Vulnerabilities (CVE)

Filtered by CWE-22
Total 8108 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2005-0253 1 Guillaumegardey 1 Biborb 2025-04-03 4.0 MEDIUM N/A
Directory traversal vulnerability in index.php for BibORB 1.3.2, and possibly earlier versions, allows remote attackers to delete arbitrary files via a Delete action and .. (dot dot) sequences in the database_name parameter.
CVE-2006-0976 1 Spid 1 Spid 2025-04-03 5.0 MEDIUM N/A
Directory traversal vulnerability in scan_lang_insert.php in Boris Herbiniere-Seve SPiD 1.3.1 allows remote attackers to read arbitrary files via the lang parameter.
CVE-2005-2033 1 Blue-collar Productions 1 I-gallery 2025-04-03 5.0 MEDIUM N/A
Directory traversal vulnerability in folderview.asp for Blue-Collar Productions i-Gallery 3.3 allows remote attackers to read arbitrary files and directories via the folder parameter.
CVE-2002-2416 1 Zeroo 1 Http Server 2025-04-03 5.0 MEDIUM N/A
Directory traversal vulnerability in Zeroo web server 1.5 allows remote attackers to read arbitrary files via a .. (dot dot) in a URL GET request.
CVE-2002-2399 1 Cascadesoft 1 W3mail 2025-04-03 6.4 MEDIUM N/A
Directory traversal vulnerability in viewAttachment.cgi in W3Mail 1.0.6 allows remote attackers to read arbitrary files via a .. (dot dot) in the file parameter.
CVE-2005-2792 1 Phpldapadmin Project 1 Phpldapadmin 2025-04-03 5.0 MEDIUM N/A
Directory traversal vulnerability in welcome.php in phpLDAPadmin 0.9.6 and 0.9.7 allows remote attackers to read arbitrary files via a .. (dot dot) in the custom_welcome_page parameter.
CVE-2005-3355 1 Gnu 1 Gnump3d 2025-04-03 6.4 MEDIUM N/A
Directory traversal vulnerability in GNU Gnump3d before 2.9.8 has unknown impact via "CGI parameters, and cookie values".
CVE-2003-1499 1 Bytehoard 1 Bytehoard 2025-04-03 5.0 MEDIUM N/A
Directory traversal vulnerability in index.php in Bytehoard 0.7 allows remote attackers to read arbitrary files via a .. (dot dot) in the infolder parameter.
CVE-2003-1430 3 Epic Games, Linux, Microsoft 3 Unreal Engine, Linux Kernel, All Windows 2025-04-03 5.0 MEDIUM N/A
Directory traversal vulnerability in Unreal Tournament Server 436 and earlier allows remote attackers to access known files via a ".." (dot dot) in an unreal:// URL.
CVE-2004-2750 1 Jbrowser 1 Jbrowser 2025-04-03 5.0 MEDIUM N/A
Directory traversal vulnerability in browser.php in JBrowser 1.0 through 2.1 allows remote attackers to read arbitrary files via the directory parameter. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.
CVE-2002-2403 1 Key Focus 1 Kf Web Server 2025-04-03 5.0 MEDIUM N/A
Directory traversal vulnerability in KeyFocus web server 1.0.8 allows remote attackers to read arbitrary files for recognized MIME type files via "...", "....", ".....", and other multiple dot sequences.
CVE-2002-2351 1 Qualcomm 1 Eudora 2025-04-03 6.4 MEDIUM N/A
Eudora 5.1 allows remote attackers to bypass security warnings and possibly execute arbitrary code via attachments with names containing a trailing "." (dot).
CVE-2004-2686 1 Sun 2 Solaris, Sunos 2025-04-03 7.2 HIGH N/A
Directory traversal vulnerability in the vfs_getvfssw function in Solaris 2.6, 7, 8, and 9 allows local users to load arbitrary kernel modules via crafted (1) mount or (2) sysfs system calls. NOTE: this might be the same issue as CVE-2004-1767, but there are insufficient details to be sure.
CVE-2004-1444 1 Roundup-tracker 1 Roundup 2025-04-03 5.0 MEDIUM N/A
Directory traversal vulnerability in Roundup 0.6.4 and earlier allows remote attackers to view arbitrary files via .. (dot dot) sequences in an @@ command in an HTTP GET request.
CVE-2005-3347 1 Phpgroupware 1 Phpgroupware 2025-04-03 6.8 MEDIUM N/A
Multiple directory traversal vulnerabilities in index.php in phpSysInfo 2.4 and earlier, as used in phpgroupware 0.9.16 and earlier, and egrouwpware before 1.0.0.009, allow remote attackers to include arbitrary files via .. (dot dot) sequences in the (1) sensor_program parameter or the (2) _SERVER[HTTP_ACCEPT_LANGUAGE] parameter, which overwrites an internal variable, a variant of CVE-2003-0536. NOTE: due to a typo in an advisory, an issue in osh was inadvertently linked to this identifier; the proper identifier for the osh issue is CVE-2005-3346.
CVE-2001-0780 1 Cosmicperl 1 Directory Pro 2025-04-03 5.0 MEDIUM N/A
Directory traversal vulnerability in cosmicpro.cgi in Cosmicperl Directory Pro 2.0 allows remote attackers to gain sensitive information via a .. (dot dot) in the SHOW parameter.
CVE-2002-2387 1 Mollensoft Software 1 Hyperion Ftp Server 2025-04-03 5.0 MEDIUM N/A
Directory traversal vulnerability in Hyperion FTP server 2.8.1 allows remote attackers to read arbitrary files via a .. (dot dot) in the LS command.
CVE-2006-1746 1 Tincan 1 Phplist 2025-04-03 5.0 MEDIUM N/A
Directory traversal vulnerability in PHPList 2.10.2 and earlier allows remote attackers to include arbitrary local files via the (1) GLOBALS[database_module] or (2) GLOBALS[language_module] parameters, which overwrite the underlying $GLOBALS variable.
CVE-2005-2378 1 Oracle 1 Reports 2025-04-03 5.0 MEDIUM N/A
Directory traversal vulnerability in Oracle Reports allows remote attackers to read arbitrary files via an absolute or relative path to the (1) CUSTOMIZE or (2) desformat parameters to rwservlet. NOTE: vector 2 is probably the same as CVE-2006-0289, and fixed in Jan 2006 CPU.
CVE-2003-1351 1 Greg Billock 1 Edittag 2025-04-03 5.0 MEDIUM N/A
Directory traversal vulnerability in edittag.cgi in EditTag 1.1 allows remote attackers to read arbitrary files via a "%2F.." (encoded slash dot dot) in the file parameter.