Vulnerabilities (CVE)

Filtered by CWE-22
Total 10229 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2009-4740 1 Typo3 2 Typo3, Ws Ecard 2026-06-16 7.5 HIGH N/A
Directory traversal vulnerability in the Webesse E-Card (ws_ecard) extension 1.0.2 and earlier for TYPO3 has unspecified impact and remote attack vectors.
CVE-2009-4726 1 Olivier Michaud Pierre-yves 1 Quickdev4php 2026-06-16 5.0 MEDIUM N/A
Directory traversal vulnerability in download.php in Quickdev 4 PHP allows remote attackers to read arbitrary files via a .. (dot dot) in the file parameter.
CVE-2009-4725 1 Arabportal 1 Arab Portal 2026-06-16 5.1 MEDIUM N/A
Directory traversal vulnerability in modules/aljazeera/admin/setup.php in Arab Portal 2.2 and earlier, when register_globals is enabled and magic_quotes_gpc is disabled, allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the module parameter.
CVE-2009-4723 1 Netpet 1 Netpet Cms 2026-06-16 7.5 HIGH N/A
Directory traversal vulnerability in confirm.php in Netpet CMS 1.9 allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the language parameter.
CVE-2009-4700 1 Skadate 1 Skadate Online Dating Software 2026-06-16 5.0 MEDIUM N/A
Directory traversal vulnerability in index.php in SkaDate Dating allows remote attackers to read arbitrary files via a .. (dot dot) in the layout parameter.
CVE-2009-4683 1 Scriptsez 1 Good\/bad Vote 2026-06-16 7.5 HIGH N/A
Directory traversal vulnerability in vote.php in Good/Bad Vote allows remote attackers to include and execute arbitrary local files via directory traversal sequences in the id parameter in a dovote action. NOTE: some of these details are obtained from third party information.
CVE-2009-4679 2 Inertialfate, Joomla 2 Com If Nexus, Joomla\! 2026-06-16 7.5 HIGH N/A
Directory traversal vulnerability in the inertialFATE iF Portfolio Nexus (com_if_nexus) component 1.5 for Joomla! allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the controller parameter to index.php.
CVE-2009-4672 2 Grupenet, Wordpress 2 Wp-lytebox, Wordpress 2026-06-16 7.5 HIGH N/A
Directory traversal vulnerability in main.php in the WP-Lytebox plugin 1.3 for WordPress allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the pg parameter.
CVE-2009-4665 1 Cutesoft Components 1 Cute Editor For Asp.net 2026-06-16 5.0 MEDIUM N/A
Directory traversal vulnerability in CuteSoft_Client/CuteEditor/Load.ashx in CuteSoft Components Cute Editor for ASP.NET allows remote attackers to read arbitrary files via a .. (dot dot) in the file parameter.
CVE-2009-4645 1 Accellion 1 Secure File Transfer Appliance 2026-06-16 7.8 HIGH N/A
Directory traversal vulnerability in web_client_user_guide.html in Accellion Secure File Transfer Appliance before 8_0_105 allows remote attackers to read arbitrary files via a .. (dot dot) in the lang parameter.
CVE-2009-4627 1 Dan Brown 1 Moa Gallery 2026-06-16 5.0 MEDIUM N/A
Directory traversal vulnerability in sources/_template_parser.php in Moa Gallery 1.2.0 and earlier allows remote attackers to read arbitrary files via a .. (dot dot) in the p_filename parameter, a different issue than CVE-2009-4614.
CVE-2009-4626 1 Phpnagios 1 Phpnagios 2026-06-16 7.5 HIGH N/A
Directory traversal vulnerability in menu.php in phpNagios 1.2.0 allows remote attackers to include and execute arbitrary local files via directory traversal sequences in the conf[lang] parameter.
CVE-2009-4581 1 Roseonlinecms 1 Roseonlinecms 2026-06-16 6.8 MEDIUM 9.8 CRITICAL
Directory traversal vulnerability in modules/admincp.php in RoseOnlineCMS 3 B1 and earlier, when magic_quotes_gpc is disabled, allows remote attackers to include and execute arbitrary local files via directory traversal sequences in the admin parameter.
CVE-2009-4512 1 Indymedia 1 Oscailt 2026-06-16 5.1 MEDIUM N/A
Directory traversal vulnerability in index.php in Oscailt 3.3, when Use Friendly URL's is disabled, allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the obj_id parameter.
CVE-2009-4449 1 Mybb 1 Mybb 2026-06-16 6.3 MEDIUM 6.5 MEDIUM
Directory traversal vulnerability in MyBB (aka MyBulletinBoard) 1.4.10, and possibly earlier versions, when changing the user avatar from the gallery, allows remote authenticated users to determine the existence of files via directory traversal sequences in the avatar and possibly the gallery parameters, related to (1) admin/modules/user/users.php and (2) usercp.php.
CVE-2009-4435 1 Compmaster.prv.pl 1 F3site 2026-06-16 6.8 MEDIUM N/A
Multiple directory traversal vulnerabilities in F3Site 2009 allow remote attackers to include and execute arbitrary local files via directory traversal sequences in the GLOBALS[nlang] parameter to (1) mod/poll.php and (2) mod/new.php.
CVE-2009-4434 1 Idevspot 1 Isupport 2026-06-16 5.0 MEDIUM N/A
Directory traversal vulnerability in index.php in IDevSpot iSupport 1.8 and earlier allows remote attackers to read arbitrary files via a .. (dot dot) in the include_file parameter.
CVE-2009-4427 1 Phpldapadmin Project 1 Phpldapadmin 2026-06-16 7.5 HIGH N/A
Directory traversal vulnerability in cmd.php in phpLDAPadmin 1.1.0.5 allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the cmd parameter.
CVE-2009-4426 1 Launchpad 1 Ignition 2026-06-16 6.8 MEDIUM N/A
Multiple directory traversal vulnerabilities in Ignition 1.2, when magic_quotes_gpc is disabled, allow remote attackers to include and execute arbitrary local files via a .. (dot dot) in the blog parameter to (1) comment.php and (2) view.php.
CVE-2009-4421 1 Alexander Palmo 1 Simple Php Blog 2026-06-16 6.5 MEDIUM N/A
Directory traversal vulnerability in languages_cgi.php in Simple PHP Blog 0.5.1 and earlier allows remote authenticated users to include and execute arbitrary local files via a .. (dot dot) in the blog_language1 parameter.