Vulnerabilities (CVE)

Filtered by CWE-22
Total 7186 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2007-6376 1 Francisco Burzi 1 Php-nuke 2025-04-09 7.5 HIGH N/A
Directory traversal vulnerability in autohtml.php in Francisco Burzi PHP-Nuke 8.0 allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the filename parameter, a different vector than CVE-2006-4190. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.
CVE-2009-1090 1 Rapidleech 1 Rapidleech 2025-04-09 6.8 MEDIUM N/A
Directory traversal vulnerability in upload.php in Rapidleech rev.36 and earlier allows remote attackers to include and execute arbitrary local files via directory traversal sequences in the uploaded parameter.
CVE-2008-2969 1 Yektaweb 1 Academic Web Tools 2025-04-09 5.0 MEDIUM N/A
Directory traversal vulnerability in download.php in Academic Web Tools (AWT YEKTA) 1.4.3.1, and 1.4.2.8 and earlier, allows remote attackers to read arbitrary files via a .. (dot dot) in the dfile parameter.
CVE-2008-5968 1 Phpicalendar 1 Phpicalendar 2025-04-09 7.5 HIGH N/A
Directory traversal vulnerability in print.php in PHP iCalendar 2.24 and earlier allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the cookie_language parameter in a phpicalendar_* cookie, a different vector than CVE-2006-1292.
CVE-2009-4374 1 Alienvault 1 Open Source Security Information Management 2025-04-09 7.5 HIGH N/A
Directory traversal vulnerability in repository/repository_attachment.php in AlienVault Open Source Security Information Management (OSSIM) 2.1.5, and possibly other versions before 2.1.5-4, allows remote attackers to upload files into arbitrary directories via a .. (dot dot) in the id_document parameter.
CVE-2007-5092 1 Multimedia 1 Dance Music Module For Phpnuke 2025-04-09 6.8 MEDIUM N/A
Directory traversal vulnerability in index.php in the Dance Music module for phpNuke, when register_globals is enabled, allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in an ACCEPT_FILE array parameter to modules.php.
CVE-2009-1936 1 Cpcommerce Project 1 Cpcommerce 2025-04-09 6.8 MEDIUM 9.8 CRITICAL
_functions.php in cpCommerce 1.2.x, possibly including 1.2.9, sends a redirect but does not exit when it is called directly, which allows remote attackers to bypass a protection mechanism to conduct remote file inclusion and directory traversal attacks, execute arbitrary PHP code, or read arbitrary files via the GLOBALS[prefix] parameter, a different vector than CVE-2003-1500.
CVE-2008-1751 1 Ksemail 1 Ksemail 2025-04-09 6.8 MEDIUM N/A
Multiple directory traversal vulnerabilities in index.php in Ksemail allow remote attackers to read arbitrary local files via a .. (dot dot) in the (1) language and (2) lang parameters.
CVE-2008-5291 1 Fuzzylime 1 Fuzzylime Cms 2025-04-09 7.5 HIGH N/A
Directory traversal vulnerability in code/track.php in FuzzyLime 3.03 allows remote attackers to include and execute arbitrary local files via directory traversal sequences in the p parameter, a different vector than CVE-2007-4805 and CVE-2008-3165.
CVE-2009-0932 1 Debian 2 Horde, Horde Groupware 2025-04-09 6.4 MEDIUM N/A
Directory traversal vulnerability in framework/Image/Image.php in Horde before 3.2.4 and 3.3.3 and Horde Groupware before 1.1.5 allows remote attackers to include and execute arbitrary local files via directory traversal sequences in the Horde_Image driver name.
CVE-2008-3675 1 Gelatocms 1 Gelatocms 2025-04-09 5.0 MEDIUM N/A
Directory traversal vulnerability in classes/imgsize.php in Gelato 0.95 allows remote attackers to read arbitrary files via (1) a .. (dot dot) and possibly (2) a full pathname in the img parameter. NOTE: some of these details are obtained from third party information.
CVE-2009-1089 1 Rapidleech 1 Rapidleech 2025-04-09 5.0 MEDIUM N/A
Absolute path traversal vulnerability in upload.php in Rapidleech rev.36 and earlier allows remote attackers to read arbitrary files via a base64-encoded absolute path in the filename parameter.
CVE-2007-4820 1 Sisfo Kampus 1 Sisfo Kampus 2025-04-09 7.5 HIGH N/A
Absolute path traversal vulnerability in blanko.preview.php in Sisfo Kampus 2006 allows remote attackers to read arbitrary local files, and possibly execute local PHP scripts, via the nmf parameter.
CVE-2009-2922 1 Pixaria 1 Pixaria Gallery 2025-04-09 7.8 HIGH N/A
Absolute path traversal vulnerability in pixaria.image.php in Pixaria Gallery 2.0.0 through 2.3.5 allows remote attackers to read arbitrary files via a base64-encoded file parameter.
CVE-2008-7064 1 Quicksilver Forums 1 Quicksilver Forums 2025-04-09 7.5 HIGH N/A
Directory traversal vulnerability in the get_lang function in global.php in Quicksilver Forums 1.4.2 and earlier, as used in QSF Portal before 1.4.5, when running on Windows, allows remote attackers to include and execute arbitrary local files via a "\" (backslash) in the lang parameter to index.php, which bypasses a protection mechanism that only checks for "/" (forward slash), as demonstrated by uploading and including PHP code in an avatar file.
CVE-2006-5487 1 Marshal 1 Mailmarshal Smtp 2025-04-09 10.0 HIGH N/A
Directory traversal vulnerability in Marshal MailMarshal SMTP 5.x, 6.x, and 2006, and MailMarshal for Exchange 5.x, allows remote attackers to write arbitrary files via ".." sequences in filenames in an ARJ compressed archive.
CVE-2007-5706 1 Jeeblestechnology 1 Jeebles Directory 2025-04-09 9.3 HIGH N/A
Absolute path traversal vulnerability in download.php in Jeebles Directory 2.9.60 allows remote attackers to read arbitrary files via a full pathname in the query string. NOTE: some of these details are obtained from third party information.
CVE-2008-4913 1 Lokicms 1 Lokicms 2025-04-09 5.0 MEDIUM N/A
Directory traversal vulnerability in admin.php in LokiCMS 0.3.3 and earlier allows remote attackers to delete arbitrary files via a .. (dot dot) in the delete parameter.
CVE-2009-4383 1 Rocomotion 1 P Forum 2025-04-09 5.0 MEDIUM N/A
Directory traversal vulnerability in Pforum.php in Rocomotion P forum before 1.28 allows remote attackers to read arbitrary files via directory traversal sequences in unspecified vectors.
CVE-2008-3365 2 Microsoft, Pixelpost 7 Windows, Windows-nt, Windows 2000 and 4 more 2025-04-09 6.8 MEDIUM N/A
Directory traversal vulnerability in index.php in Pixelpost 1.7.1 on Windows, when register_globals is enabled, allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the language_full parameter.