Vulnerabilities (CVE)

Filtered by CWE-22
Angry Yack Logo
Total 8266 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2017-1000472 2 Debian, Pocoproject 2 Debian Linux, Poco 2024-11-21 5.8 MEDIUM 6.5 MEDIUM
The ZipCommon::isValidPath() function in Zip/src/ZipCommon.cpp in POCO C++ Libraries before 1.8 does not properly restrict the filename value in the ZIP header, which allows attackers to conduct absolute path traversal attacks during the ZIP decompression, and possibly create or overwrite arbitrary files, via a crafted ZIP file, related to a "file path injection vulnerability".
CVE-2017-1000448 1 Structured-data 1 Structured Data Linter 2024-11-21 5.0 MEDIUM 7.5 HIGH
Structured Data Linter versions 2.4.1 and older are vulnerable to a directory traversal attack in the URL input field resulting in the possibility of disclosing information about the remote host.
CVE-2017-0930 1 Augustine Project 1 Augustine 2024-11-21 4.0 MEDIUM 6.5 MEDIUM
augustine node module suffers from a Path Traversal vulnerability due to lack of validation of url, which allows a malicious user to read content of any file with known path.
CVE-2017-0918 2 Debian, Gitlab 2 Debian Linux, Gitlab 2024-11-21 6.5 MEDIUM 8.8 HIGH
Gitlab Community Edition version 10.3 is vulnerable to a path traversal issue in the GitLab CI runner component resulting in remote code execution.
CVE-2016-9484 1 Jqueryform 1 Php Formmail Generator 2024-11-21 5.0 MEDIUM 7.5 HIGH
The generated PHP form code does not properly validate user input folder directories, allowing a remote unauthenticated attacker to perform a path traversal and access arbitrary files on the server. The PHP FormMail Generator website does not use version numbers and is updated continuously. Any PHP form code generated by this website prior to 2016-12-06 may be vulnerable.
CVE-2016-7063 1 Pritunl 1 Pritunl-client 2024-11-21 7.5 HIGH 9.8 CRITICAL
A flaw was found in pritunl-client before version 1.0.1116.6. Arbitrary write to user specified path may lead to privilege escalation.
CVE-2016-7041 1 Redhat 2 Jboss Brms, Jboss Drools 2024-11-21 6.8 MEDIUM 6.5 MEDIUM
Drools Workbench contains a path traversal vulnerability. The vulnerability allows a remote, authenticated attacker to bypass the directory restrictions and retrieve arbitrary files from the affected host.
CVE-2016-15038 2024-11-21 6.4 MEDIUM 6.5 MEDIUM
A vulnerability, which was classified as critical, was found in NUUO NVRmini 2 up to 3.0.8. Affected is an unknown function of the file /deletefile.php. The manipulation of the argument filename leads to path traversal. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-258780.
CVE-2016-15023 1 Sitefusion 1 Application Server 2024-11-21 2.7 LOW 3.5 LOW
A vulnerability, which was classified as problematic, was found in SiteFusion Application Server up to 6.6.6. This affects an unknown part of the file getextension.php of the component Extension Handler. The manipulation leads to path traversal. Upgrading to version 6.6.7 is able to address this issue. The identifier of the patch is 49fff155c303d6cd06ce8f97bba56c9084bf08ac. It is recommended to upgrade the affected component. The identifier VDB-219765 was assigned to this vulnerability.
CVE-2016-15019 1 Jekbox Project 1 Jekbox 2024-11-21 4.0 MEDIUM 4.3 MEDIUM
A vulnerability was found in tombh jekbox. It has been rated as problematic. This issue affects some unknown processing of the file lib/server.rb. The manipulation leads to exposure of information through directory listing. The attack may be initiated remotely. The patch is named 64eb2677671018fc08b96718b81e3dbc83693190. It is recommended to apply a patch to fix this issue. The associated identifier of this vulnerability is VDB-218375.
CVE-2016-15017 1 Ecodev 1 Media Upload 2024-11-21 5.2 MEDIUM 5.5 MEDIUM
A vulnerability has been found in fabarea media_upload on TYPO3 and classified as critical. This vulnerability affects the function getUploadedFileList of the file Classes/Service/UploadFileService.php. The manipulation leads to pathname traversal. Upgrading to version 0.9.0 is able to address this issue. The patch is identified as b25d42a4981072321c1a363311d8ea2a4ac8763a. It is recommended to upgrade the affected component. VDB-217786 is the identifier assigned to this vulnerability.
CVE-2016-10977 1 Neliosoftware 1 Nelio Ab Testing 2024-11-21 4.0 MEDIUM 6.5 MEDIUM
The nelio-ab-testing plugin before 4.5.0 for WordPress has filename=..%2f directory traversal.
CVE-2016-10966 1 Creativeinteractivemedia 1 Real3d Flipbook 2024-11-21 5.0 MEDIUM 7.5 HIGH
The real3d-flipbook-lite plugin 1.0 for WordPress has bookName=../ directory traversal for file upload.
CVE-2016-10965 1 Creativeinteractivemedia 1 Real3d Flipbook 2024-11-21 6.4 MEDIUM 7.5 HIGH
The real3d-flipbook-lite plugin 1.0 for WordPress has deleteBook=../ directory traversal for file deletion.
CVE-2016-10924 1 Zedna Ebook Download Project 1 Zedna Ebook Download 2024-11-21 5.0 MEDIUM 7.5 HIGH
