NVD List

Id Name Description Reject CVSS Version CVSS Score Severity Pub Date Modified Date Actions
28844  CVE-2015-8794  Absolute path traversal vulnerability in program/steps/addressbook/photo.inc in Roundcube before 1.0.6 and 1.1.x before 1.1.2 allows remote authenticated users to read arbitrary files via a full pathname in the _alt parameter, related to contact photo handling.    Medium  2017-01-19  2016-02-25  View
26335  CVE-2015-5065  Absolute path traversal vulnerability in proxy.php in the google currency lookup in the Paypal Currency Converter Basic For WooCommerce plugin before 1.4 for WordPress allows remote attackers to read arbitrary files via a full pathname in the requrl parameter.    Medium  2017-01-19  2016-12-07  View
72972  CVE-2004-2595  Absolute path traversal vulnerability in Quake II server before R1Q2 on Linux, as used in multiple products, allows remote attackers to cause a denial of service (application crash) via a download command with a full pathname for a directory in the argument, which causes the server to crash when it cannot read data.    Medium  2017-07-18  2017-07-10  View
72971  CVE-2004-2594  Absolute path traversal vulnerability in Quake II server before R1Q2 on Windows, as used in multiple products, allows remote attackers to read arbitrary files via a / in a pathname argument, as demonstrated by download /server.cfg.    Medium  2017-07-18  2017-07-10  View
60726  CVE-2006-2021  Absolute path traversal vulnerability in recordings/misc/audio.php in the Asterisk Recording Interface (ARI) web interface in Asterisk@Home before 2.8 allows remote attackers to read arbitrary MP3, WAV, and GSM files via a full pathname in the recording parameter. NOTE: this issue can also be used to determine existence of files.    Medium  2016-12-20  2011-03-07  View

Page 562 of 17672, showing 5 records out of 88360 total, starting on record 2806, ending on 2810

Actions