VYPR

CWE-22

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')

BaseStableLikelihood: High

Description

The product uses external input to construct a pathname that is intended to identify a file or directory that is located underneath a restricted parent directory, but the product does not properly neutralize special elements within the pathname that can cause the pathname to resolve to a location that is outside of the restricted directory.

Hierarchy (View 1000)

Parents

Children

Related attack patterns (CAPEC)

CAPEC-126 · CAPEC-64 · CAPEC-76 · CAPEC-78 · CAPEC-79

CVEs mapped to this weakness (10,395)

page 109 of 520
  • CVE-2020-13818HigJun 4, 2020
    risk 0.52cvss 7.5epss 0.37

    In Zoho ManageEngine OpManager before 125144, when is used, directory traversal validation can be bypassed.

  • CVE-2017-18586CriAug 22, 2019
    risk 0.52cvss 9.1epss 0.03

    The insert-pages plugin before 3.2.4 for WordPress has directory traversal via custom template paths.

  • CVE-2019-11826HigJun 30, 2019
    risk 0.52cvss 8.0epss 0.02

    Relative path traversal vulnerability in SYNO.PhotoTeam.Upload.Item in Synology Moments before 1.3.0-0691 allows remote authenticated users to upload arbitrary files via the name parameter.

  • CVE-2018-16221HigMay 29, 2019
    risk 0.52cvss 8.0epss 0.01

    The diagnostics web interface in the Yeahlink Ultra-elegant IP Phone SIP-T41P (firmware 66.83.0.35) does not validate (escape) the path information (path traversal), which allows an authenticated remote attacker to get access to privileged information (e.g., /etc/passwd) via…

  • CVE-2019-3799MedMay 6, 2019
    risk 0.52cvss 6.5epss 0.85

    Spring Cloud Config, versions 2.1.x prior to 2.1.2, versions 2.0.x prior to 2.0.4, and versions 1.4.x prior to 1.4.6, and older unsupported versions allow applications to serve arbitrary configuration files through the spring-cloud-config-server module. A malicious user, or…

  • CVE-2018-16858HigMar 25, 2019
    risk 0.52cvss 7.8epss 0.67

    It was found that libreoffice before versions 6.0.7 and 6.1.3 was vulnerable to a directory traversal attack which could be used to execute arbitrary macros bundled with a document. An attacker could craft a document, which when opened by LibreOffice, would execute a Python…

  • CVE-2018-7771HigJul 3, 2018
    risk 0.52cvss 8.0epss 0.01

    The vulnerability exists within processing of editscript.php in Schneider Electric U.motion Builder software versions prior to v1.3.4. A directory traversal vulnerability allows a caller with standard user privileges to write arbitrary php files anywhere in the web service…

  • CVE-2018-3758HigJun 7, 2018
    risk 0.52cvss 8.8epss 0.27

    Unrestricted file upload (RCE) in express-cart module before 1.1.7 allows a privileged user to gain access in the hosting machine.

  • CVE-2018-11494HigMay 26, 2018
    risk 0.52cvss 8.0epss 0.02

    The "program extension upload" feature in OpenCart through 3.0.2.0 has a six-step process (upload, install, unzip, move, xml, remove) that allows attackers to execute arbitrary code if the remove step is skipped, because the attacker can discover a secret temporary directory…

  • CVE-2018-9110CriMar 28, 2018
    risk 0.52cvss 9.1epss 0.03

    Studio 42 elFinder before 2.1.37 has a directory traversal vulnerability in elFinder.class.php with the zipdl() function that can allow a remote attacker to download files accessible by the web server process and delete files owned by the account running the web server process.…

  • CVE-2018-9109CriMar 28, 2018
    risk 0.52cvss 9.1epss 0.03

    Studio 42 elFinder before 2.1.36 has a directory traversal vulnerability in elFinder.class.php with the zipdl() function that can allow a remote attacker to download files accessible by the web server process and delete files owned by the account running the web server process.

  • CVE-2018-1323HigMar 12, 2018
    risk 0.52cvss 7.5epss 0.46

    The IIS/ISAPI specific code in the Apache Tomcat JK ISAPI Connector 1.2.0 to 1.2.42 that normalised the requested path before matching it to the URI-worker map did not handle some edge cases correctly. If only a sub-set of the URLs supported by Tomcat were exposed via IIS, then…

  • CVE-2017-11469HigJul 20, 2017
    risk 0.52cvss 7.5epss 0.05

    get2post.php in IDERA Uptime Monitor 7.8 has directory traversal in the file_name parameter.

  • CVE-2017-11456HigJul 19, 2017
    risk 0.52cvss 7.5epss 0.09

    Geneko GWR routers allow directory traversal sequences starting with a /../ substring, as demonstrated by unauthenticated read access to the configuration file.

  • CVE-2015-5609CriMay 23, 2017
    risk 0.52cvss 9.1epss 0.03

    Absolute path traversal vulnerability in the Image Export plugin 1.1 for WordPress allows remote attackers to read and delete arbitrary files via a full pathname in the file parameter to download.php.

  • CVE-2016-6896HigJan 18, 2017
    risk 0.52cvss 7.1epss 0.38

    Directory traversal vulnerability in the wp_ajax_update_plugin function in wp-admin/includes/ajax-actions.php in WordPress 4.5.3 allows remote authenticated users to cause a denial of service or read certain text files via a .. (dot dot) in the plugin parameter to…

  • CVE-2016-2087HigJan 18, 2017
    risk 0.52cvss 7.4epss 0.10

    Directory traversal vulnerability in the client in HexChat 2.11.0 allows remote IRC servers to read or modify arbitrary files via a .. (dot dot) in the server name.

  • CVE-2015-8798HigJun 8, 2016
    risk 0.52cvss 8.0epss 0.02

    Directory traversal vulnerability in the Management Server in Symantec Embedded Security: Critical System Protection (SES:CSP) 1.0.x before 1.0 MP5, Embedded Security: Critical System Protection for Controllers and Devices (SES:CSP) 6.5.0 before MP1, Critical System Protection…

  • CVE-2026-84568HigSep 14, 2026
    risk 0.51cvss 7.8epss 0.00

    A path traversal issue was addressed with improved path validation. This issue is fixed in macOS Golden Gate 27, macOS Sequoia 15.8, macOS Tahoe 26.7. An attacker with control of a network directory server may be able to execute arbitrary code with root privileges.

  • CVE-2026-64790HigSep 14, 2026
    risk 0.51cvss 7.8epss 0.00

    A path handling issue was addressed with improved validation. This issue is fixed in macOS Golden Gate 27, macOS Sequoia 15.8, macOS Tahoe 26.7. An app may be able to gain elevated privileges.