Skip to main content

CWE archive

CWE-22 CVEs

Programmatic archive

9,499 CVEs tagged with CWE-221,262 Critical, 3,933 High, 3,904 Medium, 389 Low, 11 Unrated.

CVE-2008-2985

Published Jul 2, 2008

Directory traversal vulnerability in load_language.php in CMReams CMS 1.3.1.1 Beta 2, when register_globals is enabled, allows remote attackers to include and execute arbitrary lo…

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2008-2942

Published Jun 30, 2008

Directory traversal vulnerability in patch.py in Mercurial 1.0.1 allows user-assisted attackers to modify arbitrary files via ".." (dot dot) sequences in a patch file.

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2008-2913

Published Jun 30, 2008

Directory traversal vulnerability in func.php in Devalcms 1.4a, when magic_quotes_gpc is disabled, allows remote attackers to include and execute arbitrary local files via a .. (d…

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2008-2887

Published Jun 27, 2008

Directory traversal vulnerability in index.php in chaozz@work FubarForum 1.5 allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the page pa…

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2008-2889

Published Jun 27, 2008

Directory traversal vulnerability in the FTP client in AceBIT WISE-FTP 4.1.0 and 5.5.8 allows remote FTP servers to create or overwrite arbitrary files via a ..\ (dot dot backslas…

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2008-2894

Published Jun 27, 2008

Directory traversal vulnerability in the FTP client in NCH Software Classic FTP 1.02 for Windows allows remote FTP servers to create or overwrite arbitrary files via a .. (dot dot…

CVSS 9.3 · Critical
Vendor/product tagsBeta · best-effort

CVE-2008-2895

Published Jun 27, 2008

Directory traversal vulnerability in index.php in AproxEngine 5.1.0.4 allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the page parameter.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2008-2896

Published Jun 27, 2008

Directory traversal vulnerability in index.php in FireAnt 1.3 allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the page parameter.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2008-2898

Published Jun 27, 2008

Directory traversal vulnerability in includes/header.php in Hedgehog-CMS 1.21 allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the c_temp…

CVSS 9.3 · Critical
Vendor/product tagsBeta · best-effort

CVE-2008-2876

Published Jun 26, 2008

Directory traversal vulnerability in index.php in mUnky 0.0.1 allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the zone parameter.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2008-2863

Published Jun 25, 2008

Multiple absolute path traversal vulnerabilities in eLineStudio Site Composer (ESC) 2.6 allow remote attackers to create or delete arbitrary directories via a full pathname in the…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2008-2838

Published Jun 24, 2008

Directory traversal vulnerability in index.php in Traindepot 0.1 allows remote attackers to read arbitrary files via a .. (dot dot) in the module parameter.

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2008-2840

Published Jun 24, 2008

Multiple directory traversal vulnerabilities in Exero CMS 1.0.0 and 1.0.1 allow remote attackers to include and execute arbitrary local files via a .. (dot dot) in the theme param…

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2008-2818

Published Jun 23, 2008

Directory traversal vulnerability in Easy-Clanpage 3.0 b1 allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the section parameter to the d…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2008-2820

Published Jun 23, 2008

Directory traversal vulnerability in lang/lang-system.php in Open Azimyt CMS 0.22 minimal and 0.21 stable allows remote attackers to include and execute arbitrary local files via…

CVSS 6.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2008-2821

Published Jun 23, 2008

Directory traversal vulnerability in the FTP client in Glub Tech Secure FTP before 2.5.16 on Windows allows remote FTP servers to create or overwrite arbitrary files via a ..\ (do…

CVSS 9.3 · Critical
Vendor/product tagsBeta · best-effort

CVE-2008-2822

Published Jun 23, 2008

Multiple directory traversal vulnerabilities in the FTP client in 3D-FTP Client 8.01 (8.0 build 1) allow remote FTP servers to create or overwrite arbitrary files via a .. (dot do…

CVSS 9.3 · Critical
Vendor/product tagsBeta · best-effort

CVE-2008-2795

Published Jun 20, 2008

Directory traversal vulnerability in the FTP and SFTP clients in IDM Computer Solutions Inc UltraEdit 14.00b allows remote FTP servers to create or overwrite arbitrary files via a…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2008-2665

Published Jun 20, 2008

Directory traversal vulnerability in the posix_access function in PHP 5.2.6 and earlier allows remote attackers to bypass safe_mode restrictions via a .. (dot dot) in an http URL,…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2008-2666

Published Jun 20, 2008

Multiple directory traversal vulnerabilities in PHP 5.2.6 and earlier allow context-dependent attackers to bypass safe_mode restrictions by creating a subdirectory named http: and…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2008-2779

Published Jun 19, 2008

Directory traversal vulnerability in GlobalSCAPE CuteFTP Home 8.2.0 Build 02.26.2008.4 and CuteFTP Pro 8.2.0 Build 04.01.2008.1 allows remote FTP servers to create or overwrite ar…

CVSS 9.3 · Critical
Vendor/product tagsBeta · best-effort

CVE-2008-2782

Published Jun 19, 2008

Multiple directory traversal vulnerabilities in OtomiGenX 2.2 allow remote attackers to include and execute arbitrary local files via a .. (dot dot) in the lang parameter to (1) l…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2008-2695

Published Jun 13, 2008

Directory traversal vulnerability in entry.php in phpInv 0.8.0 allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the action parameter.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2008-2699

Published Jun 13, 2008

Multiple directory traversal vulnerabilities in Galatolo WebManager (GWM) 1.0 allow remote attackers to include and execute arbitrary local files via directory traversal sequences…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort
Showing 9,051-9,075 of 9,499 CVEsPage 363 of 380