CWE-22
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
Description
The product uses external input to construct a pathname that is intended to identify a file or directory that is located underneath a restricted parent directory, but the product does not properly neutralize special elements within the pathname that can cause the pathname to resolve to a location that is outside of the restricted directory.
Hierarchy (View 1000)
Related attack patterns (CAPEC)
CAPEC-126 · CAPEC-64 · CAPEC-76 · CAPEC-78 · CAPEC-79
CVEs mapped to this weakness (10,395)
page 100 of 520| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2020-8209 | Hig | 0.53 | 7.5 | 0.49 | Aug 17, 2020 | Improper access control in Citrix XenMobile Server 10.12 before RP2, Citrix XenMobile Server 10.11 before RP4, Citrix XenMobile Server 10.10 before RP6 and Citrix XenMobile Server before 10.9 RP5 and leads to the ability to read arbitrary files. | ||
| CVE-2020-12499 | Hig | 0.53 | 8.2 | 0.00 | Jul 21, 2020 | In PHOENIX CONTACT PLCnext Engineer version 2020.3.1 and earlier an improper path sanitation vulnerability exists on import of project files. | ||
| CVE-2020-13158 | Hig | 0.53 | 7.5 | 0.54 | Jun 22, 2020 | Artica Proxy before 4.30.000000 Community Edition allows Directory Traversal via the fw.progrss.details.php popup parameter. | ||
| CVE-2020-5590 | Hig | 0.53 | 8.1 | 0.02 | Jun 19, 2020 | Directory traversal vulnerability in EC-CUBE 3.0.0 to 3.0.18 and 4.0.0 to 4.0.3 allows remote authenticated attackers to delete arbitrary files and/or directories on the server via unspecified vectors. | ||
| CVE-2020-12851 | Hig | 0.53 | 8.1 | 0.01 | Jun 4, 2020 | Pydio Cells 2.0.4 allows an authenticated user to write or overwrite existing files in another user’s personal and cells folders (repositories) by uploading a custom generated ZIP file and leveraging the file extraction feature present in the web application. The extracted… | ||
| CVE-2020-8810 | Hig | 0.53 | 8.1 | 0.02 | Feb 25, 2020 | An issue was discovered in Gurux GXDLMS Director through 8.5.1905.1301. When downloading OBIS codes, it does not verify that the downloaded files are actual OBIS codes and doesn't check for path traversal. This allows the attacker exploiting CVE-2020-8809 to send executable… | ||
| CVE-2013-2474 | Hig | 0.53 | 7.5 | 0.10 | Jan 27, 2020 | Directory traversal vulnerability in AWS XMS 2.5 allows remote attackers to view arbitrary files via the 'what' parameter. | ||
| CVE-2019-7751 | Hig | 0.53 | 7.5 | 0.14 | Dec 31, 2019 | A directory traversal and local file inclusion vulnerability in FPProducerInternetServer.exe in Ricoh MarcomCentral, formerly PTI Marketing, FusionPro VDP before 10.0 allows a remote attacker to list or enumerate sensitive contents of files. Furthermore, this could allow for… | ||
| CVE-2019-19731 | Hig | 0.53 | 7.5 | 0.12 | Dec 16, 2019 | Roxy Fileman 1.4.5 for .NET is vulnerable to path traversal. A remote attacker can write uploaded files to arbitrary locations via the RENAMEFILE action. This can be leveraged for code execution by uploading a specially crafted Windows shortcut file and writing the file to the… | ||
| CVE-2019-16758 | Hig | 0.53 | 7.5 | 0.17 | Nov 21, 2019 | In Lexmark Services Monitor 2.27.4.0.39 (running on TCP port 2070), a remote attacker can use a directory traversal technique using /../../../ or ..%2F..%2F..%2F to obtain local files on the host operating system. | ||
