Skip to main content

CWE archive

CWE-22 CVEs

Programmatic archive

9,805 CVEs tagged with CWE-221,302 Critical, 4,058 High, 4,014 Medium, 425 Low, 6 Unrated.

CVE-2007-6621

Published Jan 4, 2008

Directory traversal vulnerability in joovili.images.php in Joovili 3.0.0 through 3.0.6 allows remote attackers to read arbitrary files via a .. (dot dot) in the picture parameter.

CVSS 6.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2007-6623

Published Jan 4, 2008

Absolute path traversal vulnerability in ZeusCMS 0.3 and earlier might allow remote attackers to list arbitrary directories via a full pathname in the dir parameter.

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2007-6624

Published Jan 4, 2008

Directory traversal vulnerability in printview.php in PNphpBB2 1.2i and earlier allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the phpE…

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2007-6612

Published Jan 3, 2008

Directory traversal vulnerability in DirHandler (lib/mongrel/handlers.rb) in Mongrel 1.0.4 and 1.1.x before 1.1.3 allows remote attackers to read arbitrary files via an HTTP reque…

CVSS 6.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2007-6604

Published Dec 31, 2007

Multiple directory traversal vulnerabilities in index.php in XCMS 1.82 and earlier allow remote attackers to read arbitrary files via a .. (dot dot) in (1) the s parameter to the…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2007-6567

Published Dec 28, 2007

Directory traversal vulnerability in index.php in XZero Community Classifieds 4.95.11 and earlier allows remote attackers to include and execute arbitrary local files via a .. (do…

CVSS 6.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2007-6581

Published Dec 28, 2007

Multiple directory traversal vulnerabilities in Social Engine 2.0 allow remote attackers to include and execute arbitrary local files via a .. (dot dot) in the global_lang paramet…

CVSS 6.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2007-6582

Published Dec 28, 2007

Directory traversal vulnerability in index.php in mBlog 1.2 allows remote attackers to read arbitrary files via a .. (dot dot) in the page parameter in a page mode action.

CVSS 6.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2007-6584

Published Dec 28, 2007

Multiple directory traversal vulnerabilities in 1024 CMS 1.3.1 allow remote attackers to include and execute arbitrary local files via a .. (dot dot) in (1) the lang parameter to…

CVSS 6.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2007-6552

Published Dec 28, 2007

Directory traversal vulnerability in index.php in AuraCMS 2.2 allows remote authenticated users to include and execute arbitrary local files via a .. (dot dot) in the act paramete…

CVSS 6.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2007-6554

Published Dec 28, 2007

Multiple directory traversal vulnerabilities in TeamCal Pro 3.1.000 and earlier allow remote attackers to include and execute arbitrary local files via a .. (dot dot) in the lang…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2007-6528

Published Dec 27, 2007

Directory traversal vulnerability in tiki-listmovies.php in TikiWiki before 1.9.9 allows remote attackers to read arbitrary files via a .. (dot dot) and modified filename in the m…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2007-6508

Published Dec 21, 2007

Directory traversal vulnerability in view.php in xeCMS 1.0 allows remote attackers to read arbitrary files via a ..%2F (dot dot slash) in the list parameter.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2007-6475

Published Dec 20, 2007

Multiple directory traversal vulnerabilities in GF-3XPLORER 2.4 allow remote attackers to include and execute arbitrary local files via a .. (dot dot) in the lang_sel parameter to…

CVSS 6.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2007-6453

Published Dec 20, 2007

Directory traversal vulnerability in raidenhttpd-admin/workspace.php in RaidenHTTPD 2.0.19, when the WebAdmin function is enabled, allows remote attackers to include and execute a…

CVSS 10.0 · Critical
Vendor/product tagsBeta · best-effort

CVE-2007-6471

Published Dec 20, 2007

Incomplete blacklist vulnerability in main.php in phPay 2.02.01 on Windows allows remote attackers to conduct directory traversal attacks and include and execute arbitrary local f…

CVSS 5.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2007-4709

Published Dec 19, 2007

Directory traversal vulnerability in CFNetwork in Apple Mac OS X 10.5.1 allows remote attackers to overwrite arbitrary files via a crafted HTTP response.

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2007-6397

Published Dec 17, 2007

Multiple directory traversal vulnerabilities in index.php in Flat PHP Board 1.2 and earlier allow remote attackers to (1) create arbitrary files via a .. (dot dot) in the username…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2007-6400

Published Dec 17, 2007

Directory traversal vulnerability in download_file.php in PolDoc CMS (aka PDDMS) 0.96 allows remote attackers to read arbitrary files via a .. (dot dot) or absolute pathname in th…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2007-6404

Published Dec 17, 2007

Directory traversal vulnerability in Sergey Lyubka Simple HTTPD (shttpd) 1.38 and earlier on Windows allows remote attackers to read arbitrary files via a ..\ (dot dot backslash)…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2007-6368

Published Dec 15, 2007

Directory traversal vulnerability in index.php in ezContents 1.4.5 allows remote attackers to read arbitrary files via a .. (dot dot) in the link parameter.

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2007-6369

Published Dec 15, 2007

Multiple directory traversal vulnerabilities in resize.php in the PictPress 0.91 and earlier plugin for WordPress allow remote attackers to read arbitrary files via a .. (dot dot)…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2007-6376

Published Dec 15, 2007

Directory traversal vulnerability in autohtml.php in Francisco Burzi PHP-Nuke 8.0 allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the fi…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2007-6378

Published Dec 15, 2007

Directory traversal vulnerability in upload.dll in BadBlue 2.72b and earlier allows remote attackers to create or overwrite arbitrary files via a .. (dot dot) in the filename para…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort
Showing 9,551-9,575 of 9,805 CVEsPage 383 of 393