Total
7096 CVE
CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
---|---|---|---|---|---|
CVE-2017-16744 | 1 Tridium | 2 Niagara, Niagara Ax Framework | 2024-11-21 | 6.5 MEDIUM | 7.2 HIGH |
A path traversal vulnerability in Tridium Niagara AX Versions 3.8 and prior and Niagara 4 systems Versions 4.4 and prior installed on Microsoft Windows Systems can be exploited by leveraging valid platform (administrator) credentials. | |||||
CVE-2017-16720 | 1 Advantech | 1 Webaccess | 2024-11-21 | 10.0 HIGH | 9.8 CRITICAL |
A Path Traversal issue was discovered in WebAccess versions 8.3.2 and earlier. An attacker has access to files within the directory structure of the target device. | |||||
CVE-2017-16654 | 2 Debian, Sensiolabs | 2 Debian Linux, Symfony | 2024-11-21 | 5.0 MEDIUM | 7.5 HIGH |
An issue was discovered in Symfony before 2.7.38, 2.8.31, 3.2.14, 3.3.13, 3.4-BETA5, and 4.0-BETA5. The Intl component includes various bundle readers that are used to read resource bundles from the local filesystem. The read() methods of these classes use a path and a locale to determine the language bundle to retrieve. The locale argument value is commonly retrieved from untrusted user input (like a URL parameter). An attacker can use this argument to navigate to arbitrary directories via the dot-dot-slash attack, aka Directory Traversal. | |||||
CVE-2017-16223 | 1 Nodeaaaaa Project | 1 Nodeaaaaa | 2024-11-21 | 5.0 MEDIUM | 7.5 HIGH |
nodeaaaaa is a static file server. nodeaaaaa is vulnerable to a directory traversal issue, giving an attacker access to the filesystem by placing "../" in the url. | |||||
CVE-2017-16222 | 1 Elding Project | 1 Elding | 2024-11-21 | 5.0 MEDIUM | 5.3 MEDIUM |
elding is a simple web server. elding is vulnerable to a directory traversal issue, allowing an attacker to access the filesystem by placing "../" in the url. The files accessible, however, are limited to files with a file extension. Sending a GET request to /../../../etc/passwd, for example, will return a 404 on etc/passwd/index.js. | |||||
CVE-2017-16221 | 1 Yzt Project | 1 Yzt | 2024-11-21 | 5.0 MEDIUM | 7.5 HIGH |
yzt is a simple file server. yzt is vulnerable to a directory traversal issue, giving an attacker access to the filesystem by placing "../" in the url. | |||||
CVE-2017-16220 | 1 Wind-mvc Project | 1 Wind-mvc | 2024-11-21 | 5.0 MEDIUM | 7.5 HIGH |
wind-mvc is an mvc framework. wind-mvc is vulnerable to a directory traversal issue, giving an attacker access to the filesystem by placing "../" in the url. | |||||
CVE-2017-16219 | 1 Yttivy Project | 1 Yttivy | 2024-11-21 | 5.0 MEDIUM | 7.5 HIGH |
yttivy is a static file server. yttivy is vulnerable to a directory traversal issue, giving an attacker access to the filesystem by placing "../" in the url. | |||||
CVE-2017-16218 | 1 Dgard8.lab6 Project | 1 Dgard8.lab6 | 2024-11-21 | 5.0 MEDIUM | 7.5 HIGH |
dgard8.lab6 is a static file server. dgard8.lab6 is vulnerable to a directory traversal issue, giving an attacker access to the filesystem by placing "../" in the url. | |||||
CVE-2017-16217 | 1 Webrtc-experiment | 1 Fbr-client | 2024-11-21 | 5.0 MEDIUM | 7.5 HIGH |
fbr-client sends files through sockets via socket.io and webRTC. fbr-client is vulnerable to a directory traversal issue, giving an attacker access to the filesystem by placing "../" in the url. | |||||
CVE-2017-16216 | 1 Tencent-server Project | 1 Tencent-server | 2024-11-21 | 5.0 MEDIUM | 7.5 HIGH |
tencent-server is a simple web server. tencent-server is vulnerable to a directory traversal issue, giving an attacker access to the filesystem by placing "../" in the url. | |||||
CVE-2017-16215 | 1 Sgqserve Project | 1 Sgqserve | 2024-11-21 | 5.0 MEDIUM | 7.5 HIGH |
sgqserve is a simple file server. sgqserve is vulnerable to a directory traversal issue, giving an attacker access to the filesystem by placing "../" in the url. | |||||
CVE-2017-16214 | 1 Peiserver Project | 1 Peiserver | 2024-11-21 | 5.0 MEDIUM | 7.5 HIGH |
peiserver is a static file server. peiserver is vulnerable to a directory traversal issue, giving an attacker access to the filesystem by placing "../" in the url. | |||||
CVE-2017-16213 | 1 Mfrserver Project | 1 Mfrserver | 2024-11-21 | 5.0 MEDIUM | 7.5 HIGH |
mfrserver is a simple file server. mfrserver is vulnerable to a directory traversal issue, giving an attacker access to the filesystem by placing "../" in the url. | |||||
CVE-2017-16212 | 1 Ltt Project | 1 Ltt | 2024-11-21 | 5.0 MEDIUM | 7.5 HIGH |
ltt is a static file server. ltt is vulnerable to a directory traversal issue, giving an attacker access to the filesystem by placing "../" in the url. | |||||
CVE-2017-16211 | 1 Lessindex Project | 1 Lessindex | 2024-11-21 | 5.0 MEDIUM | 7.5 HIGH |
lessindex is a static file server. lessindex is vulnerable to a directory traversal issue, giving an attacker access to the filesystem by placing "../" in the url. | |||||
CVE-2017-16210 | 1 Jn Jj Server Project | 1 Jn Jj Server | 2024-11-21 | 5.0 MEDIUM | 7.5 HIGH |
jn_jj_server is a static file server. jn_jj_server is vulnerable to a directory traversal issue, giving an attacker access to the filesystem by placing "../" in the url. | |||||
CVE-2017-16209 | 1 Enserver Project | 1 Enserver | 2024-11-21 | 5.0 MEDIUM | 7.5 HIGH |
enserver is a simple web server. enserver is vulnerable to a directory traversal issue, giving an attacker access to the filesystem by placing "../" in the url. | |||||
CVE-2017-16208 | 1 Dmmcquay.lab6 Project | 1 Dmmcquay.lab6 | 2024-11-21 | 5.0 MEDIUM | 7.5 HIGH |
dmmcquay.lab6 is a REST server. dmmcquay.lab6 is vulnerable to a directory traversal issue, giving an attacker access to the filesystem by placing "../" in the url. | |||||
CVE-2017-16201 | 1 Zjjserver Project | 1 Zjjserver | 2024-11-21 | 5.0 MEDIUM | 7.5 HIGH |
zjjserver is a static file server. zjjserver is vulnerable to a directory traversal issue, giving an attacker access to the filesystem by placing "../" in the url. |