Vulnerabilities (CVE)

Filtered by CWE-22
Total 7227 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2008-5794 1 Lovecms 1 Lovecms 2025-04-09 5.0 MEDIUM N/A
Directory traversal vulnerability in system/admin/images.php in LoveCMS 1.6.2 Final allows remote attackers to delete arbitrary files via a .. (dot dot) in the delete parameter.
CVE-2008-0488 1 Vb Marketing 1 Vb Marketing 2025-04-09 7.5 HIGH N/A
Directory traversal vulnerability in tseekdir.cgi in VB Marketing allows remote attackers to include and execute arbitrary local files via directory traversal sequences in the location parameter.
CVE-2008-0703 1 Sflog 1 Sflog 2025-04-09 5.0 MEDIUM N/A
Multiple directory traversal vulnerabilities in sflog! 0.96 allow remote attackers to read arbitrary files via a .. (dot dot) in the (1) permalink or (2) section parameter to index.php, possibly involving includes/entries.inc.php and other files included by index.php.
CVE-2008-4758 1 Php-daily 1 Php-daily 2025-04-09 5.0 MEDIUM N/A
Directory traversal vulnerability in download_file.php in PHP-Daily allows remote attackers to read arbitrary local files via a .. (dot dot) in the fichier parameter.
CVE-2008-6290 1 Niclor 1 Include Sito 2025-04-09 6.8 MEDIUM N/A
Directory traversal vulnerability in includefile.php in nicLOR Sito, when register_globals is enabled or magic_quotes_gpc is disabled, allows remote attackers to include and execute arbitrary files via a .. (dot dot) in the page_file parameter.
CVE-2009-4116 1 Cutephp 1 Cutenews 2025-04-09 3.5 LOW N/A
Multiple directory traversal vulnerabilities in CutePHP CuteNews 1.4.6, when magic_quotes_gpc is disabled, allow remote authenticated users with editor or administrative application access to read arbitrary files via a .. (dot dot) in the source parameter in a (1) list or (2) editnews action to the Editnews module, and (3) the save_con[skin] parameter in the Options module. NOTE: vector 3 can be leveraged for code execution by using a .. to include and execute arbitrary local files.
CVE-2008-6201 1 Kwsphp 1 Kwsphp 2025-04-09 6.8 MEDIUM N/A
Directory traversal vulnerability in help.php in the eskuel module in KwsPHP 1.3.456, as available before 20080416, allows remote attackers to execute arbitrary commands via the action parameter. NOTE: some of these details are obtained from third party information.
CVE-2006-5846 1 Freewebshop 1 Freewebshop 2025-04-09 6.4 MEDIUM N/A
Directory traversal vulnerability in index.php in FreeWebshop 2.2.2 and earlier allows remote attackers to read and include arbitrary files via a .. (dot dot) in the page parameter, a different vector than CVE-2006-5773.
CVE-2008-4632 1 Kure 1 Kure 2025-04-09 6.8 MEDIUM N/A
Multiple directory traversal vulnerabilities in index.php in Kure 0.6.3, when magic_quotes_gpc is disabled, allow remote attackers to read and possibly execute arbitrary local files via a .. (dot dot) in the (1) post and (2) doc parameters.
CVE-2007-5489 1 Artmedic Webdesign 1 Artmedic Cms 2025-04-09 7.5 HIGH N/A
Directory traversal vulnerability in index.php in Artmedic CMS 3.4 and earlier allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the page parameter.
CVE-2009-0271 1 Fujitsu 1 Systemcastwizard Lite 2025-04-09 5.0 MEDIUM N/A
Directory traversal vulnerability in the TFTP service in Fujitsu SystemcastWizard Lite 2.0A, 2.0, 1.9, and earlier allows remote attackers to read arbitrary files via directory traversal sequences in unspecified vectors.
CVE-2007-6624 1 Pnphpbb 1 Pnphpbb 2025-04-09 6.8 MEDIUM N/A
Directory traversal vulnerability in printview.php in PNphpBB2 1.2i and earlier allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the phpEx parameter.
CVE-2009-3181 1 Anantasoft 1 Gazelle Cms 2025-04-09 5.0 MEDIUM N/A
Directory traversal vulnerability in Anantasoft Gazelle CMS 1.0 allows remote attackers to overwrite arbitrary files via a .. (dot dot) in the customizetemplate parameter in a direct request to admin/settemplate.php.
CVE-2008-6195 1 Landesk 1 Landesk Management Suite 2025-04-09 7.8 HIGH N/A
Directory traversal vulnerability in the PXE TFTP Service (PXEMTFTP.exe) in LANDesk Management Suite (LDMS) 8.80.1.1 and earlier allows remote attackers to read arbitrary files via a subdirectory name followed by ".." sequences, a different vulnerability than CVE-2008-1643.
CVE-2008-0797 1 Itheora 1 Itheora 2025-04-09 5.0 MEDIUM N/A
Directory traversal vulnerability in lib/download.php in iTheora 1.0 rc1 allows remote attackers to read arbitrary files via directory traversal sequences in the url parameter.
CVE-2007-5461 1 Apache 1 Tomcat 2025-04-09 3.5 LOW N/A
Absolute path traversal vulnerability in Apache Tomcat 4.0.0 through 4.0.6, 4.1.0, 5.0.0, 5.5.0 through 5.5.25, and 6.0.0 through 6.0.14, under certain configurations, allows remote authenticated users to read arbitrary files via a WebDAV write request that specifies an entity with a SYSTEM tag.
CVE-2009-2161 1 Torrenttrader 1 Torrenttrader Classic 2025-04-09 5.1 MEDIUM N/A
Directory traversal vulnerability in backend/admin-functions.php in TorrentTrader Classic 1.09, when used on a case-insensitive web site, allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the ss_uri parameter, in conjunction with a modified component name.
CVE-2009-3534 1 Lionwiki 1 Lionwiki 2025-04-09 6.8 MEDIUM N/A
Directory traversal vulnerability in index.php in LionWiki 3.0.3, when magic_quotes_gpc is disabled, allows remote attackers to read arbitrary files via a .. (dot dot) in the page parameter.
CVE-2007-6672 1 Mortbay Jetty 1 Jetty 2025-04-09 5.0 MEDIUM N/A
Mortbay Jetty 6.1.5 and 6.1.6 allows remote attackers to bypass protection mechanisms and read the source of files via multiple '/' (slash) characters in the URI.
CVE-2009-3561 1 Xerver 1 Xerver 2025-04-09 5.0 MEDIUM N/A
Directory traversal vulnerability in Xerver HTTP Server 4.32 allows remote attackers to read arbitrary files via a full pathname with a drive letter in the currentPath parameter in a chooseDirectory action.