Vulnerabilities (CVE)

Filtered by CWE-22
Total 7161 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2006-5149 1 Openbiblio 1 Openbiblio 2025-04-09 7.5 HIGH N/A
Multiple directory traversal vulnerabilities in OpenBiblio before 0.5.2 allow remote attackers to include and execute arbitrary local files via a .. (dot dot) in (1) the page parameter to shared/help.php or (2) the tab parameter to shared/header.php.
CVE-2009-4194 1 Kmint21 1 Golden Ftp Server 2025-04-09 6.0 MEDIUM 8.1 HIGH
Directory traversal vulnerability in Golden FTP Server 4.30 Free and Professional, 4.50, and possibly other versions allows remote authenticated users to delete arbitrary files via a .. (dot dot) in the DELE command. NOTE: some of these details are obtained from third party information.
CVE-2009-4216 1 Klinza 1 Klinza Professional Cms 2025-04-09 9.3 HIGH N/A
Directory traversal vulnerability in funzioni/lib/menulast.php in klinza professional cms 5.0.1 and earlier allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the LANG parameter.
CVE-2009-0448 1 Syntax Desktop 1 Syntax Desktop 2025-04-09 7.5 HIGH N/A
Directory traversal vulnerability in admin/modules/aa/preview.php in Syntax Desktop 2.7 allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the synTarget parameter.
CVE-2008-3708 1 Dotcms 1 Dotcms 2025-04-09 4.3 MEDIUM N/A
Multiple directory traversal vulnerabilities in dotCMS 1.6.0.9 allow remote attackers to read arbitrary files via a .. (dot dot) in the id parameter to (1) news/index.dot and (2) getting_started/macros/macros_detail.dot.
CVE-2009-2161 1 Torrenttrader 1 Torrenttrader Classic 2025-04-09 5.1 MEDIUM N/A
Directory traversal vulnerability in backend/admin-functions.php in TorrentTrader Classic 1.09, when used on a case-insensitive web site, allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the ss_uri parameter, in conjunction with a modified component name.
CVE-2008-3190 1 1scripts 1 Codedb 2025-04-09 6.8 MEDIUM N/A
Directory traversal vulnerability in list.php in 1Scripts CodeDB 1.1.1 allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the lang parameter.
CVE-2009-1496 2 Ijobid, Joomla 2 Com Cmimarketplace, Joomla 2025-04-09 5.0 MEDIUM N/A
Directory traversal vulnerability in the Cmi Marketplace (com_cmimarketplace) component 0.1 for Joomla! allows remote attackers to list arbitrary directories via a .. (dot dot) in the viewit parameter to index.php.
CVE-2008-0094 1 Modxcms 1 Modxcms 2025-04-09 6.4 MEDIUM N/A
Multiple directory traversal vulnerabilities in MODx Content Management System 0.9.6.1 allow remote attackers to (1) include and execute arbitrary local files via a .. (dot dot) in the as_language parameter to assets/snippets/AjaxSearch/AjaxSearch.php, reached through index-ajax.php; and (2) read arbitrary local files via a .. (dot dot) in the file parameter to assets/js/htcmime.php.
CVE-2009-0645 1 Jaws 1 Jaws 2025-04-09 6.5 MEDIUM N/A
Directory traversal vulnerability in index.php in Jaws 0.8.8 allows remote authenticated users to read arbitrary files via a .. (dot dot) in the (1) language, (2) Introduction_complete, and (3) use_log parameters, different vectors than CVE-2004-2445.
CVE-2008-1565 2 Hotscripts, Phpbb 2 Pjirc, Pjirc Module 2025-04-09 7.5 HIGH N/A
Directory traversal vulnerability in forum/irc/irc.php in the PJIRC 0.5 module for phpBB allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the phpEx parameter.
CVE-2009-0765 1 Bookelves 1 Kipper 2025-04-09 7.5 HIGH N/A
Directory traversal vulnerability in index.php in Kipper 2.01 allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the configfile parameter.
CVE-2008-4592 1 Sportspanel 1 Sports Clubs Web Portal 2025-04-09 10.0 HIGH N/A
Directory traversal vulnerability in index.php in Sports Clubs Web Panel 0.0.1 allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the p parameter.
CVE-2009-3912 1 Tftgallery 1 Tftgallery 2025-04-09 5.0 MEDIUM N/A
Directory traversal vulnerability in index.php in TFTgallery 0.13 allows remote attackers to read arbitrary files via a ..%2F (encoded dot dot slash) in the album parameter.
CVE-2008-4243 1 Epic Games 1 Unreal Tournament 3 2025-04-09 7.8 HIGH N/A
Directory traversal vulnerability in ImageServer (aka UTImageServer) in WebAdmin before 1.7 for Epic Games Unreal Tournament 3 (UT3) 1.3 allows remote attackers to read arbitrary files via a .. (dot dot) in the URI.
CVE-2008-5593 1 Bpowerhouse 1 Mini Cms 2025-04-09 7.5 HIGH N/A
Multiple directory traversal vulnerabilities in index.php in Mini CMS 1.0.1 allow remote attackers to include and execute arbitrary local files via a .. (dot dot) in the (1) page and (2) admin parameters.
CVE-2009-0753 1 Mldonkey 1 Mldonkey 2025-04-09 5.0 MEDIUM N/A
Absolute path traversal vulnerability in MLDonkey 2.8.4 through 2.9.7 allows remote attackers to read arbitrary files via a leading "//" (double slash) in the filename.
CVE-2007-1138 1 Cromosoft 1 Simple Plantilla Php 2025-04-09 5.0 MEDIUM N/A
Absolute path traversal vulnerability in list_main_pages.php in Cromosoft Simple Plantilla PHP (SPP) allows remote attackers to list arbitrary directories, and read arbitrary files, via an absolute pathname in the nfolder parameter.
CVE-2007-4008 1 Entertainment Cms 1 Entertainment Cms 2025-04-09 7.5 HIGH N/A
Directory traversal vulnerability in custom.php in Entertainment Media Sharing CMS allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the pagename parameter.
CVE-2008-6502 1 Prochatrooms 1 Pro Chat Rooms 2025-04-09 4.6 MEDIUM N/A
Directory traversal vulnerability in Pro Chat Rooms 3.0.2 allows remote authenticated users to select an arbitrary local PHP script as an avatar via a .. (dot dot) in the avatar parameter, and cause other users to execute this script by using sendData.php to send a message to (1) an individual user or (2) a room, leading to cross-site request forgery (CSRF), cross-site scripting (XSS), or other impacts.