Vulnerabilities (CVE)

Filtered by CWE-22
Total 7027 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2007-4062 1 Nessus 1 Vulnerability Scanner 2025-04-09 7.8 HIGH N/A
The SCANCTRL.ScanCtrlCtrl.1 ActiveX control in scan.dll in Nessus Vulnerability Scanner 3.0.6 allows remote attackers to delete arbitrary files via unspecified vectors involving the deleteNessusRC method, probably a directory traversal vulnerability.
CVE-2007-5694 1 Sitebar 1 Sitebar 2025-04-09 6.8 MEDIUM N/A
Absolute path traversal vulnerability in the translation module (translator.php) in SiteBar 3.3.8 allows remote authenticated users to read arbitrary files via an absolute path in the dir parameter, a different vulnerability than CVE-2007-5491.
CVE-2008-4602 1 Qualityunit 1 Post Affiliate Pro 2025-04-09 6.5 MEDIUM N/A
Directory traversal vulnerability in index.php in Post Affiliate Pro 2.0 allows remote authenticated users to read and possibly execute arbitrary local files via a .. (dot dot) in the md parameter.
CVE-2009-2151 1 Adaptweb 1 Adaptweb 2025-04-09 5.0 MEDIUM N/A
Directory traversal vulnerability in index.php in AdaptWeb 0.9.2 allows remote attackers to read arbitrary files via a .. (dot dot) in the newlang parameter.
CVE-2009-2600 1 Akiva 1 Webboard 2025-04-09 5.0 MEDIUM N/A
Multiple directory traversal vulnerabilities in view.php in Webboard 2.90 beta and earlier allow remote attackers to read arbitrary files via a .. (dot dot) in the topic parameter.
CVE-2009-0640 1 Swannsecurity 1 Dvr4-securanet 2025-04-09 5.0 MEDIUM N/A
Directory traversal vulnerability in the administrative web server in Swann DVR4-SecuraNet allows remote attackers to read arbitrary files via a .. (dot dot) in the URI, as demonstrated by reading the vy_netman.cfg file that contains passwords.
CVE-2008-4421 1 Hammer-software 1 Metagauge 2025-04-09 7.8 HIGH N/A
Directory traversal vulnerability in MetaGauge 1.0.0.17, and probably other versions before 1.0.3.38, allows remote attackers to read arbitrary files via a "..\" (dot dot backslash) in the URL.
CVE-2009-2552 1 Supersimple 1 Super Simple Blog Script 2025-04-09 6.8 MEDIUM N/A
Multiple directory traversal vulnerabilities in comments.php in Super Simple Blog Script 2.5.4 allow remote attackers to overwrite, include, and execute arbitrary local files via the entry parameter.
CVE-2007-4843 1 X-diesel 1 Unreal Commander 2025-04-09 5.8 MEDIUM N/A
Directory traversal vulnerability in X-Diesel Unreal Commander 0.92 build 565 and 573 allows remote FTP servers to create or overwrite arbitrary files via a .. (dot dot) in a filename. NOTE: this can be leveraged for code execution by writing to a Startup folder.
CVE-2007-4718 1 Claroline 1 Claroline 2025-04-09 5.1 MEDIUM N/A
Directory traversal vulnerability in inc/lib/language.lib.php in Claroline before 1.8.6 allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the language parameter.
CVE-2007-6471 1 Phpay 1 Phpay 2025-04-09 5.8 MEDIUM N/A
Incomplete blacklist vulnerability in main.php in phPay 2.02.01 on Windows allows remote attackers to conduct directory traversal attacks and include and execute arbitrary local files via a ..\ (dot dot backslash) in the config parameter.
CVE-2009-4427 1 Phpldapadmin Project 1 Phpldapadmin 2025-04-09 7.5 HIGH N/A
Directory traversal vulnerability in cmd.php in phpLDAPadmin 1.1.0.5 allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the cmd parameter.
CVE-2007-1031 1 Spoonlabs 1 Vivvo Article Management Cms 2025-04-09 6.8 MEDIUM N/A
Directory traversal vulnerability in include/db_conn.php in SpoonLabs Vivvo Article Management CMS 3.4 allows remote attackers to include and execute arbitrary local files via the root parameter.
CVE-2009-0766 1 Bookelves 1 Kipper 2025-04-09 7.5 HIGH N/A
Directory traversal vulnerability in default.php in Kipper 2.01 allows remote attackers to include and execute arbitrary local files via directory traversal sequences in the configfile parameter. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.
CVE-2008-2519 1 Core Ftp 1 Core Ftp 2025-04-09 6.8 MEDIUM N/A
Directory traversal vulnerability in Core FTP client 2.1 Build 1565 allows remote FTP servers to create or overwrite arbitrary files via .. (dot dot) sequences in responses to LIST commands, a related issue to CVE-2002-1345. NOTE: this can be leveraged for code execution by writing to a Startup folder.
CVE-2008-7176 1 Celina Jorge 1 Facil Cms 2025-04-09 6.8 MEDIUM N/A
Multiple directory traversal vulnerabilities in Facil CMS 0.1RC allow remote attackers to read arbitrary files via a .. (dot dot) in the (1) change_lang parameter to index.php or (2) modload parameter to modules.php.
CVE-2009-3219 1 The-ghost 1 Ar Web Content Manager 2025-04-09 6.8 MEDIUM N/A
Directory traversal vulnerability in a.php in AR Web Content Manager (AWCM) 2.1, when magic_quotes_gpc is disabled, allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the a parameter.
CVE-2008-6505 1 Apache 1 Struts 2025-04-09 5.0 MEDIUM N/A
Multiple directory traversal vulnerabilities in Apache Struts 2.0.x before 2.0.12 and 2.1.x before 2.1.3 allow remote attackers to read arbitrary files via a ..%252f (encoded dot dot slash) in a URI with a /struts/ path, related to (1) FilterDispatcher in 2.0.x and (2) DefaultStaticContentLoader in 2.1.x.
CVE-2008-6090 1 Scriptsez 1 Mini Hosting Panel 2025-04-09 4.3 MEDIUM N/A
Directory traversal vulnerability in members.php in ScriptsEz Mini Hosting Panel allows remote attackers to read arbitrary local files via a .. (dot dot) in the dir parameter in a view action.
CVE-2008-6825 1 Trixbox 1 Trixbox 2025-04-09 6.8 MEDIUM N/A
Directory traversal vulnerability in user/index.php in Fonality trixbox CE 2.6.1 and earlier allows remote attackers to include and execute arbitrary files via a .. (dot dot) in the langChoice parameter.