Vulnerabilities (CVE)

Filtered by CWE-22
Total 7723 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2017-8115 1 Modx 1 Modx Revolution 2025-04-20 5.0 MEDIUM 5.3 MEDIUM
Directory traversal in setup/processors/url_search.php (aka the search page of an unused processor) in MODX Revolution 2.5.7 might allow remote attackers to obtain system directory information.
CVE-2017-15893 1 Synology 1 File Station 2025-04-20 4.0 MEDIUM 6.5 MEDIUM
Directory traversal vulnerability in the SYNO.FileStation.Extract in Synology File Station before 1.1.1-0099 allows remote authenticated users to write arbitrary files via the dest_folder_path parameter.
CVE-2017-1577 1 Ibm 1 Websphere Portal 2025-04-20 5.0 MEDIUM 7.5 HIGH
IBM WebSphere Portal 7.0, 8.0, 8.5, and 9.0 could allow a remote attacker to traverse directories on the system. An attacker could send a specially-crafted URL request containing "dot dot" sequences (/../) to view arbitrary files on the system. IBM X-Force ID: 132117.
CVE-2017-7442 1 Gonitro 1 Nitro Pro 2025-04-20 6.8 MEDIUM 8.8 HIGH
Nitro Pro 11.0.3.173 allows remote attackers to execute arbitrary code via saveAs and launchURL calls with directory traversal sequences.
CVE-2016-7842 1 Hibara 1 Attachecase 2025-04-20 4.3 MEDIUM 5.5 MEDIUM
Directory traversal vulnerability in AttacheCase 2.8.2.8 and earlier and 3.2.0.4 and earlier allows remote attackers to read arbitrary files via specially crafted ATC file.
CVE-2017-10665 1 Phpgrid 1 Phpgrid 2025-04-20 6.8 MEDIUM 7.8 HIGH
Directory traversal vulnerability in ajaxfileupload.php in Kayson Group Ltd. phpGrid before 7.2.5 allows remote attackers to execute arbitrary code by uploading a crafted file with a .. (dot dot) in the file name.
CVE-2017-5143 1 Honeywell 1 Xl Web Ii Controller 2025-04-20 7.5 HIGH 8.6 HIGH
An issue was discovered in Honeywell XL Web II controller XL1000C500 XLWebExe-2-01-00 and prior, and XLWeb 500 XLWebExe-1-02-08 and prior. A user without authenticating can make a directory traversal attack by accessing a specific URL.
CVE-2017-8297 1 Simple-file-manager Project 1 Simple-file-manager 2025-04-20 7.5 HIGH 9.8 CRITICAL
A path traversal vulnerability exists in simple-file-manager before 2017-04-26, affecting index.php (the sole "Simple PHP File Manager" component).
CVE-2017-5899 1 S-nail Project 1 S-nail 2025-04-20 6.9 MEDIUM 7.0 HIGH
Directory traversal vulnerability in the setuid root helper binary in S-nail (later S-mailx) before 14.8.16 allows local users to write to arbitrary files and consequently gain root privileges via a .. (dot dot) in the randstr argument.
CVE-2016-6269 1 Trendmicro 1 Smart Protection Server 2025-04-20 7.5 HIGH 9.1 CRITICAL
Multiple directory traversal vulnerabilities in Trend Micro Smart Protection Server 2.5 before build 2200, 2.6 before build 2106, and 3.0 before build 1330 allow remote attackers to read and delete arbitrary files via the tmpfname parameter to (1) log_mgt_adhocquery_ajaxhandler.php, (2) log_mgt_ajaxhandler.php, (3) log_mgt_ajaxhandler.php or (4) tf parameter to wcs_bwlists_handler.php.
CVE-2017-8853 1 Fiyo 1 Fiyo Cms 2025-04-20 6.4 MEDIUM 7.5 HIGH
Fiyo CMS v2.0.7 has an arbitrary file delete vulnerability in dapur/apps/app_config/controller/backuper.php via directory traversal in the file parameter during an act=db action.
CVE-2015-8352 1 Zen-cart 1 Zen Cart 2025-04-20 10.0 HIGH 9.8 CRITICAL
Directory traversal vulnerability in Zen Cart 1.5.4 allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the act parameter to ajax.php.
CVE-2016-7982 1 Spip 1 Spip 2025-04-20 5.0 MEDIUM 7.5 HIGH
Directory traversal vulnerability in ecrire/exec/valider_xml.php in SPIP 3.1.2 and earlier allows remote attackers to enumerate the files on the system via the var_url parameter in a valider_xml action.
CVE-2017-10993 1 Contao 1 Contao Cms 2025-04-20 6.5 MEDIUM 8.8 HIGH
Contao before 3.5.28 and 4.x before 4.4.1 allows remote attackers to include and execute arbitrary local PHP files via a crafted parameter in a URL, aka Directory Traversal.
CVE-2017-12694 1 Spidercontrol 1 Scada Web Server 2025-04-20 5.0 MEDIUM 7.5 HIGH
A Directory Traversal issue was discovered in SpiderControl SCADA Web Server. An attacker may be able to use a simple GET request to perform a directory traversal into system files.
CVE-2017-15363 1 Luracast 1 Restler 2025-04-20 5.0 MEDIUM 7.5 HIGH
Directory traversal vulnerability in public/examples/resources/getsource.php in Luracast Restler through 3.0.0, as used in the restler extension before 1.7.1 for TYPO3, allows remote attackers to read arbitrary files via the file parameter.
CVE-2017-1000170 1 Jqueryfiletree Project 1 Jqueryfiletree 2025-04-20 5.0 MEDIUM 7.5 HIGH
jqueryFileTree 2.1.5 and older Directory Traversal
CVE-2015-8235 1 Call-cc 1 Spiffy 2025-04-20 5.0 MEDIUM 7.5 HIGH
Directory traversal vulnerability in Spiffy before 5.4.
CVE-2017-9097 1 Hoytech 1 Antiweb 2025-04-20 6.4 MEDIUM 9.1 CRITICAL
In Anti-Web through 3.8.7, as used on NetBiter FGW200 devices through 3.21.2, WS100 devices through 3.30.5, EC150 devices through 1.40.0, WS200 devices through 3.30.4, EC250 devices through 1.40.0, and other products, an LFI vulnerability allows a remote attacker to read or modify files through a path traversal technique, as demonstrated by reading the password file, or using the template parameter to cgi-bin/write.cgi to write to an arbitrary file.
CVE-2017-17739 1 Brightsign 2 4k242, 4k242 Firmware 2025-04-20 7.5 HIGH 9.8 CRITICAL
The BrightSign Digital Signage (4k242) device (Firmware 6.2.63 and below) has directory traversal via the /storage.html rp parameter, allowing an attacker to read or write to files.