CWE-22
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
Description
The product uses external input to construct a pathname that is intended to identify a file or directory that is located underneath a restricted parent directory, but the product does not properly neutralize special elements within the pathname that can cause the pathname to resolve to a location that is outside of the restricted directory.
Hierarchy (View 1000)
Related attack patterns (CAPEC)
CAPEC-126 · CAPEC-64 · CAPEC-76 · CAPEC-78 · CAPEC-79
CVEs mapped to this weakness (10,395)
page 127 of 520| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2022-27615 | Hig | 0.50 | 7.7 | 0.01 | Jul 28, 2022 | Improper limitation of a pathname to a restricted directory ('Path Traversal') vulnerability in cgi component in Synology DNS Server before 2.2.2-5027 allows remote authenticated users to delete arbitrary files via unspecified vectors. | ||
| CVE-2022-1661 | Hig | 0.50 | 7.5 | 0.16 | Jun 2, 2022 | The affected products are vulnerable to directory traversal, which may allow an attacker to obtain arbitrary operating system files. | ||
| CVE-2022-31268 | Hig | 0.50 | 7.5 | 0.11 | May 21, 2022 | A Path Traversal vulnerability in Gitblit 1.9.3 can lead to reading website files via /resources//../ (e.g., followed by a WEB-INF or META-INF pathname). | ||
| CVE-2022-24878 | Hig | 0.50 | 7.7 | 0.01 | May 6, 2022 | Flux is an open and extensible continuous delivery solution for Kubernetes. Path Traversal in the kustomize-controller via a malicious `kustomization.yaml` allows an attacker to cause a Denial of Service at the controller level. Workarounds include automated tooling in the… | ||
| CVE-2021-35250 | Hig | 0.50 | 7.5 | 0.13 | Apr 25, 2022 | A researcher reported a Directory Transversal Vulnerability in Serv-U 15.3. This may allow access to files relating to the Serv-U installation and server files. This issue has been resolved in Serv-U 15.3 Hotfix 1. | ||
| CVE-2022-1392 | Hig | 0.50 | 7.5 | 0.11 | Apr 25, 2022 | The Videos sync PDF WordPress plugin through 1.7.4 does not validate the p parameter before using it in an include statement, which could lead to Local File Inclusion issues | ||
| CVE-2022-1119 | Hig | 0.50 | 7.5 | 0.20 | Apr 19, 2022 | The Simple File List WordPress plugin is vulnerable to Arbitrary File Download via the eeFile parameter found in the ~/includes/ee-downloader.php file due to missing controls which makes it possible unauthenticated attackers to supply a path to a file that will subsequently be… | ||
| CVE-2020-25150 | Hig | 0.50 | 7.6 | 0.02 | Apr 14, 2022 | A relative path traversal attack in the B. Braun Melsungen AG SpaceCom Version L81/U61 and earlier, and the Data module compactplus Versions A10 and A11 allows attackers with service user privileges to upload arbitrary files. By uploading a specially crafted tar file an attacker… | ||
| CVE-2021-44138 | Hig | 0.50 | 7.5 | 0.12 | Apr 4, 2022 | There is a Directory traversal vulnerability in Caucho Resin, as distributed in Resin 4.0.52 - 4.0.56, which allows remote attackers to read files in arbitrary directories via a ; in a pathname within an HTTP request. | ||
| CVE-2022-26233 | Hig | 0.50 | 7.5 | 0.15 | Apr 3, 2022 | Barco Control Room Management through Suite 2.9 Build 0275 was discovered to be vulnerable to directory traversal, allowing attackers to access sensitive information and components. Requests must begin with the "GET /..\.." substring. | ||
| CVE-2022-24730 | Hig | 0.50 | 7.7 | 0.01 | Mar 23, 2022 | Argo CD is a declarative, GitOps continuous delivery tool for Kubernetes. Argo CD starting with version 1.3.0 but before versions 2.1.11, 2.2.6, and 2.3.0 is vulnerable to a path traversal bug, compounded by an improper access control bug, allowing a malicious user with… | ||
