CWE:
 

Tytuł
Data
Autor
Med.
Sahi pro 8.x Directory Traversal
12.07.2019
Alexander Bluestein
Med.
GrandNode 4.40 Path Traversal / File Download
25.06.2019
Corey Robinson
Med.
ABB IDAL FTP Server Path Traversal
25.06.2019
Eldar Marcussen
Med.
Cisco Prime Infrastructure Health Monitor TarArchive Directory Traversal
20.06.2019
mr_me
Med.
Sahi Pro 7.x / 8.x Directory Traversal
19.06.2019
Goutham Madhwaraj
Med.
BlogEngine.NET 3.3.7 Directory Traversal / Remote Code Execution
19.06.2019
Aaron Bishop
High
Supra Smart Cloud TV Remote File Inclusion
06.06.2019
Mishra Dhiraj
Med.
Typora 0.9.9.24.6 Directory Traversal
29.05.2019
Mishra Dhiraj
Med.
Moodle Jmol Filter 6.1 Directory Traversal / Cross-Site Scripting
21.05.2019
Dionach Ltd
Med.
NetNumber Titan ENUM/DNS/NP 7.9.1 Bypass / Traversal
11.05.2019
MobileNetworkSecurity
Med.
Spring Cloud Config 2.1.x Path Traversal
01.05.2019
Mishra Dhiraj
Med.
Joomla Core 1.5.0 3.9.4 Directory Traversal / Authenticated Arbitrary File Deletion
23.04.2019
Haboob Team
High
Oracle Business Intelligence Directory Traversal
21.04.2019
Vahagn Vardanyan
Med.
Evernote 7.9 Path Traversal / Code Execution
19.04.2019
Mishra Dhiraj
Med.
Joomla 3.9.4 Arbitrary File Deletion / Directory Traversal
17.04.2019
Haboob Team
Med.
Titan FTP Server 2019 Build 3505 Directory Traversal
27.03.2019
Kevin Randall
Med.
CoreFTP Server FTP / SFTP Server 2 Build 674 MDTM Directory Traversal
13.03.2019
Kevin Randall
Med.
MarcomCentral FusionPro VDP Creator Directory Traversal
05.03.2019
0v3rride
Med.
Micro Focus Filr 3.4.0.217 Path Traversal / Privilege Escalation
22.02.2019
Leandro Cuozzo
High
SureMDM Local / Remote File Inclusion
02.02.2019
Digital Interruption
Med.
GL-AR300M-Lite 2.2.7 Command Injection / Directory Traversal
17.01.2019
Pasquale Turi
Med.
Aspose.ZIP For .NET Path Traversal
10.01.2019
Jaroslav Lobacevski
High
Roxy Fileman 1.4.5 File Upload / Directory Traversal
08.01.2019
Pongtorn Angsuchotmete...
Med.
Transcend Wi-Fi SD Card Cross Site Request Forgery / Traversal
18.12.2018
MustLive
Low
Responsive FileManager 9.13.4 XSS / File Manipulation / Traversal
15.12.2018
farisv
Med.
Zyxel VMG1312-B10D 5.13AAXA.8 Directory Traversal
26.11.2018
x-hayben21
High
D-Link Plain-Text Password Storage / Code Execution / Directory Traversal
19.10.2018
Blazej Adamczyk
Med.
Citrix StorageZones Controller Improper Access Restrictions / Traversal
27.09.2018
Wolfgang Ettlinger
Med.
Rubedo CMS 3.4.0 Directory Traversal
12.09.2018
Marouene Boubakri
Med.
Softneta MedDream PACS Server Premium 6.7.1.1 Directory Traversal
08.09.2018
Carlos Avila
Med.
Argus Surveillance DVR 4.0.0.0 Directory Traversal
29.08.2018
hyp3rlinx
Med.
PCViewer vt1000 Directory Traversal
23.08.2018
Berk Dusunur
Med.
Oracle GlassFish Server 4.1 Directory Traversal
14.08.2018