| CVE-2019-18951 | Hig | 0.53 | 7.5 | 0.20 | Nov 13, 2019 | SibSoft Xfilesharing through 2.5.1 allows op=page&tmpl=../ directory traversal to read arbitrary files. | ||
| CVE-2019-18371 | Hig | 0.53 | 7.5 | 0.56 | Oct 23, 2019 | An issue was discovered on Xiaomi Mi WiFi R3G devices before 2.28.23-stable. There is a directory traversal vulnerability to read arbitrary files via a misconfigured NGINX alias, as demonstrated by api-third-party/download/extdisks../etc/config/account. With this vulnerability,… | ||
| CVE-2019-16902 | Hig | 0.53 | 7.5 | 0.10 | Sep 27, 2019 | In the ARforms plugin 3.7.1 for WordPress, arf_delete_file in arformcontroller.php allows unauthenticated deletion of an arbitrary file by supplying the full pathname. | ||
| CVE-2017-18585 | Hig | 0.53 | 8.1 | 0.02 | Aug 22, 2019 | The posts-in-page plugin before 1.3.0 for WordPress has ic_add_posts template='../ directory traversal. | ||
| CVE-2019-14240 | Hig | 0.53 | 8.1 | 0.01 | Jul 23, 2019 | WCMS v0.3.2 has a CSRF vulnerability, with resultant directory traversal, to modify index.html via the /wex/html.php?finish=../index.html URI. | ||
| CVE-2019-12925 | Hig | 0.53 | 8.1 | 0.02 | Jul 8, 2019 | MailEnable Enterprise Premium 10.23 was vulnerable to multiple directory traversal issues, with which authenticated users could add, remove, or potentially read files in arbitrary folders accessible by the IIS user. This could lead to reading other users' credentials including… | ||
| CVE-2019-10137 | Hig | 0.53 | 8.1 | 0.03 | Jul 2, 2019 | A path traversal flaw was found in spacewalk-proxy, all versions through 2.9, in the way the proxy processes cached client tokens. A remote, unauthenticated attacker could use this flaw to test the existence of arbitrary files, if they have access to the proxy's filesystem, or… | ||
| CVE-2018-16594 | Hig | 0.53 | 8.1 | 0.01 | Jun 19, 2019 | The Photo Sharing Plus component on Sony Bravia TV through 8.587 devices allows Directory Traversal. | ||
| CVE-2019-9222 | Hig | 0.53 | 8.1 | 0.01 | Apr 17, 2019 | An issue was discovered in GitLab Community and Enterprise Edition before 11.6.10, 11.7.x before 11.7.6, and 11.8.x before 11.8.1. It has Insecure Permissions. | ||
| CVE-2019-3943 | Hig | 0.53 | 8.1 | 0.04 | Apr 10, 2019 | MikroTik RouterOS versions Stable 6.43.12 and below, Long-term 6.42.12 and below, and Testing 6.44beta75 and below are vulnerable to an authenticated, remote directory traversal via the HTTP or Winbox interfaces. An authenticated, remote attack can use this vulnerability to read… |
- risk 0.53cvss 7.5epss 0.49
Improper access control in Citrix XenMobile Server 10.12 before RP2, Citrix XenMobile Server 10.11 before RP4, Citrix XenMobile Server 10.10 before RP6 and Citrix XenMobile Server before 10.9 RP5 and leads to the ability to read arbitrary files.
- risk 0.53cvss 8.2epss 0.00
In PHOENIX CONTACT PLCnext Engineer version 2020.3.1 and earlier an improper path sanitation vulnerability exists on import of project files.
- risk 0.53cvss 7.5epss 0.54
Artica Proxy before 4.30.000000 Community Edition allows Directory Traversal via the fw.progrss.details.php popup parameter.
- risk 0.53cvss 8.1epss 0.02
Directory traversal vulnerability in EC-CUBE 3.0.0 to 3.0.18 and 4.0.0 to 4.0.3 allows remote authenticated attackers to delete arbitrary files and/or directories on the server via unspecified vectors.
