Vulnerabilities (CVE)

Filtered by CWE-22
Total 7178 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2007-5920 1 Picoflat Cms 1 Picoflat Cms 2025-04-09 6.8 MEDIUM N/A
index.php in Domenico Mancini PicoFlat CMS before 0.4.18 allows remote attackers to include certain files via unspecified vectors, possibly due to a directory traversal vulnerability. NOTE: this can be leveraged to bypass authentication and upload files by including pico_insert.php or unspecified other administrative scripts. NOTE: some of these details are obtained from third party information.
CVE-2008-3371 1 Talkback 1 Talkback 2025-04-09 7.5 HIGH N/A
Directory traversal vulnerability in install/help.php in TalkBack 2.3.5, and other versions before 2.3.6.2, allows remote attackers to include and execute arbitrary local files via directory traversal sequences in the language parameter.
CVE-2008-6933 1 Minigal 1 Minigal 2025-04-09 5.0 MEDIUM N/A
Directory traversal vulnerability in index.php in MiniGal b13 (aka MG2) allows remote attackers to read the source code of .php files, and possibly the content of other files, via a .. (dot dot) in the list parameter.
CVE-2009-3181 1 Anantasoft 1 Gazelle Cms 2025-04-09 5.0 MEDIUM N/A
Directory traversal vulnerability in Anantasoft Gazelle CMS 1.0 allows remote attackers to overwrite arbitrary files via a .. (dot dot) in the customizetemplate parameter in a direct request to admin/settemplate.php.
CVE-2008-4519 1 Fastpublish 1 Fastpublish Cms 2025-04-09 7.5 HIGH N/A
Multiple directory traversal vulnerabilities in Fastpublish CMS 1.9999 d allow remote attackers to include and execute arbitrary local files via a .. (dot dot) in the target parameter to (1) index2.php and (2) index.php.
CVE-2008-4707 1 Sylvain Pasquet 1 Bbzl Php 2025-04-09 5.0 MEDIUM N/A
Directory traversal vulnerability in index.php in BbZL.PhP 0.92 allows remote attackers to access unauthorized directories via a .. (dot dot) in the lien_2 parameter.
CVE-2007-6623 1 Zeuscms 1 Zeuscms 2025-04-09 5.0 MEDIUM N/A
Absolute path traversal vulnerability in ZeusCMS 0.3 and earlier might allow remote attackers to list arbitrary directories via a full pathname in the dir parameter.
CVE-2008-2415 1 Digitalhive 1 Digitalhive 2025-04-09 6.8 MEDIUM N/A
Directory traversal vulnerability in template/purpletech/base_include.php in DigitalHive (aka hive) 2.0 RC2 allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the page parameter.
CVE-2008-6183 1 Myphpindexer 1 My Php Indexer 2025-04-09 7.8 HIGH N/A
Multiple directory traversal vulnerabilities in index.php in My PHP Indexer 1.0 allow remote attackers to read arbitrary files via a .. (dot dot) in the (1) d and (2) f parameters.
CVE-2008-0357 1 Galaxyscripts 1 Mini File Host 2025-04-09 4.3 MEDIUM N/A
Directory traversal vulnerability in pages/upload.php in Galaxyscripts Mini File Host 1.2.1 and earlier allows remote attackers to include and execute arbitrary local files via directory traversal sequences in the language parameter.
CVE-2008-5207 1 Jonascms 1 Jonascms 2025-04-09 6.8 MEDIUM N/A
Multiple directory traversal vulnerabilities in Jonascms 1.2 allow remote attackers to include and execute arbitrary local files via a .. (dot dot) in the taal parameter to (1) backup.php and (2) gb_voegtoe.php. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.
CVE-2008-6074 1 Phpcrs 1 Phpcrs 2025-04-09 5.1 MEDIUM N/A
Directory traversal vulnerability in frame.php in phpcrs 2.06 and earlier, when magic_quotes_gpc is disabled, allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the importFunction parameter.
CVE-2008-1933 1 Microsoft 1 Zune Software 2025-04-09 4.3 MEDIUM N/A
Absolute path traversal vulnerability in a certain ActiveX control in Zune allows user-assisted remote attackers to overwrite arbitrary files via the SaveToFile method. NOTE: the victim must explicitly allow the code to run.
CVE-2009-0331 1 Quirm 1 Espg 2025-04-09 7.8 HIGH N/A
Directory traversal vulnerability in gallery/comment.php in Enhanced Simple PHP Gallery (ESPG) 1.72 allows remote attackers to read arbitrary files via a .. (dot dot) in the file parameter. NOTE: the vulnerability may be in my little homepage Comment script. If so, then this should not be treated as a vulnerability in ESPG.
CVE-2007-5782 1 Fireconfig 1 Fireconfig 2025-04-09 5.0 MEDIUM N/A
Directory traversal vulnerability in dl.php in FireConfig 0.5 allows remote attackers to read arbitrary files via a .. (dot dot) in the file parameter.
CVE-2009-3823 1 Ac4p 1 Mobilelib Gold 2025-04-09 4.3 MEDIUM N/A
Directory traversal vulnerability in myhtml.php in Mobilelib GOLD 3.0, when magic_quotes_gpc is enabled, allows remote attackers to read arbitrary files via a .. (dot dot) in the GLOBALS[page] parameter.
CVE-2008-7055 1 Visualshapers 1 Ezcontents 2025-04-09 5.1 MEDIUM N/A
module.php in ezContents 2.0.3 allows remote attackers to bypass the directory traversal protection mechanism to include and execute arbitrary local files via "....//" (doubled dot dot slash) sequences in the link parameter, which is not properly filtered using the str_replace function.
CVE-2008-6833 1 Fuzzylime 1 Fuzzylime \(cms\) 2025-04-09 10.0 HIGH N/A
Directory traversal vulnerability in commsrss.php in fuzzylime (cms) before 3.01b allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in a files array element for a blogs action, as demonstrated by the files[0] parameter.
CVE-2007-6317 1 Real Time Logic 2 Barracudadrive Web Server, Barracudadrive Web Server Home Server 2025-04-09 5.5 MEDIUM N/A
Multiple directory traversal vulnerabilities in BarracudaDrive Web Server before 3.8 allow (1) remote attackers to read arbitrary files via certain ..\ (dot dot backslash) sequences in the URL path, or (2) remote authenticated users to delete arbitrary files or create arbitrary directories via a ..\ (dot dot backslash) sequence in the dir parameter to /drive/c/bdusers/USER/.
CVE-2008-2818 1 Easy-clanpage 1 Easy-clanpage 2025-04-09 7.5 HIGH N/A
Directory traversal vulnerability in Easy-Clanpage 3.0 b1 allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the section parameter to the default URI.