Skip to main content

CWE archive

CWE-22 CVEs

Programmatic archive

9,783 CVEs tagged with CWE-221,296 Critical, 4,049 High, 4,007 Medium, 425 Low, 6 Unrated.

CVE-2009-2100

Published Jun 17, 2009

Directory traversal vulnerability in the JoomlaPraise Projectfork (com_projectfork) component 2.0.10 for Joomla! allows remote attackers to read arbitrary files via directory trav…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2008-5515

Published Jun 16, 2009

Apache Tomcat 4.1.0 through 4.1.39, 5.5.0 through 5.5.27, 6.0.0 through 6.0.18, and possibly earlier versions normalizes the target pathname before filtering the query string when…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2009-2081

Published Jun 16, 2009

Directory traversal vulnerability in help.php in phpWebThings 1.5.2 and earlier, when magic_quotes_gpc is disabled, allows remote attackers to read arbitrary files via a .. (dot d…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2009-2037

Published Jun 12, 2009

Multiple directory traversal vulnerabilities in Online Grades & Attendance 3.2.5 and earlier, and possibly 3.2.6, when register_globals is enabled, allow remote attackers to inclu…

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2009-1760

Published Jun 11, 2009

Directory traversal vulnerability in src/torrent_info.cpp in Rasterbar libtorrent before 0.14.4, as used in firetorrent, qBittorrent, deluge Torrent, and other applications, allow…

CVSS 5.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2009-2015

Published Jun 9, 2009

Directory traversal vulnerability in includes/file_includer.php in the Ideal MooFAQ (com_moofaq) component 1.0 for Joomla! allows remote attackers to read arbitrary files via a ..…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2009-2007

Published Jun 8, 2009

Multiple directory traversal vulnerabilities in Dokeos 1.8.5, and possibly earlier, allow remote attackers to (1) read portions of arbitrary files via a .. (dot dot) and a ..\ (do…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2009-1948

Published Jun 5, 2009

Multiple directory traversal vulnerabilities in forum.php in Unclassified NewsBoard (UNB) 1.6.4, when register_globals is enabled and magic_quotes_gpc is disabled, allow remote at…

CVSS 5.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2008-6825

Published Jun 5, 2009

Directory traversal vulnerability in user/index.php in Fonality trixbox CE 2.6.1 and earlier allows remote attackers to include and execute arbitrary files via a .. (dot dot) in t…

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2009-1936

Published Jun 5, 2009

_functions.php in cpCommerce 1.2.x, possibly including 1.2.9, sends a redirect but does not exit when it is called directly, which allows remote attackers to bypass a protection m…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2009-1912

Published Jun 4, 2009

Directory traversal vulnerability in src/func/language.php in webSPELL 4.2.0e and earlier allows remote attackers to include and execute arbitrary local .php files via a .. (dot d…

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2009-1847

Published Jun 1, 2009

Directory traversal vulnerability in index.php in Easy PX 41 CMS 9.0 B1 allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the fiche parame…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2009-1846

Published Jun 1, 2009

Multiple directory traversal vulnerabilities in SiteX 0.7.4 Build 418 and earlier allow remote attackers to include and execute arbitrary local files via a .. (dot dot) in the THE…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2009-1779

Published May 22, 2009

PHP remote file inclusion vulnerability in admin.php in Frax.dk Php Recommend 1.3 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the form_include_t…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2009-1774

Published May 22, 2009

Directory traversal vulnerability in plugins/ddb/foot.php in Strawberry 1.1.1 allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the file p…

CVSS 9.3 · Critical
Vendor/product tagsBeta · best-effort

CVE-2009-1770

Published May 22, 2009

Directory traversal vulnerability in includes/database/examples/addressbook.php in Flyspeck CMS 6.8 allows remote attackers to include and execute arbitrary local files via a .. (…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2009-1765

Published May 22, 2009

Multiple directory traversal vulnerabilities in pluck 4.6.2, when register_globals is enabled, allow remote attackers to include and execute arbitrary local files via a .. (dot do…

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2009-1748

Published May 22, 2009

Multiple directory traversal vulnerabilities in index.php in Catviz 0.4.0 Beta 1 allow remote attackers to read arbitrary files via a .. (dot dot) in the (1) webpages_form or (2)…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2009-1161

Published May 21, 2009

Directory traversal vulnerability in the TFTP service in Cisco CiscoWorks Common Services (CWCS) 3.0.x through 3.2.x on Windows, as used in Cisco Unified Service Monitor, Security…

CVSS 10.0 · Critical

CVE-2009-1744

Published May 21, 2009

InstallHFZ.exe 6.5.201.0 in Pinnacle Hollywood Effects 6, a module in Pinnacle Systems Pinnacle Studio 12, allows remote attackers to cause a denial of service (application crash)…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2009-1737

Published May 20, 2009

Directory traversal vulnerability in bom.php in MyPic 2.1 allows remote attackers to list files in arbitrary directories via a .. (dot dot) in the dir parameter.

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2009-1730

Published May 20, 2009

Multiple directory traversal vulnerabilities in NetMechanica NetDecision TFTP Server 4.2 allow remote attackers to read or modify arbitrary files via directory traversal sequences…

CVSS 10.0 · Critical
Vendor/product tagsBeta · best-effort
Showing 9,001-9,025 of 9,783 CVEsPage 361 of 392