Total
7246 CVE
CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
---|---|---|---|---|---|
CVE-2017-17108 | 1 Konakart | 1 Konakart | 2024-11-21 | 7.5 HIGH | 9.8 CRITICAL |
Path traversal vulnerability in the administrative panel in KonaKart eCommerce Platform version 8.7 and earlier could allow an attacker to download system files, as well as upload specially crafted JSP files and in turn gain access to the server. | |||||
CVE-2017-16922 | 1 Wowza | 1 Streaming Engine | 2024-11-21 | 5.0 MEDIUM | 5.3 MEDIUM |
In com.wowza.wms.timedtext.http.HTTPProviderCaptionFile in Wowza Streaming Engine before 4.7.1, traversal of the directory structure and retrieval of a file are possible via a remote, specifically crafted HTTP request. | |||||
CVE-2017-16859 | 1 Atlassian | 2 Crucible, Fisheye | 2024-11-21 | 4.0 MEDIUM | 6.5 MEDIUM |
The review attachment resource in Atlassian Fisheye and Crucible before version 4.3.2, from version 4.4.0 before 4.4.3 and before version 4.5.0 allows remote attackers to read files contained within context path of the running application through a path traversal vulnerability in the command parameter. | |||||
CVE-2017-16814 | 1 Foxitsoftware | 1 Mobilepdf | 2024-11-21 | 3.3 LOW | 5.5 MEDIUM |
A Directory Traversal issue was discovered in the Foxit MobilePDF app before 6.1 for iOS. This occurs by abusing the URL + escape character during a Wi-Fi transfer, which could be exploited by attackers to bypass intended restrictions on local application files. | |||||
CVE-2017-16744 | 1 Tridium | 2 Niagara, Niagara Ax Framework | 2024-11-21 | 6.5 MEDIUM | 7.2 HIGH |
A path traversal vulnerability in Tridium Niagara AX Versions 3.8 and prior and Niagara 4 systems Versions 4.4 and prior installed on Microsoft Windows Systems can be exploited by leveraging valid platform (administrator) credentials. | |||||
CVE-2017-16720 | 1 Advantech | 1 Webaccess | 2024-11-21 | 10.0 HIGH | 9.8 CRITICAL |
A Path Traversal issue was discovered in WebAccess versions 8.3.2 and earlier. An attacker has access to files within the directory structure of the target device. | |||||
CVE-2017-16654 | 2 Debian, Sensiolabs | 2 Debian Linux, Symfony | 2024-11-21 | 5.0 MEDIUM | 7.5 HIGH |
An issue was discovered in Symfony before 2.7.38, 2.8.31, 3.2.14, 3.3.13, 3.4-BETA5, and 4.0-BETA5. The Intl component includes various bundle readers that are used to read resource bundles from the local filesystem. The read() methods of these classes use a path and a locale to determine the language bundle to retrieve. The locale argument value is commonly retrieved from untrusted user input (like a URL parameter). An attacker can use this argument to navigate to arbitrary directories via the dot-dot-slash attack, aka Directory Traversal. | |||||
CVE-2017-16223 | 1 Nodeaaaaa Project | 1 Nodeaaaaa | 2024-11-21 | 5.0 MEDIUM | 7.5 HIGH |
nodeaaaaa is a static file server. nodeaaaaa is vulnerable to a directory traversal issue, giving an attacker access to the filesystem by placing "../" in the url. | |||||
CVE-2017-16222 | 1 Elding Project | 1 Elding | 2024-11-21 | 5.0 MEDIUM | 5.3 MEDIUM |
elding is a simple web server. elding is vulnerable to a directory traversal issue, allowing an attacker to access the filesystem by placing "../" in the url. The files accessible, however, are limited to files with a file extension. Sending a GET request to /../../../etc/passwd, for example, will return a 404 on etc/passwd/index.js. | |||||
CVE-2017-16221 | 1 Yzt Project | 1 Yzt | 2024-11-21 | 5.0 MEDIUM | 7.5 HIGH |
yzt is a simple file server. yzt is vulnerable to a directory traversal issue, giving an attacker access to the filesystem by placing "../" in the url. | |||||
CVE-2017-16220 | 1 Wind-mvc Project | 1 Wind-mvc | 2024-11-21 | 5.0 MEDIUM | 7.5 HIGH |
wind-mvc is an mvc framework. wind-mvc is vulnerable to a directory traversal issue, giving an attacker access to the filesystem by placing "../" in the url. | |||||
CVE-2017-16219 | 1 Yttivy Project | 1 Yttivy | 2024-11-21 | 5.0 MEDIUM | 7.5 HIGH |
yttivy is a static file server. yttivy is vulnerable to a directory traversal issue, giving an attacker access to the filesystem by placing "../" in the url. | |||||
CVE-2017-16218 | 1 Dgard8.lab6 Project | 1 Dgard8.lab6 | 2024-11-21 | 5.0 MEDIUM | 7.5 HIGH |
dgard8.lab6 is a static file server. dgard8.lab6 is vulnerable to a directory traversal issue, giving an attacker access to the filesystem by placing "../" in the url. | |||||
CVE-2017-16217 | 1 Webrtc-experiment | 1 Fbr-client | 2024-11-21 | 5.0 MEDIUM | 7.5 HIGH |
fbr-client sends files through sockets via socket.io and webRTC. fbr-client is vulnerable to a directory traversal issue, giving an attacker access to the filesystem by placing "../" in the url. | |||||
CVE-2017-16216 | 1 Tencent-server Project | 1 Tencent-server | 2024-11-21 | 5.0 MEDIUM | 7.5 HIGH |
tencent-server is a simple web server. tencent-server is vulnerable to a directory traversal issue, giving an attacker access to the filesystem by placing "../" in the url. | |||||
CVE-2017-16215 | 1 Sgqserve Project | 1 Sgqserve | 2024-11-21 | 5.0 MEDIUM | 7.5 HIGH |
sgqserve is a simple file server. sgqserve is vulnerable to a directory traversal issue, giving an attacker access to the filesystem by placing "../" in the url. | |||||
CVE-2017-16214 | 1 Peiserver Project | 1 Peiserver | 2024-11-21 | 5.0 MEDIUM | 7.5 HIGH |
peiserver is a static file server. peiserver is vulnerable to a directory traversal issue, giving an attacker access to the filesystem by placing "../" in the url. | |||||
CVE-2017-16213 | 1 Mfrserver Project | 1 Mfrserver | 2024-11-21 | 5.0 MEDIUM | 7.5 HIGH |
mfrserver is a simple file server. mfrserver is vulnerable to a directory traversal issue, giving an attacker access to the filesystem by placing "../" in the url. | |||||
CVE-2017-16212 | 1 Ltt Project | 1 Ltt | 2024-11-21 | 5.0 MEDIUM | 7.5 HIGH |
ltt is a static file server. ltt is vulnerable to a directory traversal issue, giving an attacker access to the filesystem by placing "../" in the url. | |||||
CVE-2017-16211 | 1 Lessindex Project | 1 Lessindex | 2024-11-21 | 5.0 MEDIUM | 7.5 HIGH |
lessindex is a static file server. lessindex is vulnerable to a directory traversal issue, giving an attacker access to the filesystem by placing "../" in the url. |