Vulnerabilities (CVE)

Filtered by CWE-22
Total 7126 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2018-19042 1 Media File Manager Project 1 Media File Manager 2024-11-21 5.0 MEDIUM 5.3 MEDIUM
The Media File Manager plugin 1.4.2 for WordPress allows arbitrary file movement via a ../ directory traversal in the dir_from and dir_to parameters of an mrelocator_move action to the wp-admin/admin-ajax.php URI.
CVE-2018-19040 1 Media File Manager Project 1 Media File Manager 2024-11-21 5.0 MEDIUM 5.3 MEDIUM
The Media File Manager plugin 1.4.2 for WordPress allows directory listing via a ../ directory traversal in the dir parameter of an mrelocator_getdir action to the wp-admin/admin-ajax.php URI.
CVE-2018-19003 1 Ge 6 Ex2100e, Ex2100e Firmware, Ls2100e and 3 more 2024-11-21 5.0 MEDIUM 7.5 HIGH
GE Mark VIe, EX2100e, EX2100e_Reg, and LS2100e Versions 03.03.28C to 05.02.04C, EX2100e All versions prior to v04.09.00C, EX2100e_Reg All versions prior to v04.09.00C, and LS2100e All versions prior to v04.09.00C The affected versions of the application have a path traversal vulnerability that fails to restrict the ability of an attacker to gain access to restricted information.
CVE-2018-1999020 1 Opennetworking 1 Onos 2024-11-21 5.8 MEDIUM 5.5 MEDIUM
Open Networking Foundation (ONF) ONOS version 1.13.2 and earlier version contains a Directory Traversal vulnerability in core/common/src/main/java/org/onosproject/common/app/ApplicationArchive.java line 35 that can result in arbitrary file deletion (overwrite). This attack appear to be exploitable via a specially crafted zip file should be uploaded.
CVE-2018-18990 1 Lcds 1 Laquis Scada 2024-11-21 5.0 MEDIUM 5.3 MEDIUM
LCDS Laquis SCADA prior to version 4.1.0.4150 allows a user-supplied path in file operations prior to proper validation. An attacker can leverage this vulnerability to disclose sensitive information under the context of the web server process.
CVE-2018-18950 1 Kindeditor 1 Kindeditor 2024-11-21 5.0 MEDIUM 7.5 HIGH
KindEditor through 4.1.11 has a path traversal vulnerability in php/upload_json.php. Anyone can browse a file or directory in the kindeditor/attached/ folder via the path parameter without authentication.
CVE-2018-18936 1 Popojicms 1 Popojicms 2024-11-21 6.4 MEDIUM 7.5 HIGH
An issue was discovered in PopojiCMS v2.0.1. admin_library.php allows remote attackers to delete arbitrary files via directory traversal in the po-admin/route.php?mod=library&act=delete id parameter.
CVE-2018-18894 1 Lexmark 98 6500e, 6500e Firmware, C748 and 95 more 2024-11-21 5.0 MEDIUM 7.5 HIGH
Certain older Lexmark devices (C, M, X, and 6500e before 2018-12-18) contain a directory traversal vulnerability in the embedded web server.
CVE-2018-18890 1 1234n 1 Minicms 2024-11-21 5.0 MEDIUM 5.3 MEDIUM
MiniCMS 1.10 allows full path disclosure via /mc-admin/post.php?state=delete&delete= with an invalid filename.
CVE-2018-18876 1 Columbiaweather 2 Weather Microserver, Weather Microserver Firmware 2024-11-21 5.0 MEDIUM 5.3 MEDIUM
In firmware version MS_2.6.9900 of Columbia Weather MicroServer, a readouts_rd.php directory traversal issue makes it possible to read any file present on the underlying operating system.
CVE-2018-18869 1 Phome 1 Empirecms 2024-11-21 7.5 HIGH 9.8 CRITICAL
EmpireCMS V7.5 allows remote attackers to upload and execute arbitrary code via ..%2F directory traversal in a .php filename in the upload/e/admin/ecmscom.php path parameter.
