CVE-2017-9964

CVSS v3 Score
6.9
Medium
CVSS v2 Score
5.8
Medium

Vulnerability Description

A Path Traversal issue was discovered in Schneider Electric Pelco VideoXpert Enterprise all versions prior to 2.1. By sniffing communications, an unauthorized person can execute a directory traversal attack resulting in authentication bypass or session hijack.

CVSS:7.0(High)

An issue was discovered in Advantech SUISAccess Server Version 3.0 and prior. The directory traversal/file upload error allows an attacker to upload and unpack a zip file.

CWE-222016
CVSS:7.0(High)

Directory traversal vulnerability in the setuid root helper binary in S-nail (later S-mailx) before 14.8.16 allows local users to write to arbitrary files and consequently gain root privileges via a ....

CWE-222017
CVSS:7.0(High)

In MODX Revolution before 2.5.7, when PHP 5.3.3 is used, an attacker is able to include and execute arbitrary files on the web server due to insufficient validation of the action parameter to setup/in...

CWE-222017
CVSS:7.0(High)

This vulnerability allows local attackers to escalate privileges on vulnerable installations of Samsung Notes Fixed in version 2.0.02.31. An attacker must first obtain the ability to execute low-privi...

CWE-222018
CVSS:7.0(High)

A directory traversal vulnerability in the ZIP archive extraction routines of KNIME Analytics Platform 3.2.0 and above can result in arbitrary files being overwritten on the user's system. This vulner...

CWE-222022
CVSS:7.0(High)

Azure Arc-Enabled Servers Elevation of Privilege Vulnerability

CWE-222023