Mishra Dhiraj
Med.
LG-Ericsson iPECS NMS 30M Directory Traversal
09.08.2018
Safak Aslan
Med.
CMS ISWEB 3.5.3 Directory Traversal
06.08.2018
Thiago Sena
Med.
cgit < 1.2.1 cgit_clone_objects() Directory Traversal
03.08.2018
Google Security Resear...
Med.
GeoVision GV-SNVR0811 Directory Traversal
25.07.2018
Berk Dusunur
Low
D-link DAP-1360 Path Traversal / Cross-Site Scripting
25.07.2018
r3m0t3nu11
Med.
VelotiSmart WiFi B-380 Camera Directory Traversal
17.07.2018
Miguel Mendez Z
Med.
Dicoogle PACS 2.5.0 Directory Traversal
12.07.2018
Carlos Avila
Med.
Mirasys DVMS Workstation 5.12.6 Path Traversal
22.06.2018
Dick Snel
Med.
IPConfigure Orchid VMS 2.0.5 Directory Traversal Information Disclosure
20.06.2018
Sanjiv Kawa
Med.
Redatam Web Server Directory Traversal
18.06.2018
Berk Dusunur
High
WordPress Redirection 2.7.3 Remote File Inclusion
13.06.2018
Glyn Wintle
Med.
TAC Xenta 511/911 Directory Traversal
31.05.2018
Marek Cybul
High
Cisco SA520W Security Appliance Path Traversal
19.05.2018
Nassim Asrir
High
ProjectPier 0.8.8 SQL Injection / Authentication Bypass / RFI
15.05.2018
Imre Rad
Med.
IceWarp Mail Server < 11.1.1 Directory Traversal
04.05.2018
Piotr Karolak
Med.
Sitecore.NET 8.1 Directory Traversal
27.04.2018
Chris Moberly
Med.
Ncomputing vSpace Pro v10 and v11 Directory Traversal PoC
24.04.2018
Javier Bernardo
Med.
Seagate Media Server Path Traversal
20.04.2018
Yorick Koster
Med.
TwonkyMedia Server 7.0.11-8.5 Directory Traversal
29.03.2018
Sven Fassbender
Med.
Acrolinx Server Directory Traversal
27.03.2018
Berk Dusunur
Med.
Bomgar Remote Support Portal (RSP) Path Traversal
24.03.2018
Filip Palian
Med.
Advantech WebAccess < 8.3 Directory Traversal / Remote Code Execution
13.03.2018
Chris Lyne
Med.
Parallels Remote Application Server 15.5 Path Traversal
04.03.2018
Nicolas Markitanis
Med.
uWSGI < 2.0.17 Directory Traversal
03.03.2018
Marios Nicolaides
Med.
Sophos XG Firewall 16.05.4 MR-4 Path Traversal
16.02.2018
SecuriTeam
Med.
Oracle Hospitality Simphony (MICROS) 2.9 Directory Traversal
05.02.2018
Dmitry Chastuhin
Med.
Joomla! Picture Calendar For Joomla 3.1.4 Directory Traversal
31.01.2018
Ihsan Sencan
Med.
PACSOne Server 6.6.2 DICOM Web Viewer Directory Traversal
29.01.2018
Carlos Avila
Med.
Yawcam 0.6.0 Directory Traversal
09.01.2018
David Panter
Med.
WordPress WooCommerce 2.0 / 3.0 Directory Traversal
01.12.2017
Fu2x200
Med.
Android Gmail < 7.11.5.176568039 Directory Traversal in Attachment Download
28.11.2017
Google
Med.
Ulterius Server < 1.9.5.0 Directory Traversal
15.11.2017
Rick Osgood
Med.
3CX Phone System 15.5.3554.1 Directory Traversal
18.10.2017
Jens Regel
Med.
WordPress Smush Image 2.7.4.1 Directory Traversal
05.10.2017
Ricardo Sanchez
Med.
Cloudview NMS 2.00b Writable Directory Traversal Execution
17.09.2017