The ebook-download plugin before 1.2 for WordPress has directory traversal.
CVE-2016-10828 1 Cpanel 1 Cpanel 2024-11-21 9.0 HIGH 8.8 HIGH
cPanel before 55.9999.141 allows arbitrary code execution because of an unsafe @INC path (SEC-97).
CVE-2016-10759 1 Precurio 1 Precurio 2024-11-21 7.5 HIGH 9.8 CRITICAL
The Xinha plugin in Precurio 2.1 allows Directory Traversal, with resultant arbitrary code execution, via ExtendedFileManager/Classes/ExtendedFileManager.php because ExtendedFileManager can be used to rename the .htaccess file that blocks .php uploads.
CVE-2016-10751 1 Osclass 1 Osclass 2024-11-21 6.5 MEDIUM 7.2 HIGH
osClass 3.6.1 allows oc-admin/plugins.php Directory Traversal via the plugin parameter. This is exploitable for remote PHP code execution because an administrator can upload an image that contains PHP code in the EXIF data via index.php?page=ajax&action=ajax_upload.
CVE-2016-10733 1 Projectsend 1 Projectsend 2024-11-21 7.5 HIGH 9.8 CRITICAL
ProjectSend (formerly cFTP) r582 allows directory traversal via file=../ in the process-zip-download.php query string.
CVE-2016-10726 1 Duraspace 1 Dspace 2024-11-21 5.0 MEDIUM 7.5 HIGH
The XMLUI feature in DSpace before 3.6, 4.x before 4.5, and 5.x before 5.5 allows directory traversal via the themes/ path in an attack with two or more arbitrary characters and a colon before a pathname, as demonstrated by a themes/Reference/aa:etc/passwd URI.
CVE-2016-10561 1 Bitty Project 1 Bitty 2024-11-21 5.0 MEDIUM 5.3 MEDIUM
Bitty is a development web server tool that functions similar to `python -m SimpleHTTPServer`. Version 0.2.10 has a directory traversal vulnerability that is exploitable via the URL path in GET requests.
CVE-2016-10538 2 Cli Project, Debian 2 Cli, Debian Linux 2024-11-21 4.9 MEDIUM 3.5 LOW
The package `node-cli` before 1.0.0 insecurely uses the lock_file and log_file. Both of these are temporary, but it allows the starting user to overwrite any file they have access to.
CVE-2016-10528 1 Restafary Project 1 Restafary 2024-11-21 4.0 MEDIUM 4.9 MEDIUM
restafary is a REpresentful State Transfer API for Creating, Reading, Using, Deleting files on a server from the web. Restafary before 1.6.1 is able to set up a root path, which should only allow it to run inside of that root path it specified.
CVE-2015-9546 1 Google 1 Android 2024-11-21 5.8 MEDIUM 4.8 MEDIUM
An issue was discovered on Samsung mobile devices with KK(4.4) and later software through 2015-06-16. In some cases, HTTP is used for an Inputmethod, rather than HTTPS. A man-in-the-middle attacker can modify the client-server data stream to insert directory traversal sequences into an extracted file path. The Samsung ID is SVE-2015-4363 (November 2015).
CVE-2015-9538 1 Imagely 1 Nextgen Gallery 2024-11-21 4.0 MEDIUM 6.5 MEDIUM
The NextGEN Gallery plugin before 2.1.15 for WordPress allows ../ Directory Traversal in path selection.
CVE-2015-9480 1 Robot-cpa 1 Robotcpa 2024-11-21 5.0 MEDIUM 7.5 HIGH
The RobotCPA plugin 5 for WordPress has directory traversal via the f.php l parameter.
CVE-2015-9473 1 Estrutura-basica Project 1 Estrutura-basica 2024-11-21 5.0 MEDIUM 7.5 HIGH
The estrutura-basica theme through 2015-09-13 for WordPress has directory traversal via the scripts/download.php arquivo parameter.
CVE-2015-9470 1 Ionadas 1 History Collection 2024-11-21 5.0 MEDIUM 7.5 HIGH
The history-collection plugin through 1.1.1 for WordPress has directory traversal via the download.php var parameter.
CVE-2015-9464 1 S3bubble 1 S3bubble-amazon-s3-html-5-video-with-adverts 2024-11-21 5.0 MEDIUM 7.5 HIGH
The s3bubble-amazon-s3-html-5-video-with-adverts plugin 0.7 for WordPress has directory traversal via the adverts/assets/plugins/ultimate/content/downloader.php path parameter.
CVE-2015-9463 1 S3bubble 1 S3bubble-amazon-s3-audio-streaming 2024-11-21 5.0 MEDIUM 7.5 HIGH
The s3bubble-amazon-s3-audio-streaming plugin 2.0 for WordPress has directory traversal via the adverts/assets/plugins/ultimate/content/downloader.php path parameter.
CVE-2015-9406 1 Mtheme-unus Project 1 Mtheme-unus 2024-11-21 5.0 MEDIUM 7.5 HIGH
Directory traversal vulnerability in the mTheme-Unus theme before 2.3 for WordPress allows an attacker to read arbitrary files via a .. (dot dot) in the files parameter to css/css.php.
CVE-2015-9287 1 Cam 1 The University Of Cambridge Web Authentication System Apache Authentication Agent 2024-11-21 5.0 MEDIUM 9.8 CRITICAL
Directory Traversal was discovered in University of Cambridge mod_ucam_webauth before 2.0.2. The key identification field ("kid") of the IdP's HTTP response message ("WLS-Response") can be manipulated by an attacker. The "kid" field is not signed like the rest of the message, and manipulation is therefore trivial. The "kid" field should only ever represent an integer. However, it is possible to provide any string value. An attacker could use this to their advantage to force the application agent ...

