Vulnerabilities (CVE)

Filtered by CWE-22
Total 7182 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2018-16473 1 Takeapeek Project 1 Takeapeek 2024-11-21 5.0 MEDIUM 5.3 MEDIUM
A path traversal in takeapeek module versions <=0.2.2 allows an attacker to list directory and files.
CVE-2018-16457 1 Open Source Real-estate Script Project 1 Open Source Real-estate Script 2024-11-21 5.0 MEDIUM 5.3 MEDIUM
PHP Scripts Mall Open Source Real-estate Script 3.6.2 allows remote attackers to list the wp-content/themes/template_dp_dec2015/img directory.
CVE-2018-16446 1 Seamcms 1 Seacms 2024-11-21 6.4 MEDIUM 7.5 HIGH
An issue was discovered in SeaCMS through 6.61. adm1n/admin_database.php allows remote attackers to delete arbitrary files via directory traversal sequences in the bakfiles parameter. This can allow the product to be reinstalled by deleting install_lock.txt.
CVE-2018-16437 1 Gxlcms 1 Gxlcms 2024-11-21 4.0 MEDIUM 4.9 MEDIUM
Gxlcms 2.0 before bug fix 20180915 has Directory Traversal exploitable by an administrator.
CVE-2018-16367 1 Qduoj 1 Onlinejudge 2024-11-21 9.0 HIGH 9.9 CRITICAL
In OnlineJudge 2.0, the sandbox has an incorrect access control vulnerability that can write a file anywhere. A user can write a directory listing to /tmp, and can leak file data with a #include.
CVE-2018-16344 1 Zzcms 1 Zzcms 2024-11-21 6.4 MEDIUM 7.5 HIGH
An issue was discovered in zzcms 8.3. It allows remote attackers to delete arbitrary files via directory traversal sequences in the flv parameter. This can be leveraged for database access by deleting install.lock.
CVE-2018-16320 1 Idreamsoft 1 Icms 2024-11-21 6.5 MEDIUM 7.2 HIGH
idreamsoft iCMS 7.0.11 allows admincp.php?app=config Directory Traversal, resulting in execution of arbitrary PHP code from a ZIP file.
CVE-2018-16299 1 Localize My Post Project 1 Localize My Post 2024-11-21 5.0 MEDIUM 7.5 HIGH
The Localize My Post plugin 1.0 for WordPress allows Directory Traversal via the ajax/include.php file parameter.
CVE-2018-16283 1 Wechat Brodcast Project 1 Wechat Brodcast 2024-11-21 7.5 HIGH 9.8 CRITICAL
The Wechat Broadcast plugin 1.2.0 and earlier for WordPress allows Directory Traversal via the Image.php url parameter.
CVE-2018-16237 1 Damicms 1 Damicms 2024-11-21 4.0 MEDIUM 2.7 LOW
An issue was discovered in damiCMS V6.0.1. There is Directory Traversal via '|' characters in the s parameter to admin.php, as demonstrated by an admin.php?s=Tpl/Add/id/c:|windows|win.ini URI.
CVE-2018-16221 1 Yealink 2 Ultra-elegant Ip Phone Sip-t41p, Ultra-elegant Ip Phone Sip-t41p Firmware 2024-11-21 7.7 HIGH 8.0 HIGH
The diagnostics web interface in the Yeahlink Ultra-elegant IP Phone SIP-T41P (firmware 66.83.0.35) does not validate (escape) the path information (path traversal), which allows an authenticated remote attacker to get access to privileged information (e.g., /etc/passwd) via path traversal (relative path information in the file parameter of the corresponding POST request).
CVE-2018-16202 1 Ionicframework 1 Ionic Web View 2024-11-21 5.0 MEDIUM 8.6 HIGH
Directory traversal vulnerability in cordova-plugin-ionic-webview versions prior to 2.2.0 (not including 2.0.0-beta.0, 2.0.0-beta.1, 2.0.0-beta.2, and 2.1.0-0) allows remote attackers to access arbitrary files via unspecified vectors.
CVE-2018-16171 2 Cybozu, Microsoft 2 Remote Service Manager, Windows 2024-11-21 6.8 MEDIUM 8.8 HIGH
Directory traversal vulnerability in Cybozu Remote Service 3.0.0 to 3.1.8 allows remote attackers to execute Java code file on the server via unspecified vectors.
CVE-2018-16170 2 Cybozu, Microsoft 2 Remote Service Manager, Windows 2024-11-21 6.5 MEDIUM 8.1 HIGH
Directory traversal vulnerability in Cybozu Remote Service 3.0.0 to 3.1.8 for Windows allows remote authenticated attackers to read arbitrary files via unspecified vectors.
CVE-2018-16141 1 Thinkcmf 1 Thinkcmfx 2024-11-21 5.5 MEDIUM 6.5 MEDIUM
ThinkCMF X2.2.3 has an arbitrary file deletion vulnerability in do_avatar in \application\User\Controller\ProfileController.class.php via an imgurl parameter with a ..\ sequence. A member user can delete any file on a Windows server.
CVE-2018-16133 1 Cybrotech 1 Cybrohttpserver 2024-11-21 5.0 MEDIUM 5.3 MEDIUM
Cybrotech CyBroHttpServer 1.0.3 allows Directory Traversal via a ../ in the URI.
CVE-2018-16059 1 Endress 2 Wirelesshart Fieldgate Swg70, Wirelesshart Fieldgate Swg70 Firmware 2024-11-21 5.0 MEDIUM 5.3 MEDIUM
Endress+Hauser WirelessHART Fieldgate SWG70 3.x devices allow Directory Traversal via the fcgi-bin/wgsetcgi filename parameter.
CVE-2018-15810 1 Visiology 1 Flipbox 2024-11-21 5.0 MEDIUM 7.5 HIGH
Visiology Flipbox Software Suite before 2.7.0 allows directory traversal via %5c%2e%2e%2f because it does not sanitize filename parameters.
CVE-2018-15782 1 Rsa 1 Authentication Manager 2024-11-21 7.2 HIGH 7.7 HIGH
The Quick Setup component of RSA Authentication Manager versions prior to 8.4 is vulnerable to a relative path traversal vulnerability. A local attacker could potentially provide an administrator with a crafted license that if used during the quick setup deployment of the initial RSA Authentication Manager system, could allow the attacker unauthorized access to that system.
CVE-2018-15750 1 Saltstack 1 Salt 2024-11-21 5.0 MEDIUM 5.3 MEDIUM
Directory Traversal vulnerability in salt-api in SaltStack Salt before 2017.7.8 and 2018.3.x before 2018.3.3 allows remote attackers to determine which files exist on the server.