Vulnerabilities (CVE)

CWE filter

CWE-21

Filter

5 total CVE
CVE Vendors Products Updated CVSS
CVE-2019-1020001 2019-08-01 5.0
yard before 0.9.20 allows path traversal.
CVE-2019-11626 1 Doorgets 1 Doorgets Cms 2019-05-01 5.0
routers/ajaxRouter.php in doorGets 7.0 has a web site physical path leakage vulnerability, as demonstrated by an ajax/index.php?uri=1234%5c request.
CVE-2014-2232 1 Infoware 1 Mapsuite 2018-12-12 5.0
Absolute path traversal vulnerability in the MapAPI in Infoware MapSuite before 1.0.36 and 1.1.x before 1.1.49 allows remote attackers to read arbitrary files via unspecified vectors.
CVE-2017-1000438 1 Openmicroscopy 1 Omero 2018-01-17 6.5
In OMERO 5.3.3 or earlier a user could create an OriginalFile and adjust its path such that it now points to another user's file on the underlying filesystem, then manipulate the user's data.
CVE-2016-1505 1 Radicale 1 Radicale 2016-11-28 7.5
The filesystem storage backend in Radicale before 1.1 on Windows allows remote attackers to read or write to arbitrary files via a crafted path, as demonstrated by /c:/file/ignore.