james fitts
Med.
Carlo Gavazzi Powersoft 2.1.1.1 Directory Traversal
15.09.2017
james fitts
Med.
Indusoft Web Studio - Directory Traversal Information Disclosure
14.09.2017
james fitts
Med.
Huawei HG255s Directory Traversal
08.09.2017
Ahmet Mersin
High
Automated Logic WebCTRL 6.1 Path Traversal Arbitrary File Write
23.08.2017
Gjoko 'LiquidWorm' Krs...
Low
Cisco DDR2200 / 2201v1 Insecure Direct Object Reference / Path Traversal
17.07.2017
Matheus Bernardes
Med.
Schneider Electric Pelco VideoXpert Core Admin Portal Directory Traversal
11.07.2017
Gjoko 'LiquidWorm' Krs...
Med.
Kaspersky Anti-Virus File Server 8.0.3.297 - Multiple Vulnerabilities
29.06.2017
CORE
Med.
WordPress Photo Gallery 1.3.34 / 1.3.42 Path Traversal
21.06.2017
Tom Adams
Med.
Home FTP Server 1.14.0 Build 176 Directory Traversal
31.05.2017
Sultan Albalawi
Med.
Trend Micro Threat Discovery Appliance 2.6.1062r1 logoff.cgi Directory Traversal
20.04.2017
Steven Seeley
Med.
XiongMai uc-http 1.0.0 Local File Inclusion / Directory Traversal
13.04.2017
keksec
Med.
MyBB <1.8.11 Directory Traversal
12.04.2017
Zhiyang Zeng
Med.
Miele Professional PG 8528 Directory Traversal
25.03.2017
Jens Regel
Med.
OpenSSH On Cygwin SFTP Client Directory Traversal
22.03.2017
jannh
Med.
HttpServer 1.0 Directory Traversal
20.03.2017
malwrforensics
High
dnaLIMS Code Execution / XSS / Traversal / Session Hijacking
11.03.2017
Nicholas von Pechmann
Med.
Joomla Akeeba Backup 5.2.5 Directory Traversal
08.03.2017
Persian Hack Team
High
Ettercap 0.8.2 Etterfilter Out-Of-Bounds Read
06.03.2017
AromalUllas
Med.
Simplessus Files 3.7.7 Path Traversal
19.02.2017
Dr. Adrian Vollmer
High
Trendmicro InterScan 6.5-SP2_Build_Linux_1548 Remote Root
18.02.2017
Matt Bergin (@thatguyl...
Med.
Trendmicro InterScan 6.5-SP2_Build_Linux_1548 Arbitrary File Write
18.02.2017
Matt Bergin
Med.
Coppermine Gallery 1.5.44 Directory Traversal
16.02.2017
Hacker Fantastic
Med.
Horos 2.1.0 Web Portal Remote Information Disclosure / Directory Traversal
18.12.2016
Gjoko 'LiquidWorm' Krs...
Med.
Shuttle Tech ADSL Wireless 920 WM XSS / Directory Traversal
06.12.2016
Persian Hack Team
High
Apache ActiveMQ 5.11.1 / 5.13.2 Directory Traversal / Command Execution
04.12.2016
David Jorm
Low
Biesta Billing 4.0 Beta Cross Site Request Forgery / Traversal
29.11.2016
TaurusOmar
High
Crestron AM-100 1.2.1 Path Traversal / Hard-Coded Credentials
23.11.2016
Zach Lanier
Low
Atlassian Confluence AppFusions Doxygen 1.3.0 Path Traversal
22.11.2016
RCE
Med.
SAP NetWeaver AS ABAP 7.4 Directory Traversal
19.11.2016
Daria Prosochkina
Med.
Oracle Netbeans IDE 8.1 Directory Traversal
21.10.2016
hyp3rlinx
Low
SPIP 3.1.2 File Enumeration / Path Traversal
20.10.2016
Nicolas CHATELAIN
Med.
Kajona 4.7 Cross Site Scripting / Directory Traversal
17.09.2016
Tim Coen


