Vulnerabilities (CVE)

Filtered by CWE-22
Total 7182 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2008-2818 1 Easy-clanpage 1 Easy-clanpage 2025-04-09 7.5 HIGH N/A
Directory traversal vulnerability in Easy-Clanpage 3.0 b1 allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the section parameter to the default URI.
CVE-2007-5484 1 Wwwisis 1 Wwwisis 2025-04-09 5.0 MEDIUM N/A
Directory traversal vulnerability in wxis.exe in WWWISIS 7.1 allows local users to read arbitrary files via a .. (dot dot) in the IsisScript parameter to iah.
CVE-2009-4231 1 Basic-cms 1 Sweetrice 2025-04-09 7.5 HIGH N/A
Directory traversal vulnerability in as/lib/plugins.php in SweetRice 0.5.3 and earlier allows remote attackers to include and execute arbitrary local files via .. (dot dot) in the plugin parameter.
CVE-2006-7112 1 Maxdev 1 Mdpro 2025-04-09 6.0 MEDIUM N/A
Directory traversal vulnerability in error.php in MD-Pro 1.0.76 and earlier allows remote authenticated users to read and include arbitrary files via the PNSVlang cookie, as demonstrated by uploading a GIF image using AddDownload or injecting PHP code into a log file, then accessing it.
CVE-2008-1310 1 Packettrap 1 Pt360 Tool Suite 2025-04-09 10.0 HIGH N/A
Directory traversal vulnerability in the TFTP server in PacketTrap Networks pt360 Tool Suite 1.1.33.1.0, and other versions before 2.0.3900.0, allows remote attackers to read and overwrite arbitrary files via directory traversal sequences in the pathname.
CVE-2008-1856 1 Linpha 1 Linpha 2025-04-09 5.1 MEDIUM N/A
plugins/maps/db_handler.php in LinPHA 1.3.3 and earlier does not require authentication for a settings action that modifies the configuration file, which allows remote attackers to conduct directory traversal attacks and execute arbitrary local files by placing directory traversal sequences into the maps_type configuration setting, and then sending a request to maps_view.php, which causes plugins/maps/map.main.class.php to use the modified configuration.
CVE-2008-1642 1 Savas Place 1 Savas Guestbook 2025-04-09 7.5 HIGH N/A
Directory traversal vulnerability in index.php in Sava's GuestBook 2.0 allows remote attackers to include and execute arbitrary local files via directory traversal sequences in the action parameter. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.
CVE-2008-6335 1 Emetrix 1 Online Keyword Research Tool 2025-04-09 7.8 HIGH N/A
Directory traversal vulnerability in download.php in eMetrix Online Keyword Research Tool allows remote attackers to read arbitrary files via a .. (dot dot) in the filename parameter.
CVE-2009-1502 1 Matteoiammarrone 1 S-cms 2025-04-09 7.5 HIGH N/A
Directory traversal vulnerability in plugin.php in S-Cms 1.1 Stable and 1.5.2 allows remote attackers to include and execute arbitrary local files via directory traversal sequences in the page parameter.
CVE-2007-6344 1 Mcms 1 Easy Web Make 2025-04-09 6.8 MEDIUM N/A
Directory traversal vulnerability in modules/cms/index.php in Mcms Easy Web Make 1.3, allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the template parameter.
CVE-2008-6183 1 Myphpindexer 1 My Php Indexer 2025-04-09 7.8 HIGH N/A
Multiple directory traversal vulnerabilities in index.php in My PHP Indexer 1.0 allow remote attackers to read arbitrary files via a .. (dot dot) in the (1) d and (2) f parameters.
CVE-2007-2836 1 Hiki 1 Hiki 2025-04-09 6.4 MEDIUM N/A
Directory traversal vulnerability in session.rb in Hiki 0.8.0 through 0.8.6 allows remote attackers to delete arbitrary files via directory traversal sequences in the session ID, which is matched against an insufficiently restrictive regular expression before it is used to construct a filename that is marked for deletion at logout.
CVE-2009-0929 1 Nucleus Group 1 Nucleus Cms 2025-04-09 5.0 MEDIUM N/A
Directory traversal vulnerability in the media manager in Nucleus CMS before 3.40 allows remote attackers to read arbitrary files via unknown vectors.
CVE-2008-3164 1 Fuzzylime 1 Fuzzylime Cms 2025-04-09 7.6 HIGH N/A
Directory traversal vulnerability in blog.php in fuzzylime (cms) 3.01, when magic_quotes_gpc is disabled, allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the file parameter. NOTE: it was later reported that 3.01a is also affected.
CVE-2009-1911 2 Claudio Klingler, Tinywebgallery 2 Quixplorer, Tinywebgallery 2025-04-09 6.8 MEDIUM N/A
Directory traversal vulnerability in .include/init.php (aka admin/_include/init.php) in QuiXplorer 2.3.2 and earlier, as used in TinyWebGallery (TWG) 1.7.6 and earlier, allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the lang parameter to admin/index.php.
CVE-2009-2183 1 Campware.org 1 Campsite 2025-04-09 7.5 HIGH N/A
Directory traversal vulnerability in admin-files/ad.php in Campsite 3.3.0 RC1 allows remote attackers to read and possibly execute arbitrary local files via a .. (dot dot) in the GLOBALS[g_campsiteDir] parameter.
CVE-2009-4194 1 Kmint21 1 Golden Ftp Server 2025-04-09 6.0 MEDIUM 8.1 HIGH
Directory traversal vulnerability in Golden FTP Server 4.30 Free and Professional, 4.50, and possibly other versions allows remote authenticated users to delete arbitrary files via a .. (dot dot) in the DELE command. NOTE: some of these details are obtained from third party information.
CVE-2006-6047 1 Etomite 1 Etomite 2025-04-09 5.8 MEDIUM N/A
Directory traversal vulnerability in manager/index.php in Etomite 0.6.1.2 allows remote authenticated administrators to include and execute arbitrary local files via a .. (dot dot) in the f parameter, as demonstrated by injecting PHP sequences into an Apache HTTP Server log file, which is then included by index.php.
CVE-2008-0794 1 Affiliate Market 1 Affiliate Market 2025-04-09 6.4 MEDIUM N/A
Directory traversal vulnerability in user/header.php in Affiliate Market 0.1 BETA allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the language parameter.
CVE-2008-0819 1 Plutostatus 1 Plutostatus Locator 2025-04-09 3.6 LOW N/A
Directory traversal vulnerability in index.php in PlutoStatus Locator 1.0 pre alpha allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the page parameter.