Skip to main content

CWE archive

CWE-22 CVEs

Programmatic archive

9,481 CVEs tagged with CWE-221,258 Critical, 3,928 High, 3,900 Medium, 389 Low, 6 Unrated.

CVE-2006-7112

Published Mar 6, 2007

Directory traversal vulnerability in error.php in MD-Pro 1.0.76 and earlier allows remote authenticated users to read and include arbitrary files via the PNSVlang cookie, as demon…

CVSS 6.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2006-7117

Published Mar 6, 2007

Multiple directory traversal vulnerabilities in Kubix 0.7 and earlier allow remote attackers to (1) include and execute arbitrary local files via ".." sequences in the theme cooki…

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2006-7079

Published Mar 2, 2007

Variable extraction vulnerability in include/common.php in exV2 2.0.4.3 and earlier allows remote attackers to overwrite arbitrary program variables and conduct directory traversa…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2007-1138

Published Mar 2, 2007

Absolute path traversal vulnerability in list_main_pages.php in Cromosoft Simple Plantilla PHP (SPP) allows remote attackers to list arbitrary directories, and read arbitrary file…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2007-1140

Published Mar 2, 2007

Directory traversal vulnerability in edit.php in pheap allows remote attackers to read and modify arbitrary files via a .. (dot dot) in the filename parameter.

CVSS 9.4 · Critical
Vendor/product tagsBeta · best-effort

CVE-2007-1143

Published Mar 2, 2007

Directory traversal vulnerability in pn-menu.php in J-Web Pics Navigator 1.0 allows remote attackers to list arbitrary directories via a .. (dot dot) in the dir parameter.

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2007-1144

Published Mar 2, 2007

Directory traversal vulnerability in jwpn-photos.php in J-Web Pics Navigator 2.0 allows remote attackers to list arbitrary directories via a .. (dot dot) in the dir parameter.

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2007-1149

Published Mar 2, 2007

Multiple directory traversal vulnerabilities in LoveCMS 1.4 allow remote attackers to read arbitrary files via a .. (dot dot) in (1) the step parameter to install/index.php or (2)…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2007-1152

Published Mar 2, 2007

Multiple directory traversal vulnerabilities in Pyrophobia 2.1.3.1 allow remote attackers to read arbitrary files via a .. (dot dot) in the (1) act or (2) pid parameter to the top…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2007-1126

Published Feb 27, 2007

Directory traversal vulnerability in index.php in xtcommerce allows remote attackers to read arbitrary files via a .. (dot dot) in the template parameter.

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2007-1076

Published Feb 22, 2007

Multiple directory traversal vulnerabilities in phpTrafficA 1.4.1, and possibly earlier, allow remote attackers to include arbitrary local files via a .. (dot dot) in the (1) file…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2007-1042

Published Feb 21, 2007

Directory traversal vulnerability in news.php in Xpression News (X-News) 1.0.1, when magic_quotes_gpc is disabled, allows remote attackers to include arbitrary files or obtain sen…

CVSS 5.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2007-1031

Published Feb 21, 2007

Directory traversal vulnerability in include/db_conn.php in SpoonLabs Vivvo Article Management CMS 3.4 allows remote attackers to include and execute arbitrary local files via the…

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2007-0898

Published Feb 16, 2007

Directory traversal vulnerability in clamd in Clam AntiVirus ClamAV before 0.90 allows remote attackers to overwrite arbitrary files via a .. (dot dot) in the id MIME header param…

CVSS 6.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2007-0893

Published Feb 12, 2007

Directory traversal vulnerability in phpMyVisites before 2.2 allows remote attackers to include arbitrary files via leading ".." sequences on the pmv_ck_view COOKIE parameter, whi…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2007-0700

Published Feb 4, 2007

Directory traversal vulnerability in index.php in Guernion Sylvain Portail Web Php (aka Gsylvain35 Portail Web, PwP) allows remote attackers to read arbitrary files via a .. (dot…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2007-0205

Published Jan 11, 2007

Directory traversal vulnerability in admin/skins.php for @lex Guestbook 4.0.2 and earlier allows remote attackers to create files in arbitrary directories via ".." sequences in th…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2006-6725

Published Dec 26, 2006

Multiple directory traversal vulnerabilities in PHPBuilder 0.0.2 and earlier allow remote attackers to read arbitrary files via a .. (dot dot) in the filename parameter to (1) lib…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2006-6242

Published Dec 3, 2006

Multiple directory traversal vulnerabilities in Serendipity 1.0.3 and earlier allow remote attackers to read or include arbitrary local files via a .. (dot dot) sequence in the se…

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2006-6047

Published Nov 22, 2006

Directory traversal vulnerability in manager/index.php in Etomite 0.6.1.2 allows remote authenticated administrators to include and execute arbitrary local files via a .. (dot dot…

CVSS 5.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2006-5981

Published Nov 20, 2006

Multiple directory traversal vulnerabilities in SeleniumServer FTP Server 1.0, and possibly earlier, allow remote attackers to list arbitrary directories, read arbitrary files, an…

CVSS 6.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2006-5897

Published Nov 15, 2006

Multiple directory traversal vulnerabilities in PhpMyChat Plus 1.9 and earlier allow remote attackers to read arbitrary files via a .. (dot dot) in the ChatPath parameter to (1) a…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2006-5487

Published Nov 10, 2006

Directory traversal vulnerability in Marshal MailMarshal SMTP 5.x, 6.x, and 2006, and MailMarshal for Exchange 5.x, allows remote attackers to write arbitrary files via ".." seque…

CVSS 10.0 · Critical
Vendor/product tagsBeta · best-effort

CVE-2006-5846

Published Nov 10, 2006

Directory traversal vulnerability in index.php in FreeWebshop 2.2.2 and earlier allows remote attackers to read and include arbitrary files via a .. (dot dot) in the page paramete…

CVSS 6.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2006-5149

Published Oct 5, 2006

Multiple directory traversal vulnerabilities in OpenBiblio before 0.5.2 allow remote attackers to include and execute arbitrary local files via a .. (dot dot) in (1) the page para…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort
Showing 9,376-9,400 of 9,481 CVEsPage 376 of 380