Vulnerabilities (CVE)

Filtered by CWE-22
Total 7186 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2008-1553 1 Topper 1 Toppermod 2025-04-09 6.8 MEDIUM N/A
Directory traversal vulnerability in mod.php in TopperMod 1.0 allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the to parameter.
CVE-2007-5920 1 Picoflat Cms 1 Picoflat Cms 2025-04-09 6.8 MEDIUM N/A
index.php in Domenico Mancini PicoFlat CMS before 0.4.18 allows remote attackers to include certain files via unspecified vectors, possibly due to a directory traversal vulnerability. NOTE: this can be leveraged to bypass authentication and upload files by including pico_insert.php or unspecified other administrative scripts. NOTE: some of these details are obtained from third party information.
CVE-2009-0880 2 Ibm, Microsoft 2 Director, Windows 2025-04-09 6.8 MEDIUM N/A
Directory traversal vulnerability in the CIM server in IBM Director before 5.20.3 Service Update 2 on Windows allows remote attackers to load and execute arbitrary local DLL code via a .. (dot dot) in a /CIMListener/ URI in an M-POST request.
CVE-2009-0457 1 Magtrb 1 Aja Portal 2025-04-09 7.5 HIGH N/A
Multiple directory traversal vulnerabilities in AJA Portal 1.2 allow remote attackers to include and execute arbitrary local files via directory traversal sequences in the currentlang parameter to admin/case.php in the (1) Contact_Plus and (2) Reviews modules, and (3) the module_name parameter to admin/includes/FANCYNLOptions.php in the Fancy_NewsLetter module.
CVE-2009-2397 1 Audioarticledirectory 1 Audio Article Directory 2025-04-09 5.0 MEDIUM N/A
Directory traversal vulnerability in download.php in Audio Article Directory allows remote attackers to read arbitrary files via directory traversal sequences in the file parameter.
CVE-2008-0393 1 Gradman 1 Gradman 2025-04-09 5.8 MEDIUM N/A
Directory traversal vulnerability in info.php in GradMan 0.1.3 and earlier allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the tabla parameter, a different vector than CVE-2008-0361.
CVE-2007-3874 1 Altiris 1 Deployment Solution 2025-04-09 7.8 HIGH N/A
Directory traversal vulnerability in the tftp/mftp daemon in the PXE server component (pxemtftp.exe) in Symantec Altiris Deployment Solution 6.x before 6.8.380.0 allows remote attackers to read arbitrary files via unspecified vectors.
CVE-2008-2512 1 Symantec 1 Backupexec System Recovery 2025-04-09 5.0 MEDIUM N/A
Directory traversal vulnerability in Symantec Backup Exec System Recovery Manager 7.x before 7.0.4 and 8.x before 8.0.2 allows remote attackers to read arbitrary files via unspecified vectors.
CVE-2009-1319 1 Guestcal 1 Guest Cal 2025-04-09 7.5 HIGH N/A
Directory traversal vulnerability in includes/ini.inc.php in GuestCal 2.1 allows remote attackers to include and execute arbitrary files via a .. (dot dot) in the lang parameter to index.php.
CVE-2007-5463 1 Viart 1 Shop 2025-04-09 5.0 MEDIUM N/A
ideal_process.php in the iDEAL payment module in ViArt Shop 3.3 beta and earlier might allow remote attackers to obtain the pathname for certificate and key files via an "iDEAL transaction", possibly involving fopen error messages for nonexistent files, a different issue than CVE-2007-5364. NOTE: this can be leveraged for reading certificate or key files if an installation places these files under the web document root.
CVE-2008-6453 1 6rbscript 1 6rbscript 2025-04-09 4.3 MEDIUM N/A
Directory traversal vulnerability in section.php in 6rbScript 3.3, when magic_quotes_gpc is disabled, allows remote attackers to read arbitrary files via a .. (dot dot) in the name parameter.
CVE-2009-1407 1 Wonko 1 Notftp 2025-04-09 6.8 MEDIUM N/A
Directory traversal vulnerability in config.php in NotFTP 1.3.1 allows remote attackers to read arbitrary files via a .. (dot dot) in a certain languages[][file] parameter.
CVE-2009-2258 1 Netgear 2 Dg632, Dg632 Firmware 2025-04-09 7.8 HIGH N/A
Directory traversal vulnerability in cgi-bin/webcm in the administrative web interface on the Netgear DG632 with firmware 3.4.0_ap allows remote attackers to list arbitrary directories via a .. (dot dot) in the nextpage parameter.
CVE-2008-4501 1 Solarwinds 1 Serv-u File Server 2025-04-09 9.0 HIGH N/A
Directory traversal vulnerability in the FTP server in Serv-U 7.0.0.1 through 7.3, including 7.2.0.1, allows remote authenticated users to overwrite or create arbitrary files via a ..\ (dot dot backslash) in the RNTO command.
CVE-2008-5265 1 Tntforum 1 Tnt Forum 2025-04-09 6.8 MEDIUM N/A
Directory traversal vulnerability in index.php in TNT Forum 0.9.4, when magic_quotes_gpc is disabled, allows remote attackers to include and execute arbitrary local files via directory traversal sequences in the modulo parameter.
CVE-2009-3123 1 Visavi 1 Wap-motor 2025-04-09 5.0 MEDIUM N/A
Directory traversal vulnerability in gallery/gallery.php in Wap-Motor before 18.1 allows remote attackers to read arbitrary files via a .. (dot dot) in the image parameter.
CVE-2008-2665 1 Php 1 Php 2025-04-09 5.0 MEDIUM N/A
Directory traversal vulnerability in the posix_access function in PHP 5.2.6 and earlier allows remote attackers to bypass safe_mode restrictions via a .. (dot dot) in an http URL, which results in the URL being canonicalized to a local filename after the safe_mode check has successfully run.
CVE-2008-1178 1 Centreon 1 Centreon 2025-04-09 4.3 MEDIUM N/A
Directory traversal vulnerability in include/doc/index.php in Centreon 1.4.2.3 and earlier allows remote attackers to read arbitrary files via a .. (dot dot) in the page parameter, a different vector than CVE-2008-1119.
CVE-2008-6878 1 Zen Cart 1 Zen Cart 2025-04-09 6.8 MEDIUM N/A
Directory traversal vulnerability in admin/includes/languages/english.php in Zen Cart 1.3.8a, 1.3.8, and earlier, when .htaccess is not supported, allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the _SESSION[language] parameter. NOTE: the vendor disputes this issue, stating "at worst, the use of this vulnerability will reveal some local file paths.
CVE-2008-7084 1 Hirschelectronics 1 Velocity Security Management System 2025-04-09 5.0 MEDIUM N/A
Directory traversal vulnerability in the web server 1.0 in Velocity Security Management System allows remote attackers to read arbitrary files via a .. (dot dot) in the URI.