Skip to main content

CWE archive

CWE-22 CVEs

Programmatic archive

9,488 CVEs tagged with CWE-221,258 Critical, 3,928 High, 3,902 Medium, 389 Low, 11 Unrated.

CVE-2007-4764

Published Sep 8, 2007

Directory traversal vulnerability in pawfaliki.php in Pawfaliki 0.5.1 allows remote attackers to list arbitrary files via a .. (dot dot) in the page parameter. NOTE: the provenan…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2007-4756

Published Sep 8, 2007

Directory traversal vulnerability in the FTP client in Total Commander before 7.02 allows remote FTP servers to create or overwrite arbitrary files via "..\" (dot dot backslash) s…

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2007-4471

Published Sep 5, 2007

Multiple unspecified vulnerabilities in the Intuit QuickBooks Online Edition ActiveX control before 10 allow remote attackers to create or overwrite arbitrary files via unspecifie…

CVSS 9.3 · Critical
Vendor/product tagsBeta · best-effort

CVE-2007-4718

Published Sep 5, 2007

Directory traversal vulnerability in inc/lib/language.lib.php in Claroline before 1.8.6 allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in…

CVSS 5.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2007-4726

Published Sep 5, 2007

Directory traversal vulnerability in Web Oddity 0.09b allows remote attackers to read arbitrary files via a .. (dot dot) in the URI.

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2007-4663

Published Sep 4, 2007

Directory traversal vulnerability in PHP before 5.2.4 allows attackers to bypass open_basedir restrictions via unspecified vectors involving the glob function.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2007-4641

Published Aug 31, 2007

Directory traversal vulnerability in index.php in Pakupaku CMS 0.4 and earlier allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the page…

CVSS 6.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2007-4134

Published Aug 30, 2007

Directory traversal vulnerability in extract.c in star before 1.5a84 allows user-assisted remote attackers to overwrite arbitrary files via certain //.. (slash slash dot dot) sequ…

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2007-4220

Published Aug 29, 2007

Directory traversal vulnerability in Motorola Timbuktu Pro before 8.6.5 for Windows allows remote attackers to create or delete arbitrary files via a .. (dot dot) in a Send reques…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2007-4583

Published Aug 29, 2007

Multiple absolute path traversal vulnerabilities in the nvUtility.Utility.1 ActiveX control in nvUtility.dll 1.0.14.0 in ACTi Network Video Recorder (NVR) SP2 2.0 allow remote att…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2007-4585

Published Aug 29, 2007

Directory traversal vulnerability in activateuser.php in 2532|Gigs 1.2.1 allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the language pa…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2007-4559

Published Aug 28, 2007

Directory traversal vulnerability in the (1) extract and (2) extractall functions in the tarfile module in Python allows user-assisted remote attackers to overwrite arbitrary file…

CVSS 9.8 · Critical
evidence mentions
5
Buzz score
27.4
Vendor/product tagsBeta · best-effort

CVE-2007-4545

Published Aug 27, 2007

Multiple directory traversal vulnerabilities in Unreal Commander 0.92 build 565 and 573 allow user-assisted remote attackers to create or overwrite arbitrary files via a .. (dot d…

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2007-4457

Published Aug 21, 2007

Directory traversal vulnerability in forumreply.php in Dalai Forum 1.1 allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the chemin parame…

CVSS 6.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2007-4271

Published Aug 18, 2007

Directory traversal vulnerability in IBM DB2 UDB 8 before Fixpak 15 and 9.1 before Fixpak 3 allows local users to create arbitrary files via a .. (dot dot) in an unspecified envir…

CVSS 2.1 · Low
Vendor/product tagsBeta · best-effort

CVE-2007-4420

Published Aug 18, 2007

Absolute path traversal vulnerability in a certain ActiveX control in officeviewer.ocx 5.1.199.1 in EDraw Office Viewer Component 5.1 allows remote attackers to create or overwrit…

CVSS 9.3 · Critical
Vendor/product tagsBeta · best-effort

CVE-2007-4058

Published Jul 30, 2007

Absolute path traversal vulnerability in a certain ActiveX control in vielib.dll 2.2.5.42958 in EMC VMware 6.0.0 allows remote attackers to execute arbitrary local programs via a…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2007-4062

Published Jul 30, 2007

The SCANCTRL.ScanCtrlCtrl.1 ActiveX control in scan.dll in Nessus Vulnerability Scanner 3.0.6 allows remote attackers to delete arbitrary files via unspecified vectors involving t…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2007-4031

Published Jul 27, 2007

Directory traversal vulnerability in a certain ActiveX control in Nessus Vulnerability Scanner 3.0.6 allows remote attackers to delete arbitrary files via a .. (dot dot) in the ar…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2007-4008

Published Jul 26, 2007

Directory traversal vulnerability in custom.php in Entertainment Media Sharing CMS allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the p…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2007-3967

Published Jul 25, 2007

Directory traversal vulnerability in index.php in PHP Directory Lister (dirLIST) before 0.1.1 allows remote attackers to list the contents of a parent directory via a .. (dot dot)…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2007-3936

Published Jul 21, 2007

Directory traversal vulnerability in admin/filebrowser.asp in A-shop 0.70 and earlier, and possibly 0.71, allows remote attackers to delete arbitrary files via unspecified filenam…

CVSS 6.4 · Medium
Vendor/product tagsBeta · best-effort
Showing 9,351-9,375 of 9,488 CVEsPage 375 of 380