- risk 0.53cvss 8.1epss 0.01
Pydio Cells 2.0.4 allows an authenticated user to write or overwrite existing files in another user’s personal and cells folders (repositories) by uploading a custom generated ZIP file and leveraging the file extraction feature present in the web application. The extracted…
- risk 0.53cvss 8.1epss 0.02
An issue was discovered in Gurux GXDLMS Director through 8.5.1905.1301. When downloading OBIS codes, it does not verify that the downloaded files are actual OBIS codes and doesn't check for path traversal. This allows the attacker exploiting CVE-2020-8809 to send executable…
- risk 0.53cvss 7.5epss 0.10
Directory traversal vulnerability in AWS XMS 2.5 allows remote attackers to view arbitrary files via the 'what' parameter.
- risk 0.53cvss 7.5epss 0.14
A directory traversal and local file inclusion vulnerability in FPProducerInternetServer.exe in Ricoh MarcomCentral, formerly PTI Marketing, FusionPro VDP before 10.0 allows a remote attacker to list or enumerate sensitive contents of files. Furthermore, this could allow for…
- risk 0.53cvss 7.5epss 0.12
Roxy Fileman 1.4.5 for .NET is vulnerable to path traversal. A remote attacker can write uploaded files to arbitrary locations via the RENAMEFILE action. This can be leveraged for code execution by uploading a specially crafted Windows shortcut file and writing the file to the…
- risk 0.53cvss 7.5epss 0.17
In Lexmark Services Monitor 2.27.4.0.39 (running on TCP port 2070), a remote attacker can use a directory traversal technique using /../../../ or ..%2F..%2F..%2F to obtain local files on the host operating system.
- risk 0.53cvss 7.5epss 0.20
SibSoft Xfilesharing through 2.5.1 allows op=page&tmpl=../ directory traversal to read arbitrary files.
- risk 0.53cvss 7.5epss 0.56
An issue was discovered on Xiaomi Mi WiFi R3G devices before 2.28.23-stable. There is a directory traversal vulnerability to read arbitrary files via a misconfigured NGINX alias, as demonstrated by api-third-party/download/extdisks../etc/config/account. With this vulnerability,…
- risk 0.53cvss 7.5epss 0.10
In the ARforms plugin 3.7.1 for WordPress, arf_delete_file in arformcontroller.php allows unauthenticated deletion of an arbitrary file by supplying the full pathname.
- risk 0.53cvss 8.1epss 0.02
The posts-in-page plugin before 1.3.0 for WordPress has ic_add_posts template='../ directory traversal.
- risk 0.53cvss 8.1epss 0.01
WCMS v0.3.2 has a CSRF vulnerability, with resultant directory traversal, to modify index.html via the /wex/html.php?finish=../index.html URI.
- risk 0.53cvss 8.1epss 0.02
MailEnable Enterprise Premium 10.23 was vulnerable to multiple directory traversal issues, with which authenticated users could add, remove, or potentially read files in arbitrary folders accessible by the IIS user. This could lead to reading other users' credentials including…
- risk 0.53cvss 8.1epss 0.03
A path traversal flaw was found in spacewalk-proxy, all versions through 2.9, in the way the proxy processes cached client tokens. A remote, unauthenticated attacker could use this flaw to test the existence of arbitrary files, if they have access to the proxy's filesystem, or…
- risk 0.53cvss 8.1epss 0.01
The Photo Sharing Plus component on Sony Bravia TV through 8.587 devices allows Directory Traversal.
- risk 0.53cvss 8.1epss 0.01
An issue was discovered in GitLab Community and Enterprise Edition before 11.6.10, 11.7.x before 11.7.6, and 11.8.x before 11.8.1. It has Insecure Permissions.
- risk 0.53cvss 8.1epss 0.04
MikroTik RouterOS versions Stable 6.43.12 and below, Long-term 6.42.12 and below, and Testing 6.44beta75 and below are vulnerable to an authenticated, remote directory traversal via the HTTP or Winbox interfaces. An authenticated, remote attack can use this vulnerability to read…