Total
6548 CVE
CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
---|---|---|---|---|---|
CVE-2012-5051 | 1 Vmware | 1 Capacityiq | 2024-11-21 | 5.0 MEDIUM | N/A |
Directory traversal vulnerability in VMware CapacityIQ 1.5.x allows remote attackers to read arbitrary files via unspecified vectors. | |||||
CVE-2012-4997 | 1 Anecms | 1 Anecms | 2024-11-21 | 7.5 HIGH | N/A |
Directory traversal vulnerability in acp/index.php in AneCMS allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the p parameter. | |||||
CVE-2012-4991 | 1 Axway | 1 Securetransport | 2024-11-21 | 8.5 HIGH | N/A |
Multiple directory traversal vulnerabilities in Axway SecureTransport 5.1 SP2 and earlier allow remote authenticated users to (1) read, (2) delete, or (3) create files, or (4) list directories, via a ..%5C (encoded dot dot backslash) in a URI. | |||||
CVE-2012-4959 | 1 Novell | 1 File Reporter | 2024-11-21 | 10.0 HIGH | N/A |
Directory traversal vulnerability in NFRAgent.exe in Novell File Reporter 1.0.2 allows remote attackers to upload and execute files via a 130 /FSF/CMD request with a .. (dot dot) in a FILE element of an FSFUI record. | |||||
CVE-2012-4958 | 1 Novell | 1 File Reporter | 2024-11-21 | 7.8 HIGH | N/A |
Directory traversal vulnerability in NFRAgent.exe in Novell File Reporter 1.0.2 allows remote attackers to read arbitrary files via a 126 /FSF/CMD request with a .. (dot dot) in a FILE element of an FSFUI record. | |||||
CVE-2012-4957 | 1 Novell | 1 File Reporter | 2024-11-21 | 7.8 HIGH | N/A |
Absolute path traversal vulnerability in NFRAgent.exe in Novell File Reporter 1.0.2 allows remote attackers to read arbitrary files via a /FSF/CMD request with a full pathname in a PATH element of an SRS record. | |||||
CVE-2012-4940 | 1 Gecad | 1 Axigen Free Mail Server | 2024-11-21 | 6.4 MEDIUM | N/A |
Multiple directory traversal vulnerabilities in the View Log Files component in Axigen Free Mail Server allow remote attackers to read or delete arbitrary files via a .. (dot dot) in (1) the fileName parameter in a download action to source/loggin/page_log_dwn_file.hsp, or the fileName parameter in (2) an edit action or (3) a delete action to the default URI. | |||||
CVE-2012-4920 | 2 Wordpress, Zingiri | 2 Wordpress, Forums | 2024-11-21 | 5.0 MEDIUM | N/A |
Directory traversal vulnerability in the zing_forum_output function in forum.php in the Zingiri Forum (aka Forums) plugin before 1.4.4 for WordPress allows remote attackers to read arbitrary files via a .. (dot dot) in the url parameter to index.php. | |||||
CVE-2012-4915 | 2 Davistribe, Wordpress | 2 Google Doc Embedder, Wordpress | 2024-11-21 | 5.0 MEDIUM | N/A |
Directory traversal vulnerability in the Google Doc Embedder plugin before 2.5.4 for WordPress allows remote attackers to read arbitrary files via a .. (dot dot) in the file parameter to libs/pdf.php. | |||||
CVE-2012-4878 | 1 Flatnux | 1 Flatnux | 2024-11-21 | 5.0 MEDIUM | N/A |
Absolute path traversal vulnerability in controlcenter.php in FlatnuX CMS 2011 08.09.2 allows remote administrators to read arbitrary files via a full pathname in the dir parameter in a contents/Files action. | |||||
CVE-2012-4867 | 1 Vtiger | 1 Vtiger Crm | 2024-11-21 | 5.0 MEDIUM | N/A |
