Skip to main content

CWE archive

CWE-22 CVEs

Programmatic archive

9,831 CVEs tagged with CWE-221,304 Critical, 4,074 High, 4,022 Medium, 425 Low, 6 Unrated.

CVE-2008-7176

Published Sep 8, 2009

Multiple directory traversal vulnerabilities in Facil CMS 0.1RC allow remote attackers to read arbitrary files via a .. (dot dot) in the (1) change_lang parameter to index.php or…

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2008-7163

Published Sep 4, 2009

Directory traversal vulnerability in mods/Integrated/index.php in SineCMS 2.3.5 and earlier, when register_globals is enabled, allows remote attackers to include and execute arbit…

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2009-3064

Published Sep 3, 2009

Directory traversal vulnerability in debugger/debug_php.php in Ve-EDIT 0.1.4 allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the _GET[fi…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2009-3053

Published Sep 3, 2009

Directory traversal vulnerability in the Agora (com_agora) component 3.0.0b for Joomla! allows remote attackers to include and execute arbitrary local files via directory traversa…

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2009-2968

Published Sep 2, 2009

Directory traversal vulnerability in a support component in the web interface in VMware Studio 2.0 public beta before build 1017-185256 allows remote attackers to upload files to…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2008-7142

Published Sep 1, 2009

Absolute path traversal vulnerability in the Disk Usage module (frontend/x/diskusage/index.html) in cPanel 11.18.3 allows remote attackers to list arbitrary directories via the sh…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2008-7110

Published Aug 28, 2009

Directory traversal vulnerability in the Scanner File Utility (aka listener) in Kyocera Mita (KM) 3.3.0.1 allows remote attackers to upload files to arbitrary locations via a .. (…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2008-7093

Published Aug 26, 2009

Multiple directory traversal vulnerabilities in Unica Affinium Campaign 7.2.1.0.55 allow remote attackers to (1) create arbitrary directories or files via a .. (dot dot) in the fo…

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2008-7090

Published Aug 26, 2009

Multiple directory traversal vulnerabilities in Pligg 9.9 and earlier allow remote attackers to (1) determine the existence of arbitrary files via a .. (dot dot) in the $tb_url va…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2008-7064

Published Aug 25, 2009

Directory traversal vulnerability in the get_lang function in global.php in Quicksilver Forums 1.4.2 and earlier, as used in QSF Portal before 1.4.5, when running on Windows, allo…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2008-7055

Published Aug 24, 2009

module.php in ezContents 2.0.3 allows remote attackers to bypass the directory traversal protection mechanism to include and execute arbitrary local files via "....//" (doubled do…

CVSS 5.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2008-7054

Published Aug 24, 2009

Multiple directory traversal vulnerabilities in ezContents 2.0.3 allow remote attackers to include and execute arbitrary local files via the (1) gsLanguage and (2) language_home p…

CVSS 5.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2009-2931

Published Aug 21, 2009

Directory traversal vulnerability in p.php in SlideShowPro Director 1.1 through 1.3.8 allows remote attackers to read arbitrary files via directory traversal sequences in the a pa…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2009-2925

Published Aug 21, 2009

Directory traversal vulnerability in DJcalendar.cgi in DJCalendar allows remote attackers to read arbitrary files via a .. (dot dot) in the TEMPLATE parameter.

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2009-2923

Published Aug 21, 2009

Multiple directory traversal vulnerabilities in BitmixSoft PHP-Lance 1.52 allow remote attackers to read arbitrary files via a .. (dot dot) in the (1) language parameter to show.p…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2009-2922

Published Aug 21, 2009

Absolute path traversal vulnerability in pixaria.image.php in Pixaria Gallery 2.0.0 through 2.3.5 allows remote attackers to read arbitrary files via a base64-encoded file paramet…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2009-1873

Published Aug 18, 2009

Directory traversal vulnerability in logging/logviewer.jsp in the Management Console in Adobe JRun Application Server 4 Updater 7 allows remote authenticated users to read arbitra…

CVSS 4.0 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2009-2792

Published Aug 17, 2009

Directory traversal vulnerability in plugings/pagecontent.php in Really Simple CMS (RSCMS) 0.3a allows remote attackers to include and execute arbitrary local files via a .. (dot…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2009-2787

Published Aug 17, 2009

Directory traversal vulnerability in include/reputation/rep_profile.php in the Reputation plugin 2.2.4, 2.2.3, 2.0.4, and earlier for PunBB, when register_globals is enabled and m…

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2009-2784

Published Aug 17, 2009

Multiple directory traversal vulnerabilities in dit.cms 1.3, when register_globals is enabled, allow remote attackers to include and execute arbitrary local files via a .. (dot do…

CVSS 9.3 · Critical
Vendor/product tagsBeta · best-effort

CVE-2008-6933

Published Aug 11, 2009

Directory traversal vulnerability in index.php in MiniGal b13 (aka MG2) allows remote attackers to read the source code of .php files, and possibly the content of other files, via…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2008-6926

Published Aug 10, 2009

Directory traversal vulnerability in autoinstall4imagesgalleryupgrade.php in the Fantastico De Luxe Module for cPanel allows remote attackers to include and execute arbitrary loca…

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2008-6901

Published Aug 6, 2009

Multiple directory traversal vulnerabilities in 2532designs 2532|Gigs 1.2.2 Stable, when register_globals is enabled and magic_quotes_gpc is disabled, allow remote attackers to in…

CVSS 5.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2009-2659

Published Aug 4, 2009

The Admin media handler in core/servers/basehttp.py in Django 1.0 and 0.96 does not properly map URL requests to expected "static media files," which allows remote attackers to co…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort
Showing 8,976-9,000 of 9,831 CVEsPage 360 of 394