Vulnerabilities (CVE)

Filtered by CWE-22
Total 7439 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2008-4151 1 Cyask 1 Cyask 2025-04-09 5.0 MEDIUM N/A
Directory traversal vulnerability in collect.php in CYASK 3.x allows remote attackers to read arbitrary files via a .. (dot dot) in the neturl parameter.
CVE-2008-3677 1 Openfreeway 1 Freeway 2025-04-09 6.8 MEDIUM N/A
Directory traversal vulnerability in includes/events_application_top.php in Freeway before 1.4.2.197 allows remote attackers to include and execute arbitrary local files via unspecified vectors.
CVE-2008-2116 1 Scriptsez 1 Power Editor 2025-04-09 4.4 MEDIUM N/A
Multiple directory traversal vulnerabilities in editor.php in ScriptsEZ.net Power Editor 2.0 allow remote attackers to read arbitrary local files via a .. (dot dot) in the (1) te and (2) dir parameters in a tempedit action.
CVE-2008-2415 1 Digitalhive 1 Digitalhive 2025-04-09 6.8 MEDIUM N/A
Directory traversal vulnerability in template/purpletech/base_include.php in DigitalHive (aka hive) 2.0 RC2 allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the page parameter.
CVE-2007-6651 1 Bitweaver 1 Bitweaver 2025-04-09 5.0 MEDIUM N/A
Directory traversal vulnerability in wiki/edit.php in Bitweaver R2 CMS allows remote attackers to obtain sensitive information (script source code) via a .. (dot dot) in the suck_url parameter.
CVE-2008-5771 1 Phpweather 1 Phpweather 2025-04-09 7.5 HIGH N/A
Directory traversal vulnerability in test.php in PHP Weather 2.2.2 allows remote attackers to include and execute arbitrary local files via directory traversal sequences in the language parameter.
CVE-2008-0184 1 Prenotazioni On Line 1 Syshotel On Line System 2025-04-09 6.4 MEDIUM N/A
Absolute path traversal vulnerability in index.php in Sys-Hotel on Line System allows remote attackers to read arbitrary files via an encoded "/" ("%2F") in the file parameter.
CVE-2009-4426 1 Launchpad 1 Ignition 2025-04-09 6.8 MEDIUM N/A
Multiple directory traversal vulnerabilities in Ignition 1.2, when magic_quotes_gpc is disabled, allow remote attackers to include and execute arbitrary local files via a .. (dot dot) in the blog parameter to (1) comment.php and (2) view.php.
CVE-2008-0479 1 Web Wiz 1 Newspad 2025-04-09 5.0 MEDIUM N/A
Directory traversal vulnerability in RTE_file_browser.asp in Web Wiz NewsPad 1.02 allows remote attackers to list arbitrary directories, and .txt and .zip files, via a .....\\\ in the sub parameter.
CVE-2008-7055 1 Visualshapers 1 Ezcontents 2025-04-09 5.1 MEDIUM N/A
module.php in ezContents 2.0.3 allows remote attackers to bypass the directory traversal protection mechanism to include and execute arbitrary local files via "....//" (doubled dot dot slash) sequences in the link parameter, which is not properly filtered using the str_replace function.
CVE-2007-5742 1 Wesnoth 1 Wesnoth 2025-04-09 9.0 HIGH N/A
Directory traversal vulnerability in the WML engine preprocessor for Wesnoth 1.2.x before 1.2.8, and 1.3.x before 1.3.12, allows remote attackers to read arbitrary files via ".." sequences in unknown vectors.
CVE-2008-0156 1 Million Dollar Script 1 Million Dollar Script 2025-04-09 5.0 MEDIUM N/A
Absolute path traversal vulnerability in index.php in Million Dollar Script 2.0.14 allows remote attackers to read arbitrary files via encoded "/" (%2F) sequences in the link parameter.
CVE-2009-2333 1 Cms.tut.su 1 Cms Chainuk 2025-04-09 7.5 HIGH N/A
Multiple directory traversal vulnerabilities in CMS Chainuk 1.2 and earlier allow remote attackers to include and execute arbitrary local files via a .. (dot dot) in (1) the menu parameter to admin/admin_menu.php, and the id parameter to (2) index.php and (3) admin/admin_edit.php; and (4) delete arbitrary local files via a .. (dot dot) in the id parameter to admin/admin_delete.php. NOTE: vector 2 can be leveraged for static code injection by sending a crafted menu parameter to admin/admin_menu.php, and then sending an id=../menu.csv request to index.php.
CVE-2009-3664 1 Nullam 1 Nullam Blog 2025-04-09 7.5 HIGH N/A
Multiple directory traversal vulnerabilities in index.php in Nullam Blog 0.1.2 allow remote attackers to include or execute arbitrary files via a .. (dot dot) in the (1) p and (2) s parameters.
CVE-2008-1301 1 Alkacon 1 Opencms 2025-04-09 4.0 MEDIUM N/A
Absolute path traversal vulnerability in system/workplace/admin/workplace/logfileview/logfileViewSettings.jsp in Alkacon OpenCms 7.0.3 and 7.0.4 allows remote authenticated administrators to read arbitrary files via a full pathname in the filePath.0 parameter.
CVE-2008-1410 1 Acronis 1 Snap Deploy 2025-04-09 4.3 MEDIUM N/A
Directory traversal vulnerability in the PXE Server (pxesrv.exe) in Acronis Snap Deploy 2.0.0.1076 and earlier allows remote attackers to read arbitrary files via directory traversal sequences to the TFTP service.
CVE-2007-4559 1 Python 1 Python 2025-04-09 6.8 MEDIUM 9.8 CRITICAL
Directory traversal vulnerability in the (1) extract and (2) extractall functions in the tarfile module in Python allows user-assisted remote attackers to overwrite arbitrary files via a .. (dot dot) sequence in filenames in a TAR archive, a related issue to CVE-2001-1267.
CVE-2007-6322 1 Xml2owl 1 Xml2owl 2025-04-09 5.0 MEDIUM N/A
Directory traversal vulnerability in filedownload.php in xml2owl 0.1.1 allows remote attackers to read arbitrary files via a .. (dot dot) in the file parameter.
CVE-2009-1760 1 Rasterbar Software 1 Libtorrent 2025-04-09 5.8 MEDIUM N/A
Directory traversal vulnerability in src/torrent_info.cpp in Rasterbar libtorrent before 0.14.4, as used in firetorrent, qBittorrent, deluge Torrent, and other applications, allows remote attackers to create or overwrite arbitrary files via a .. (dot dot) and partial relative pathname in a Multiple File Mode list element in a .torrent file.
CVE-2008-5645 1 Orb Networks 1 Orb 2025-04-09 7.8 HIGH N/A
Directory traversal vulnerability in the media server in Orb Networks Orb before 2.01.0022 allows remote attackers to read arbitrary files via directory traversal sequences in an HTTP GET request.