CWE-22
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
Description
The product uses external input to construct a pathname that is intended to identify a file or directory that is located underneath a restricted parent directory, but the product does not properly neutralize special elements within the pathname that can cause the pathname to resolve to a location that is outside of the restricted directory.
Hierarchy (View 1000)
Related attack patterns (CAPEC)
CAPEC-126 · CAPEC-64 · CAPEC-76 · CAPEC-78 · CAPEC-79
CVEs mapped to this weakness (10,395)
page 108 of 520| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2020-36566 | Cri | 0.52 | 9.1 | 0.01 | Dec 27, 2022 | Due to improper path sanitization, archives containing relative file paths can cause files to be written (or overwritten) outside of the target directory. | ||
| CVE-2020-36561 | Cri | 0.52 | 9.1 | 0.01 | Dec 27, 2022 | Due to improper path sanitization, archives containing relative file paths can cause files to be written (or overwritten) outside of the target directory. | ||
| CVE-2020-36560 | Cri | 0.52 | 9.1 | 0.01 | Dec 27, 2022 | Due to improper path sanitization, archives containing relative file paths can cause files to be written (or overwritten) outside of the target directory. | ||
| CVE-2018-25046 | Cri | 0.52 | 9.1 | 0.01 | Dec 27, 2022 | Due to improper path sanitization, archives containing relative file paths can cause files to be written (or overwritten) outside of the target directory. | ||
| CVE-2022-44900 | Cri | 0.52 | 9.1 | 0.02 | Dec 6, 2022 | A directory traversal vulnerability in the SevenZipFile.extractall() function of the python library py7zr v0.20.0 and earlier allows attackers to write arbitrary files via extracting a crafted 7z file. | ||
| CVE-2022-38422 | Hig | 0.52 | 7.5 | 0.44 | Oct 14, 2022 | Adobe ColdFusion versions Update 14 (and earlier) and Update 4 (and earlier) are affected by an Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability that could result in information disclosure. Exploitation of this issue does not require… | ||
| CVE-2022-38638 | Cri | 0.52 | 9.1 | 0.01 | Sep 9, 2022 | Casdoor v1.97.3 was discovered to contain an arbitrary file write vulnerability via the fullFilePath parameter at /api/upload-resource. | ||
| CVE-2022-1992 | Cri | 0.52 | 9.1 | 0.02 | Jun 9, 2022 | Path Traversal in GitHub repository gogs/gogs prior to 0.12.9. | ||
| CVE-2022-24840 | Cri | 0.52 | 9.1 | 0.02 | Jun 9, 2022 | django-s3file is a lightweight file upload input for Django and Amazon S3 . In versions prior to 5.5.1 it was possible to traverse the entire AWS S3 bucket and in most cases to access or delete files. If the `AWS_LOCATION` setting was set, traversal was limited to that location… | ||
| CVE-2022-28052 | Hig | 0.52 | 8.0 | 0.03 | Apr 13, 2022 | Directory Traversal vulnerability in file cn/roothub/store/FileSystemStorageService in function store in Roothub 2.6.0 allows remote attackers with low privlege to arbitrarily upload files via /common/upload API, which could lead to remote arbitrary code execution. | ||
| CVE-2022-24303 | Cri | 0.52 | 9.1 | 0.03 | Mar 28, 2022 | Pillow before 9.0.1 allows attackers to delete files because spaces in temporary pathnames are mishandled. | ||
| CVE-2021-42542 | Hig | 0.52 | 8.0 | 0.01 | Oct 22, 2021 | The affected product is vulnerable to directory traversal due to mishandling of provided backup folder structure. | ||
| CVE-2021-41578 | Hig | 0.52 | 7.8 | 0.11 | Oct 4, 2021 | mySCADA myDESIGNER 8.20.0 and below allows Directory Traversal attacks when importing project files. If an attacker can trick a victim into importing a malicious mep file, then they gain the ability to write arbitrary files to OS locations where the user has permission. This… | ||
| CVE-2021-34363 | Cri | 0.52 | 9.1 | 0.02 | Jun 10, 2021 | The thefuck (aka The Fuck) package before 3.31 for Python allows Path Traversal that leads to arbitrary file deletion via the "undo archive operation" feature. | ||
| CVE-2020-36364 | Cri | 0.52 | 9.1 | 0.02 | May 19, 2021 | An issue was discovered in Smartstore (aka SmartStoreNET) before 4.1.0. Administration/Controllers/ImportController.cs allows path traversal (for copy and delete actions) in the ImportController.Create method via a TempFileName field. | ||
| CVE-2020-23575 | Hig | 0.52 | 7.5 | 0.37 | May 10, 2021 | A directory traversal vulnerability exists in Kyocera Printer d-COPIA253MF plus. Successful exploitation of this vulnerability could allow an attacker to retrieve or view arbitrary files from the affected server. | ||
| CVE-2021-27276 | Hig | 0.52 | 7.1 | 0.72 | Mar 29, 2021 | This vulnerability allows remote attackers to delete arbitrary files on affected installations of NETGEAR ProSAFE Network Management System 1.6.0.26. Although authentication is required to exploit this vulnerability, the existing authentication mechanism can be bypassed. The… | ||
| CVE-2021-27272 | Hig | 0.52 | 7.1 | 0.74 | Mar 29, 2021 | This vulnerability allows remote attackers to delete arbitrary files on affected installations of NETGEAR ProSAFE Network Management System 1.6.0.26. Although authentication is required to exploit this vulnerability, the existing authentication mechanism can be bypassed. The… | ||
| CVE-2020-8570 | Cri | 0.52 | 9.1 | 0.04 | Jan 21, 2021 | Kubernetes Java client libraries in version 10.0.0 and versions prior to 9.0.1 allow writes to paths outside of the current directory when copying multiple files from a remote pod which sends a maliciously crafted archive. This can potentially overwrite any files on the system… | ||
| CVE-2020-14352 | Hig | 0.52 | 8.0 | 0.03 | Aug 30, 2020 | A flaw was found in librepo in versions before 1.12.1. A directory traversal vulnerability was found where it failed to sanitize paths in remote repository metadata. An attacker controlling a remote repository may be able to copy files outside of the destination directory on the… |
- risk 0.52cvss 9.1epss 0.01
Due to improper path sanitization, archives containing relative file paths can cause files to be written (or overwritten) outside of the target directory.