Common Weakness Enumeration (CWE)

CVE
Szczegóły
Opis
2019-07-17
Medium
CVE-2019-4430

Vendor: IBM
Software: Maximo asset...
 

 
IBM Maximo Asset Management 7.6 could allow a remote attacker to traverse directories on the system. An attacker could send a specially-crafted URL request containing "dot dot" sequences (/../) to view arbitrary files on the system. IBM X-Force ID: 162887.

 
Low
CVE-2019-10352

Vendor: Jenkins
Software: Jenkins
 

 
A path traversal vulnerability in Jenkins 2.185 and earlier, LTS 2.176.1 and earlier in core/src/main/java/hudson/model/FileParameterValue.java allowed attackers with Job/Configure permission to define a file parameter with a file name outside the intended directory, resulting in an arbitrary file write on the Jenkins master when scheduling a build.

 
Medium
CVE-2019-13584

Vendor: Fanucamerica
Software: Robotics vir...
 

 
The remote admin webserver on FANUC Robotics Virtual Robot Controller 8.23 allows Directory Traversal via a forged HTTP request.

 
2019-07-16
High
CVE-2019-12990

Updating...
 

 
Citrix SD-WAN 10.2.x before 10.2.3 and NetScaler SD-WAN 10.0.x before 10.0.8 allow Directory Traversal.

 
Medium
CVE-2019-13623

Vendor: NSA
Software: Ghidra
 

 
In NSA Ghidra through 9.0.4, path traversal can occur in RestoreTask.java (from the package ghidra.app.plugin.core.archive) via an archive with an executable file that has an initial ../ in its filename. This allows attackers to overwrite arbitrary files in scenarios where an intermediate analysis result is archived for sharing with other persons. To achieve arbitrary code execution, one approach is to overwrite some critical Ghidra modules, e.g., the decompile module.

 
2019-07-15
Medium
CVE-2019-5447

Vendor: Rejetto
Software: Http-file-server
 

 
A path traversal vulnerability in <= v0.2.6 of http-file-server npm module allows attackers to list files in arbitrary folders.

 
2019-07-11
Low
CVE-2019-3415

Vendor: ZTE
Software: Zxmw nr8000 ...
 

 
ZTE MW NR8000V2.4.4.03 and NR8000V2.4.4.04 are impacted by path traversal vulnerability. Due to path traversal,users can download any files.

 
2019-07-10
Medium
CVE-2019-13396

Vendor: Getflightpath
Software: Flightpath
 

 
FlightPath 4.x and 5.0-x allows directory traversal and Local File Inclusion through the form_include parameter in an index.php?q=system-handle-form-submit POST request because of an include_once in system_handle_form_submit in modules/system/system.module.

 
Low
CVE-2019-5221

Updating...
 

 
There is a path traversal vulnerability on Huawei Share. The software does not properly validate the path, an attacker could crafted a file path when transporting file through Huawei Share, successful exploit could allow the attacker to transport a file to arbitrary path on the phone. Affected products: Mate 20 X versions earlier than Ever-L29B 9.1.0.300(C432E3R1P12), versions earlier than Ever-L29B 9.1.0.300(C636E3R2P1), and versions earlier than Ever-L29B 9.1.0.300(C185E3R3P1).

 
Medium
CVE-2019-5444

Vendor: Serve-here.js project
Software: Serve-here.js
 

 
Path traversal vulnerability in version up to v1.1.3 in serve-here.js npm module allows attackers to list any file in arbitrary folder.

 

 


Copyright 2019, cxsecurity.com

 

Back to Top