CVE-2018-18863 1 Ngahr 1 Resourcelink 2024-11-21 4.0 MEDIUM 6.5 MEDIUM
NGA ResourceLink 20.0.2.1 allows local file inclusion.
CVE-2018-18831 1 Mingsoft 1 Mcms 2024-11-21 5.0 MEDIUM 7.5 HIGH
An issue was discovered in com\mingsoft\cms\action\GeneraterAction.java in MCMS 4.6.5. An attacker can write a .jsp file (in the position parameter) to an arbitrary directory via a ../ Directory Traversal in the url parameter.
CVE-2018-18777 1 Microstrategy 1 Microstrategy Web 2024-11-21 4.0 MEDIUM 4.3 MEDIUM
Directory traversal vulnerability in Microstrategy Web, version 7, in "/WebMstr7/servlet/mstrWeb" (in the parameter subpage) allows remote authenticated users to bypass intended SecurityManager restrictions and list a parent directory via a /.. (slash dot dot) in a pathname used by a web application. NOTE: this is a deprecated product.
CVE-2018-18713 1 Phpyun 1 Phpyun 2024-11-21 5.0 MEDIUM 7.5 HIGH
The function down_sql_action() in /admin/model/database.class.php in PHPYun 4.6 allows remote attackers to read arbitrary files via directory traversal in an m=database&c=down_sql&name=../ URI.
CVE-2018-18703 1 Phptpoint 1 Mailing Server Using File Handling 2024-11-21 5.0 MEDIUM 7.5 HIGH
PhpTpoint Mailing Server Using File Handling 1.0 suffers from multiple Arbitrary File Read vulnerabilities in different sections that allow an attacker to read sensitive files on the system via directory traversal, bypassing the login page, as demonstrated by the Mailserver_filesystem/home.php coninb, consent, contrsh, condrft, or conspam parameter.
CVE-2018-18593 1 Hp 1 Ucmdb Configuration Manager 2024-11-21 5.0 MEDIUM 6.5 MEDIUM
Remote Directory Traversal and Remote Disclosure of Privileged Information in UCMDB Configuration Management Service, version 10.22, 10.22 CUP1, 10.22 CUP2, 10.22 CUP3, 10.22 CUP4, 10.22 CUP5, 10.22 CUP6, 10.22 CUP7, 10.33, 10.33 CUP1, 10.33 CUP2, 10.33 CUP3, 2018.02, 2018.05, 2018.08, 2018.11. The vulnerabilities could allow Remote Directory Traversal and Remote Disclosure of Privileged Information
CVE-2018-18586 1 Kyzer 1 Libmspack 2024-11-21 5.0 MEDIUM 5.3 MEDIUM
chmextract.c in the chmextract sample program, as distributed with libmspack before 0.8alpha, does not protect against absolute/relative pathnames in CHM files, leading to Directory Traversal. NOTE: the vendor disputes that this is a libmspack vulnerability, because chmextract.c was only intended as a source-code example, not a supported application
CVE-2018-18576 1 Incsub 1 Hustle 2024-11-21 5.0 MEDIUM 5.3 MEDIUM
The Hustle (aka wordpress-popup) plugin through 6.0.5 for WordPress allows Directory Traversal to obtain a directory listing via the views/admin/dashboard/ URI.
CVE-2018-18552 1 Serverscheck 1 Monitoring Software 2024-11-21 5.0 MEDIUM 6.5 MEDIUM
ServersCheck Monitoring Software through 14.3.3 allows local users to cause a denial of service (menu functionality loss) by creating an LNK file that points to a second LNK file, if this second LNK file is associated with a Start menu. Ultimately, this behavior comes from a Directory Traversal bug (via the sensor_details.html id parameter) that allows creating empty files in arbitrary directories.