Show More

CVE-2015-9277 1 Mailenable 1 Mailenable 2024-11-21 7.5 HIGH 9.1 CRITICAL
MailEnable before 8.60 allows Directory Traversal for reading the messages of other users, uploading files, and deleting files because "/../" and "/.. /" are mishandled.
CVE-2015-9275 1 Arc Project 1 Arc 2024-11-21 5.0 MEDIUM 5.3 MEDIUM
ARC 5.21q allows directory traversal via a full pathname in an archive file.
CVE-2015-9266 2 Ubnt, Ui 23 Airos 4 Xs2, Airos 4 Xs5, Edgeswitch Xp Firmware and 20 more 2024-11-21 10.0 HIGH 9.8 CRITICAL
The web management interface of Ubiquiti airMAX, airFiber, airGateway and EdgeSwitch XP (formerly TOUGHSwitch) allows an unauthenticated attacker to upload and write arbitrary files using directory traversal techniques. An attacker can exploit this vulnerability to gain root privileges. This vulnerability is fixed in the following product versions (fixes released in July 2015, all prior versions are affected): airMAX AC 7.1.3; airMAX M (and airRouter) 5.6.2 XM/XW/TI, 5.5.11 XM/TI, and 5.5.10u2 X ...

Show More

CVE-2015-9250 1 Skyboxsecurity 1 Skybox Platform 2024-11-21 5.0 MEDIUM 7.5 HIGH
An issue was discovered in Skybox Platform before 7.5.201. Directory Traversal exists in /skyboxview/webskybox/attachmentdownload and /skyboxview/webskybox/filedownload via the tempFileName parameter.
CVE-2015-8535 1 Lenovo 1 Solution Center 2024-11-21 7.2 HIGH 7.8 HIGH
MITRE is populating this ID because it was assigned prior to Lenovo becoming a CNA. A directory traversal vulnerability was discovered (fixed and publicly disclosed in 2015) in Lenovo Solution Center (LSC) prior to version 3.3.002 that could allow a user to execute arbitrary code with elevated privileges.
CVE-2015-7851 1 Ntp 1 Ntp 2024-11-21 3.5 LOW 6.5 MEDIUM
Directory traversal vulnerability in the save_config function in ntpd in ntp_control.c in NTP before 4.2.8p4, when used on systems that do not use '\' or '/' characters for directory separation such as OpenVMS, allows remote authenticated users to overwrite arbitrary files.
CVE-2015-6591 1 Freereprintables 1 Articlefr 2024-11-21 2.1 LOW 5.5 MEDIUM
Directory traversal vulnerability in application/templates/amelia/loadjs.php in Free Reprintables ArticleFR 3.0.7 and earlier allows local users to read arbitrary files via the s parameter.
CVE-2015-6589 1 Kaseya 1 Virtual System Administrator 2024-11-21 6.5 MEDIUM 8.8 HIGH
Directory traversal vulnerability in Kaseya Virtual System Administrator (VSA) 7.0.0.0 before 7.0.0.33, 8..0.0.0 before 8.0.0.23, 9.0.0.0 before 9.0.0.19, and 9.1.0.0 before 9.1.0.9 allows remote authenticated users to write to and execute arbitrary files due to insufficient restrictions in file paths to json.ashx.