Vulmon
Recent Vulnerabilities
Product List
Research Posts
Trends
Blog
About
Contact
Vulmon Alerts
By Relevance
By Risk Score
By Publish Date
path traversal vulnerabilities and exploits
(subscribe to this query)
NA
CVE-2013-7097
Directory traversal vulnerability in 7 Media Web Solutions eduTrac prior to 1.1.2 allows remote malicious users to read arbitrary files via a .. (dot dot) in the showmask parameter to installer/overview.php.
7mediaws Edutrac 1.0.4
7mediaws Edutrac 1.0.6
7mediaws Edutrac 1.0.1
7mediaws Edutrac
7mediaws Edutrac 1.0.2
7mediaws Edutrac 1.0.8
7mediaws Edutrac 1.0.3
7mediaws Edutrac 1.0.7
7mediaws Edutrac 1.0.9
7mediaws Edutrac 1.0.5
7mediaws Edutrac 1.0.0
1 EDB exploit
8.8
CVSSv3
CVE-2020-11531
The DataEngine Xnode Server application in Zoho ManageEngine DataSecurity Plus before 6.0.1 does not validate the database schema name when handling a DR-SCHEMA-SYNC request. This allows an authenticated malicious user to execute code in the context of the product by writing a JS...
Zohocorp Manageengine Adaudit Plus
Zohocorp Manageengine Datasecurity Plus
NA
CVE-2024-32113
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Apache OFBiz.This issue affects Apache OFBiz: prior to 18.12.13. Users are recommended to upgrade to version 18.12.13, which fixes the issue.
2 Github repositories
7.2
CVSSv3
CVE-2020-12827
MJML before 4.6.3 contains a path traversal vulnerability when processing the mj-include directive within an MJML document.
Mjml Mjml
7.5
CVSSv3
CVE-2021-41381
Payara Micro Community 5.2021.6 and below allows Directory Traversal.
Payara Micro Community
1 Github repository
6.5
CVSSv3
CVE-2020-27994
SolarWinds Serv-U prior to 15.2.2 allows Authenticated Directory Traversal.
Solarwinds Serv-u
1 Github repository
6.5
CVSSv3
CVE-2019-3799
Spring Cloud Config, versions 2.1.x before 2.1.2, versions 2.0.x before 2.0.4, and versions 1.4.x before 1.4.6, and older unsupported versions allow applications to serve arbitrary configuration files through the spring-cloud-config-server module. A malicious user, or attacker, c...
Vmware Spring Cloud Config
Oracle Communications Cloud Native Core Policy 1.15.0
1 EDB exploit
2 Github repositories
6.3
CVSSv3
CVE-2017-9640
A Path Traversal issue exists in Automated Logic Corporation (ALC) ALC WebCTRL, i-Vu, SiteScan Web before 6.5; ALC WebCTRL, SiteScan Web 6.1 and prior; ALC WebCTRL, i-Vu 6.0 and prior; ALC WebCTRL, i-Vu, SiteScan Web 5.5 and prior; and ALC WebCTRL, i-Vu, SiteScan Web 5.2 and prio...
Automatedlogic Sitescan Web
Automatedlogic I-vu
Carrier Automatedlogic Webctrl
1 EDB exploit
7.5
CVSSv3
CVE-2017-1000028
Oracle, GlassFish Server Open Source Edition 4.1 is vulnerable to both authenticated and unauthenticated Directory Traversal vulnerability, that can be exploited by issuing a specially crafted HTTP GET request.
Oracle Glassfish Server 4.1
3 EDB exploits
2 Github repositories
7.5
CVSSv3
CVE-2015-1876
Directory traversal vulnerability in ES File Explorer 3.2.4.1.
Estrongs Es File Explorer 3.2.4.1
CVSSv3
CVSSv2
CVSSv3
VMScore
Recommendations:
TCP
CVE-2024-4577
CVE-2024-2695
CVE-2024-31870
injection
CVE-2024-3813
arbitrary code
CVE-2024-27801
CVE-2024-30120
Vulnerability Notification Service
You don’t have to wait for vulnerability scanning results
Get Started
« PREV
1
2
3
4
5
6
7
8
9
NEXT »