- risk 0.52cvss 9.1epss 0.01
Due to improper path sanitization, archives containing relative file paths can cause files to be written (or overwritten) outside of the target directory.
- risk 0.52cvss 9.1epss 0.01
Due to improper path sanitization, archives containing relative file paths can cause files to be written (or overwritten) outside of the target directory.
- risk 0.52cvss 9.1epss 0.01
Due to improper path sanitization, archives containing relative file paths can cause files to be written (or overwritten) outside of the target directory.
- risk 0.52cvss 9.1epss 0.02
A directory traversal vulnerability in the SevenZipFile.extractall() function of the python library py7zr v0.20.0 and earlier allows attackers to write arbitrary files via extracting a crafted 7z file.
- risk 0.52cvss 7.5epss 0.44
Adobe ColdFusion versions Update 14 (and earlier) and Update 4 (and earlier) are affected by an Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability that could result in information disclosure. Exploitation of this issue does not require…
- risk 0.52cvss 9.1epss 0.01
Casdoor v1.97.3 was discovered to contain an arbitrary file write vulnerability via the fullFilePath parameter at /api/upload-resource.
- risk 0.52cvss 9.1epss 0.02
Path Traversal in GitHub repository gogs/gogs prior to 0.12.9.
- risk 0.52cvss 9.1epss 0.02
django-s3file is a lightweight file upload input for Django and Amazon S3 . In versions prior to 5.5.1 it was possible to traverse the entire AWS S3 bucket and in most cases to access or delete files. If the `AWS_LOCATION` setting was set, traversal was limited to that location…
- risk 0.52cvss 8.0epss 0.03
Directory Traversal vulnerability in file cn/roothub/store/FileSystemStorageService in function store in Roothub 2.6.0 allows remote attackers with low privlege to arbitrarily upload files via /common/upload API, which could lead to remote arbitrary code execution.
- risk 0.52cvss 9.1epss 0.03
Pillow before 9.0.1 allows attackers to delete files because spaces in temporary pathnames are mishandled.
- risk 0.52cvss 8.0epss 0.01
The affected product is vulnerable to directory traversal due to mishandling of provided backup folder structure.
- risk 0.52cvss 7.8epss 0.11
mySCADA myDESIGNER 8.20.0 and below allows Directory Traversal attacks when importing project files. If an attacker can trick a victim into importing a malicious mep file, then they gain the ability to write arbitrary files to OS locations where the user has permission. This…
- risk 0.52cvss 9.1epss 0.02
The thefuck (aka The Fuck) package before 3.31 for Python allows Path Traversal that leads to arbitrary file deletion via the "undo archive operation" feature.
- risk 0.52cvss 9.1epss 0.02
An issue was discovered in Smartstore (aka SmartStoreNET) before 4.1.0. Administration/Controllers/ImportController.cs allows path traversal (for copy and delete actions) in the ImportController.Create method via a TempFileName field.
- risk 0.52cvss 7.5epss 0.37
A directory traversal vulnerability exists in Kyocera Printer d-COPIA253MF plus. Successful exploitation of this vulnerability could allow an attacker to retrieve or view arbitrary files from the affected server.
- risk 0.52cvss 7.1epss 0.72
This vulnerability allows remote attackers to delete arbitrary files on affected installations of NETGEAR ProSAFE Network Management System 1.6.0.26. Although authentication is required to exploit this vulnerability, the existing authentication mechanism can be bypassed. The…
- risk 0.52cvss 7.1epss 0.74
This vulnerability allows remote attackers to delete arbitrary files on affected installations of NETGEAR ProSAFE Network Management System 1.6.0.26. Although authentication is required to exploit this vulnerability, the existing authentication mechanism can be bypassed. The…
- risk 0.52cvss 9.1epss 0.04
Kubernetes Java client libraries in version 10.0.0 and versions prior to 9.0.1 allow writes to paths outside of the current directory when copying multiple files from a remote pod which sends a maliciously crafted archive. This can potentially overwrite any files on the system…
- risk 0.52cvss 8.0epss 0.03
A flaw was found in librepo in versions before 1.12.1. A directory traversal vulnerability was found where it failed to sanitize paths in remote repository metadata. An attacker controlling a remote repository may be able to copy files outside of the destination directory on the…