protection mechanism via a file:./../ substring in an include statement. | |||||
| CVE-2011-4596 | 1 Openstack | 1 Nova | 2018-11-16 | 6.0 MEDIUM | N/A |
| Multiple directory traversal vulnerabilities in OpenStack Nova before 2011.3.1, when the EC2 API and the S3/RegisterImage image-registration method are enabled, allow remote authenticated users to overwrite arbitrary files via a crafted (1) tarball or (2) manifest. | |||||
| CVE-2018-16283 | 1 Wechat Brodcast Project | 1 Wechat Brodcast | 2018-11-14 | 7.5 HIGH | 9.8 CRITICAL |
| The Wechat Broadcast plugin 1.2.0 and earlier for WordPress allows Directory Traversal via the Image.php url parameter. | |||||
| CVE-2018-16344 | 1 Zzcms | 1 Zzcms | 2018-11-13 | 6.4 MEDIUM | 7.5 HIGH |
| An issue was discovered in zzcms 8.3. It allows remote attackers to delete arbitrary files via directory traversal sequences in the flv parameter. This can be leveraged for database access by deleting install.lock. | |||||
| CVE-2018-16820 | 1 Monstra | 1 Monstra | 2018-11-07 | 5.0 MEDIUM | 7.5 HIGH |
| admin/index.php in Monstra CMS 3.0.4 allows arbitrary directory listing via id=filesmanager&path=uploads/.......//./.......//./ requests. | |||||
| CVE-2018-16141 | 1 Thinkcmf | 1 Thinkcmfx | 2018-11-06 | 5.5 MEDIUM | 6.5 MEDIUM |
| ThinkCMF X2.2.3 has an arbitrary file deletion vulnerability in do_avatar in \application\User\Controller\ProfileController.class.php via an imgurl parameter with a ..\ sequence. A member user can delete any file on a Windows server. | |||||
| CVE-2018-0646 | 1 Ponsoftware | 1 Explzh | 2018-11-06 | 6.8 MEDIUM | 7.8 HIGH |
| Directory traversal vulnerability in Explzh v.7.58 and earlier allows an attacker to read arbitrary files via unspecified vectors. | |||||
| CVE-2018-15810 | 1 Visiology | 1 Flipbox | 2018-11-05 | 5.0 MEDIUM | 7.5 HIGH |
| Visiology Flipbox Software Suite before 2.7.0 allows directory traversal via %5c%2e%2e%2f because it does not sanitize filename parameters. | |||||
| CVE-2018-16437 | 1 Gxlcms | 1 Gxlcms | 2018-11-05 | 4.0 MEDIUM | 4.9 MEDIUM |
| Gxlcms 2.0 before bug fix 20180915 has Directory Traversal exploitable by an administrator. | |||||
| CVE-2018-16320 | 1 Idreamsoft | 1 Icms | 2018-11-02 | 6.5 MEDIUM | 7.2 HIGH |
| idreamsoft iCMS 7.0.11 allows admincp.php?app=config Directory Traversal, resulting in execution of arbitrary PHP code from a ZIP file. | |||||
| CVE-2018-15536 | 1 Tecrail | 1 Responsive Filemanager | 2018-11-01 | 5.8 MEDIUM | 5.5 MEDIUM |
| /filemanager/ajax_calls.php in tecrail Responsive FileManager before 9.13.4 does not properly validate file paths in archives, allowing for the extraction of crafted archives to overwrite arbitrary files via an extract action, aka Directory Traversal. | |||||
| CVE-2008-4067 | 4 Canonical, Debian, Linux and 1 more | 6 Ubuntu Linux, Debian Linux, Linux Kernel and 3 more | 2018-11-01 | 4.3 MEDIUM | N/A |
| Directory traversal vulnerability in Mozilla Firefox before 2.0.0.17 and 3.x before 3.0.2, Thunderbird before 2.0.0.17, and SeaMonkey before 1.1.12 on Linux allows remote attackers to read arbitrary files via a .. (dot dot) and URL-encoded / (slash) characters in a resource: URI. | |||||
| CVE-2008-4068 | 3 Canonical, Debian, Mozilla | 5 Ubuntu Linux, Debian Linux, Firefox and 2 more | 2018-11-01 | 7.8 HIGH | N/A |
| Directory traversal vulnerability in Mozilla Firefox before 2.0.0.17 and 3.x before 3.0.2, Thunderbird before 2.0.0.17, and SeaMonkey before 1.1.12 allows remote attackers to bypass "restrictions imposed on local HTML files," and obtain sensitive information and prompt users to write this information into a file, via directory traversal sequences in a resource: URI. | |||||
| CVE-2016-5098 | 2 Opensuse, Phpmyadmin | 2 Opensuse, Phpmyadmin | 2018-10-30 | 5.0 MEDIUM | 5.3 MEDIUM |
| Directory traversal vulnerability in libraries/error_report.lib.php in phpMyAdmin before 4.6.2-prerelease allows remote attackers to determine the existence of arbitrary files by triggering an error. | |||||
| CVE-2015-2304 | 3 Canonical, Libarchive, Opensuse | 3 Ubuntu Linux, Libarchive, Opensuse | 2018-10-30 | 6.4 MEDIUM | N/A |
| Absolute path traversal vulnerability in bsdcpio in libarchive 3.1.2 and earlier allows remote attackers to write to arbitrary files via a full pathname in an archive. | |||||