Directory traversal vulnerability in modules/com_vtiger_workflow/sortfieldsjson.php in vtiger CRM 5.1.0 allows remote attackers to read arbitrary files via a .. (dot dot) in the module_name parameter. | |||||
CVE-2012-4834 | 1 Ibm | 1 Websphere Portal | 2024-11-21 | 5.0 MEDIUM | N/A |
Directory traversal vulnerability in LayerLoader.jsp in the theme component in IBM WebSphere Portal 7.0.0.1 and 7.0.0.2 before CF19 and 8.0 before CF03 allows remote attackers to read arbitrary files via a crafted URI. | |||||
CVE-2012-4705 | 1 3s-software | 1 Codesys Gateway-server | 2024-11-21 | 10.0 HIGH | N/A |
Directory traversal vulnerability in 3S CODESYS Gateway-Server before 2.3.9.27 allows remote attackers to execute arbitrary code via vectors involving a crafted pathname. | |||||
CVE-2012-4701 | 1 Tridium | 1 Niagara Ax | 2024-11-21 | 9.3 HIGH | N/A |
Directory traversal vulnerability in Tridium Niagara AX 3.5, 3.6, and 3.7 allows remote attackers to read sensitive files, and consequently execute arbitrary code, by leveraging (1) valid credentials or (2) the guest feature. | |||||
CVE-2012-4680 | 1 Ioserver | 1 Ioserver | 2024-11-21 | 4.3 MEDIUM | N/A |
Directory traversal vulnerability in the XML Server in IOServer before 1.0.19.0, when the Root Directory pathname lacks a trailing \ (backslash) character, allows remote attackers to read arbitrary files or list arbitrary directories via a .. (dot dot) in a URI. | |||||
CVE-2012-4616 | 1 Emc | 1 Data Protection Advisor | 2024-11-21 | 5.0 MEDIUM | N/A |
Directory traversal vulnerability in the Web UI in EMC Data Protection Advisor (DPA) 5.6 through SP1, 5.7 through SP1, and 5.8 through SP4 allows remote attackers to read arbitrary files via unspecified vectors. | |||||
CVE-2012-4596 | 1 Mcafee | 1 Email Gateway | 2024-11-21 | 4.3 MEDIUM | N/A |
Directory traversal vulnerability in McAfee Email Gateway (MEG) 7.0.0 and 7.0.1 allows remote authenticated users to bypass intended access restrictions and download arbitrary files via a crafted URL. | |||||
CVE-2012-4506 | 2 Gitolite, Sitaram Chamarty | 2 Gitolite, Gitolite | 2024-11-21 | 4.6 MEDIUM | N/A |
Directory traversal vulnerability in gitolite 3.x before 3.1, when wild card repositories and a pattern matching "../" are enabled, allows remote authenticated users to create arbitrary repositories and possibly perform other actions via a .. (dot dot) in a repository name. | |||||
CVE-2012-4356 | 1 Sielcosistemi | 2 Winlog Lite, Winlog Pro | 2024-11-21 | 4.3 MEDIUM | N/A |
Multiple directory traversal vulnerabilities in Sielco Sistemi Winlog Pro SCADA before 2.07.17 and Winlog Lite SCADA before 2.07.17 allow remote attackers to read arbitrary files via port-46824 TCP packets specifying a file-open operation with opcode 0x78 and a .. (dot dot) in a pathname, followed by a file-read operation with opcode (1) 0x96, (2) 0x97, or (3) 0x98. | |||||
CVE-2012-4347 | 1 Symantec | 1 Messaging Gateway | 2024-11-21 | 5.0 MEDIUM | N/A |
Multiple directory traversal vulnerabilities in the management console in Symantec Messaging Gateway (SMG) 9.5.x allow remote authenticated users to read arbitrary files via a .. (dot dot) in the (1) logFile parameter in a logs action to brightmail/export or (2) localBackupFileSelection parameter in an APPLIANCE restoreSource action to brightmail/admin/restore/download.do. |