Vulnerabilities (CVE)

Filtered by CWE-22
Total 7022 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2008-2985 1 Cmreams 1 Cmreams Cms 2025-04-09 6.8 MEDIUM N/A
Directory traversal vulnerability in load_language.php in CMReams CMS 1.3.1.1 Beta 2, when register_globals is enabled, allows remote attackers to include and execute arbitrary local files via directory traversal sequences in the page_language parameter.
CVE-2007-3487 1 Hp 1 Photo Digital Imaging Activex Control 2025-04-09 6.4 MEDIUM N/A
Absolute path traversal in a certain ActiveX control in hpqxml.dll 2.0.0.133 in Hewlett-Packard (HP) Photo Digital Imaging allows remote attackers to create or overwrite arbitrary files via the argument to the saveXMLAsFile method.
CVE-2008-5201 1 Otmanager 1 Otmanager Cms 2025-04-09 7.5 HIGH N/A
Directory traversal vulnerability in index.php in OTManager CMS 24a allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the conteudo parameter. NOTE: in some environments, this can be leveraged for remote file inclusion by using a UNC share pathname or an ftp, ftps, or ssh2.sftp URL.
CVE-2008-0427 1 Bloo 1 Bloofoxcms 2025-04-09 7.8 HIGH N/A
Directory traversal vulnerability in file.php in bloofoxCMS 0.3 allows remote attackers to read arbitrary files via a .. (dot dot) in the file parameter.
CVE-2008-1231 1 Jspwiki 1 Jspwiki 2025-04-09 9.3 HIGH N/A
Directory traversal vulnerability in Edit.jsp in JSPWiki 2.4.104 and 2.5.139 allows remote attackers to include and execute arbitrary local .jsp files, and obtain sensitive information, via a .. (dot dot) in the editor parameter.
CVE-2008-0396 1 Bitdefender 1 Update Server 2025-04-09 7.8 HIGH N/A
Directory traversal vulnerability in BitDefender Update Server (http.exe), as used in BitDefender products including Security for Fileservers and Enterprise Manager (BDEM), allows remote attackers to read arbitrary files via .. (dot dot) sequences in an HTTP request.
CVE-2009-1222 1 Webedition 1 Webedition 2025-04-09 5.1 MEDIUM N/A
Directory traversal vulnerability in index.php in webEdition 6.0.0.4 and earlier, when register_globals is enabled and magic_quotes_gpc is disabled, allows remote attackers to include and execute arbitrary files via a .. (dot dot) in the WE_LANGUAGE parameter.
CVE-2008-2076 1 Actualscripts 1 Actualanalyzer Lite 2025-04-09 7.5 HIGH N/A
Directory traversal vulnerability in admin.php in ActualScripts ActualAnalyzer Lite 2.78 allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the style parameter.
CVE-2007-4764 1 Pawfaliki 1 Pawfaliki 2025-04-09 5.0 MEDIUM N/A
Directory traversal vulnerability in pawfaliki.php in Pawfaliki 0.5.1 allows remote attackers to list arbitrary files via a .. (dot dot) in the page parameter. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.
CVE-2009-0330 1 Wss-pro 1 Scms 2025-04-09 6.8 MEDIUM N/A
Directory traversal vulnerability in index.php in Simple Content Management System (SCMS) 1 allows remote attackers to include and execute arbitrary local files via directory traversal sequences in the p parameter.
CVE-2008-1884 1 Wikepage 1 Opus 2025-04-09 5.0 MEDIUM N/A
Directory traversal vulnerability in index.php in Wikepage Opus 13 2007.2 allows remote attackers to read arbitrary files via directory traversal sequences in the wiki parameter, a different vector than CVE-2006-4418.
CVE-2008-1281 1 Argontechnology 1 Client Management Services 2025-04-09 5.0 MEDIUM N/A
Directory traversal vulnerability in TFTPsrvs.exe 2.5.3.1 and earlier, as used in Argon Technology Client Management Services (CMS) 1.31 and earlier, allows remote attackers to read arbitrary files via a .. (dot dot) in the filename parameter.
CVE-2008-3371 1 Talkback 1 Talkback 2025-04-09 7.5 HIGH N/A
Directory traversal vulnerability in install/help.php in TalkBack 2.3.5, and other versions before 2.3.6.2, allows remote attackers to include and execute arbitrary local files via directory traversal sequences in the language parameter.
CVE-2008-4243 1 Epic Games 1 Unreal Tournament 3 2025-04-09 7.8 HIGH N/A
Directory traversal vulnerability in ImageServer (aka UTImageServer) in WebAdmin before 1.7 for Epic Games Unreal Tournament 3 (UT3) 1.3 allows remote attackers to read arbitrary files via a .. (dot dot) in the URI.
CVE-2009-1523 1 Mortbay 1 Jetty 2025-04-09 5.0 MEDIUM N/A
Directory traversal vulnerability in the HTTP server in Mort Bay Jetty 5.1.14, 6.x before 6.1.17, and 7.x through 7.0.0.M2 allows remote attackers to access arbitrary files via directory traversal sequences in the URI.
CVE-2008-5989 1 Phpcounter 1 Phpcounter 2025-04-09 6.8 MEDIUM N/A
Directory traversal vulnerability in defs.php in PHPcounter 1.3.2 and earlier, when magic_quotes_gpc is disabled, allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the l parameter.
CVE-2009-0423 1 Kevin Walker 1 Php Photo Album 2025-04-09 7.5 HIGH N/A
Directory traversal vulnerability in index.php in Php Photo Album (PHPPA) 0.8 BETA allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the preview parameter.
CVE-2007-4008 1 Entertainment Cms 1 Entertainment Cms 2025-04-09 7.5 HIGH N/A
Directory traversal vulnerability in custom.php in Entertainment Media Sharing CMS allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the pagename parameter.
CVE-2009-1779 1 Frax 1 Php Recommend 2025-04-09 7.5 HIGH N/A
PHP remote file inclusion vulnerability in admin.php in Frax.dk Php Recommend 1.3 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the form_include_template parameter.
CVE-2008-5856 1 Class 1 Class 2025-04-09 5.0 MEDIUM N/A
Directory traversal vulnerability in scripts/export.php in ClaSS before 0.8.61 allows remote attackers to read arbitrary files via directory traversal sequences in the ftype parameter.