Total
7108 CVE
CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
---|---|---|---|---|---|
CVE-2018-16493 | 1 Static-resource-server Project | 1 Static-resource-server | 2024-11-21 | 5.0 MEDIUM | 7.5 HIGH |
A path traversal vulnerability was found in module static-resource-server 1.7.2 that allows unauthorized read access to any file on the server by appending slashes in the URL. | |||||
CVE-2018-16485 | 1 M-server Project | 1 M-server | 2024-11-21 | 4.0 MEDIUM | 6.5 MEDIUM |
Path Traversal vulnerability in module m-server <1.4.1 allows malicious user to access unauthorized content of any file in the directory tree e.g. /etc/passwd by appending slashes to the URL request. | |||||
CVE-2018-16482 | 1 Mcstatic Project | 1 Mcstatic | 2024-11-21 | 5.0 MEDIUM | 7.5 HIGH |
A server directory traversal vulnerability was found on node module mcstatic <=0.0.20 that would allow an attack to access sensitive information in the file system by appending slashes in the URL path. | |||||
CVE-2018-16479 | 1 Http-live-simulator Project | 1 Http-live-simulator | 2024-11-21 | 5.0 MEDIUM | 7.5 HIGH |
Path traversal vulnerability in http-live-simulator <1.0.7 causes unauthorized access to arbitrary files on disk by appending extra slashes after the URL. | |||||
CVE-2018-16478 | 1 Simplehttpserver Project | 1 Simplehttpserver | 2024-11-21 | 5.0 MEDIUM | 5.3 MEDIUM |
A Path Traversal in simplehttpserver versions <=0.2.1 allows to list any file in another folder of web root. | |||||
CVE-2018-16475 | 1 Knight Project | 1 Knight | 2024-11-21 | 5.0 MEDIUM | 7.5 HIGH |
A Path Traversal in Knightjs versions <= 0.0.1 allows an attacker to read content of arbitrary files on a remote server. | |||||
CVE-2018-16473 | 1 Takeapeek Project | 1 Takeapeek | 2024-11-21 | 5.0 MEDIUM | 5.3 MEDIUM |
A path traversal in takeapeek module versions <=0.2.2 allows an attacker to list directory and files. | |||||
CVE-2018-16457 | 1 Open Source Real-estate Script Project | 1 Open Source Real-estate Script | 2024-11-21 | 5.0 MEDIUM | 5.3 MEDIUM |
PHP Scripts Mall Open Source Real-estate Script 3.6.2 allows remote attackers to list the wp-content/themes/template_dp_dec2015/img directory. | |||||
CVE-2018-16446 | 1 Seamcms | 1 Seacms | 2024-11-21 | 6.4 MEDIUM | 7.5 HIGH |
An issue was discovered in SeaCMS through 6.61. adm1n/admin_database.php allows remote attackers to delete arbitrary files via directory traversal sequences in the bakfiles parameter. This can allow the product to be reinstalled by deleting install_lock.txt. | |||||
CVE-2018-16437 | 1 Gxlcms | 1 Gxlcms | 2024-11-21 | 4.0 MEDIUM | 4.9 MEDIUM |
Gxlcms 2.0 before bug fix 20180915 has Directory Traversal exploitable by an administrator. | |||||
CVE-2018-16367 | 1 Qduoj | 1 Onlinejudge | 2024-11-21 | 9.0 HIGH | 9.9 CRITICAL |
In OnlineJudge 2.0, the sandbox has an incorrect access control vulnerability that can write a file anywhere. A user can write a directory listing to /tmp, and can leak file data with a #include. | |||||
CVE-2018-16344 | 1 Zzcms | 1 Zzcms | 2024-11-21 | 6.4 MEDIUM | 7.5 HIGH |
An issue was discovered in zzcms 8.3. It allows remote attackers to delete arbitrary files via directory traversal sequences in the flv parameter. This can be leveraged for database access by deleting install.lock. | |||||
CVE-2018-16320 | 1 Idreamsoft | 1 Icms | 2024-11-21 | 6.5 MEDIUM | 7.2 HIGH |
idreamsoft iCMS 7.0.11 allows admincp.php?app=config Directory Traversal, resulting in execution of arbitrary PHP code from a ZIP file. | |||||
CVE-2018-16299 | 1 Localize My Post Project | 1 Localize My Post | 2024-11-21 | 5.0 MEDIUM | 7.5 HIGH |
The Localize My Post plugin 1.0 for WordPress allows Directory Traversal via the ajax/include.php file parameter. | |||||
CVE-2018-16283 | 1 Wechat Brodcast Project | 1 Wechat Brodcast | 2024-11-21 | 7.5 HIGH | 9.8 CRITICAL |
The Wechat Broadcast plugin 1.2.0 and earlier for WordPress allows Directory Traversal via the Image.php url parameter. | |||||
CVE-2018-16237 | 1 Damicms | 1 Damicms | 2024-11-21 | 4.0 MEDIUM | 2.7 LOW |
An issue was discovered in damiCMS V6.0.1. There is Directory Traversal via '|' characters in the s parameter to admin.php, as demonstrated by an admin.php?s=Tpl/Add/id/c:|windows|win.ini URI. | |||||
CVE-2018-16221 | 1 Yealink | 2 Ultra-elegant Ip Phone Sip-t41p, Ultra-elegant Ip Phone Sip-t41p Firmware | 2024-11-21 | 7.7 HIGH | 8.0 HIGH |
The diagnostics web interface in the Yeahlink Ultra-elegant IP Phone SIP-T41P (firmware 66.83.0.35) does not validate (escape) the path information (path traversal), which allows an authenticated remote attacker to get access to privileged information (e.g., /etc/passwd) via path traversal (relative path information in the file parameter of the corresponding POST request). | |||||
CVE-2018-16202 | 1 Ionicframework | 1 Ionic Web View | 2024-11-21 | 5.0 MEDIUM | 8.6 HIGH |
Directory traversal vulnerability in cordova-plugin-ionic-webview versions prior to 2.2.0 (not including 2.0.0-beta.0, 2.0.0-beta.1, 2.0.0-beta.2, and 2.1.0-0) allows remote attackers to access arbitrary files via unspecified vectors. | |||||
CVE-2018-16171 | 2 Cybozu, Microsoft | 2 Remote Service Manager, Windows | 2024-11-21 | 6.8 MEDIUM | 8.8 HIGH |
Directory traversal vulnerability in Cybozu Remote Service 3.0.0 to 3.1.8 allows remote attackers to execute Java code file on the server via unspecified vectors. | |||||
CVE-2018-16170 | 2 Cybozu, Microsoft | 2 Remote Service Manager, Windows | 2024-11-21 | 6.5 MEDIUM | 8.1 HIGH |
Directory traversal vulnerability in Cybozu Remote Service 3.0.0 to 3.1.8 for Windows allows remote authenticated attackers to read arbitrary files via unspecified vectors. |