Total
7067 CVE
CVE | Vendors | Products | Updated | CVSS v3.1 |
---|---|---|---|---|
CVE-2016-10400 | 1 Atutor | 1 Atutor | 2024-11-21 | N/A |
Directory Traversal exists in ATutor before 2.2.2 via the icon parameter to /mods/_core/courses/users/create_course.php. The attacker can read an arbitrary file by visiting get_course_icon.php?id= after the traversal attack. | ||||
CVE-2016-10367 | 1 Opsview | 1 Opsview | 2024-11-21 | N/A |
In Opsview Monitor Pro (Prior to 5.1.0.162300841, prior to 5.0.2.27475, prior to 4.6.4.162391051, and 4.5.x without a certain 2016 security patch), an unauthenticated Directory Traversal vulnerability can be exploited by issuing a specially crafted HTTP GET request utilizing a simple URL encoding bypass, %252f instead of /. | ||||
CVE-2016-10331 | 1 Synology | 1 Photo Station | 2024-11-21 | N/A |
Directory traversal vulnerability in download.php in Synology Photo Station before 6.5.3-3226 allows remote attackers to read arbitrary files via a full pathname in the id parameter. | ||||
CVE-2016-10330 | 1 Synology | 1 Photo Station | 2024-11-21 | N/A |
Directory traversal vulnerability in synophoto_dsm_user, a SUID program, as used in Synology Photo Station before 6.5.3-3226 allows local users to write to arbitrary files via unspecified vectors. | ||||
CVE-2016-10184 | 1 Dlink | 2 Dwr-932b, Dwr-932b Firmware | 2024-11-21 | 7.5 High |
An issue was discovered on the D-Link DWR-932B router. qmiweb allows file reading with ..%2f traversal. | ||||
CVE-2016-10183 | 1 Dlink | 2 Dwr-932b, Dwr-932b Firmware | 2024-11-21 | 7.5 High |
An issue was discovered on the D-Link DWR-932B router. qmiweb allows directory listing with ../ traversal. | ||||
CVE-2016-10173 | 1 Minitar | 2 Archive-tar-minitar, Minitar | 2024-11-21 | N/A |
Directory traversal vulnerability in the minitar before 0.6 and archive-tar-minitar 0.5.2 gems for Ruby allows remote attackers to write to arbitrary files via a .. (dot dot) in a TAR archive entry. | ||||
CVE-2016-10106 | 1 Netgear | 8 Fvs318gv2, Fvs318gv2 Firmware, Fvs318n and 5 more | 2024-11-21 | N/A |
Directory traversal vulnerability in scgi-bin/platform.cgi on NETGEAR FVS336Gv3, FVS318N, FVS318Gv2, and SRX5308 devices with firmware before 4.3.3-8 allows remote authenticated users to read arbitrary files via a .. (dot dot) in the thispage parameter, as demonstrated by reading the /etc/shadow file. | ||||
CVE-2016-10048 | 2 Imagemagick, Opensuse Project | 2 Imagemagick, Leap | 2024-11-21 | N/A |
Directory traversal vulnerability in magick/module.c in ImageMagick 6.9.4-7 allows remote attackers to load arbitrary modules via unspecified vectors. | ||||
CVE-2016-10039 | 1 Modx | 1 Modx Revolution | 2024-11-21 | 7.3 High |
Directory traversal in /connectors/index.php in MODX Revolution before 2.5.2-pl allows remote attackers to perform local file inclusion/traversal/manipulation via a crafted dir parameter, related to browser/directory/getfiles. | ||||
CVE-2016-10038 | 1 Modx | 1 Modx Revolution | 2024-11-21 | N/A |
Directory traversal in /connectors/index.php in MODX Revolution before 2.5.2-pl allows remote attackers to perform local file inclusion/traversal/manipulation via a crafted dir parameter, related to browser/directory/remove. | ||||
CVE-2016-10037 | 1 Modx | 1 Modx Revolution | 2024-11-21 | 7.3 High |
Directory traversal in /connectors/index.php in MODX Revolution before 2.5.2-pl allows remote attackers to perform local file inclusion/traversal/manipulation via a crafted id (aka dir) parameter, related to browser/directory/getlist. | ||||
CVE-2016-1000112 | 1 Contussupport | 1 Contus-video-comments | 2024-11-21 | 9.1 Critical |
Unauthenticated remote .jpg file upload in contus-video-comments v1.0 wordpress plugin | ||||
CVE-2016-0855 | 1 Advantech | 1 Webaccess | 2024-11-21 | N/A |
Directory traversal vulnerability in Advantech WebAccess before 8.1 allows remote attackers to list arbitrary virtual-directory files via unspecified vectors. | ||||
CVE-2016-0784 | 1 Apache | 1 Openmeetings | 2024-11-21 | N/A |
Directory traversal vulnerability in the Import/Export System Backups functionality in Apache OpenMeetings before 3.1.1 allows remote authenticated administrators to write to arbitrary files via a .. (dot dot) in a ZIP archive entry. | ||||
CVE-2016-0709 | 1 Apache | 1 Jetspeed | 2024-11-21 | N/A |
Directory traversal vulnerability in the Import/Export function in the Portal Site Manager in Apache Jetspeed before 2.3.1 allows remote authenticated administrators to write to arbitrary files, and consequently execute arbitrary code, via a .. (dot dot) in a ZIP archive entry, as demonstrated by "../../webapps/x.jsp." | ||||
CVE-2015-9546 | 1 Google | 1 Android | 2024-11-21 | 4.8 Medium |
An issue was discovered on Samsung mobile devices with KK(4.4) and later software through 2015-06-16. In some cases, HTTP is used for an Inputmethod, rather than HTTPS. A man-in-the-middle attacker can modify the client-server data stream to insert directory traversal sequences into an extracted file path. The Samsung ID is SVE-2015-4363 (November 2015). | ||||
CVE-2015-9538 | 1 Imagely | 1 Nextgen Gallery | 2024-11-21 | 6.5 Medium |
The NextGEN Gallery plugin before 2.1.15 for WordPress allows ../ Directory Traversal in path selection. | ||||
CVE-2015-9480 | 1 Robot-cpa | 1 Robotcpa | 2024-11-21 | 7.5 High |
The RobotCPA plugin 5 for WordPress has directory traversal via the f.php l parameter. | ||||
CVE-2015-9473 | 1 Estrutura-basica Project | 1 Estrutura-basica | 2024-11-21 | 7.5 High |
The estrutura-basica theme through 2015-09-13 for WordPress has directory traversal via the scripts/download.php arquivo parameter. |