| CVE-2021-27471 | Hig | 0.50 | 7.7 | 0.03 | Mar 23, 2022 | The parsing mechanism that processes certain file types does not provide input sanitization for file paths. This may allow an attacker to craft malicious files that, when opened by Rockwell Automation Connected Components Workbench v12.00.00 and prior, can traverse the file… | ||
| CVE-2022-23347 | Hig | 0.50 | 7.5 | 0.13 | Mar 21, 2022 | BigAnt Software BigAnt Server v5.6.06 was discovered to be vulnerable to directory traversal attacks. | ||
| CVE-2022-25216 | Hig | 0.50 | 7.5 | 0.13 | Mar 11, 2022 | An absolute path traversal vulnerability allows a remote attacker to download any file on the Windows file system for which the user account running DVDFab 12 Player (recently renamed PlayerFab) has read-access, by means of an HTTP GET request to… | ||
| CVE-2020-27467 | Hig | 0.50 | 7.5 | 0.16 | Feb 24, 2022 | A Directory Traversal vulnerability exits in Processwire CMS before 2.7.1 via the download parameter to index.php. | ||
| CVE-2021-43734 | Hig | 0.50 | 7.5 | 0.11 | Feb 15, 2022 | kkFileview v4.0.0 has arbitrary file read through a directory traversal vulnerability which may lead to sensitive file leak on related host. | ||
| CVE-2021-44232 | Hig | 0.50 | 7.7 | 0.01 | Dec 14, 2021 | SAF-T Framework Transaction SAFTN_G allows an attacker to exploit insufficient validation of path information provided by normal user, leading to full server directory access. The attacker can see the whole filesystem structure but cannot overwrite, delete, or corrupt arbitrary… | ||
| CVE-2021-38146 | Hig | 0.50 | 7.5 | 0.12 | Nov 22, 2021 | The File Download API in Wipro Holmes Orchestrator 20.4.1 (20.4.1_02_11_2020) allows remote attackers to read arbitrary files via absolute path traversal in the SearchString JSON field in /home/download POST data. | ||
| CVE-2021-43555 | Hig | 0.50 | 7.3 | 0.38 | Nov 19, 2021 | mySCADA myDESIGNER Versions 8.20.0 and prior fails to properly validate contents of an imported project file, which may make the product vulnerable to a path traversal payload. This vulnerability may allow an attacker to plant files on the file system in arbitrary locations or… | ||
| CVE-2021-43496 | Hig | 0.50 | 7.5 | 0.16 | Nov 12, 2021 | Clustering master branch as of commit 53e663e259bcfc8cdecb56c0bb255bd70bfcaa70 is affected by a directory traversal vulnerability. This attack can cause the disclosure of critical secrets stored anywhere on the system and can significantly aid in getting remote code access. |
- risk 0.50cvss 7.7epss 0.01
Improper limitation of a pathname to a restricted directory ('Path Traversal') vulnerability in cgi component in Synology DNS Server before 2.2.2-5027 allows remote authenticated users to delete arbitrary files via unspecified vectors.
- risk 0.50cvss 7.5epss 0.16
The affected products are vulnerable to directory traversal, which may allow an attacker to obtain arbitrary operating system files.
- risk 0.50cvss 7.5epss 0.11
A Path Traversal vulnerability in Gitblit 1.9.3 can lead to reading website files via /resources//../ (e.g., followed by a WEB-INF or META-INF pathname).
- risk 0.50cvss 7.7epss 0.01
Flux is an open and extensible continuous delivery solution for Kubernetes. Path Traversal in the kustomize-controller via a malicious `kustomization.yaml` allows an attacker to cause a Denial of Service at the controller level. Workarounds include automated tooling in the…
- risk 0.50cvss 7.5epss 0.13
A researcher reported a Directory Transversal Vulnerability in Serv-U 15.3. This may allow access to files relating to the Serv-U installation and server files. This issue has been resolved in Serv-U 15.3 Hotfix 1.
- risk 0.50cvss 7.5epss 0.11
The Videos sync PDF WordPress plugin through 1.7.4 does not validate the p parameter before using it in an include statement, which could lead to Local File Inclusion issues
- risk 0.50cvss 7.5epss 0.20
The Simple File List WordPress plugin is vulnerable to Arbitrary File Download via the eeFile parameter found in the ~/includes/ee-downloader.php file due to missing controls which makes it possible unauthenticated attackers to supply a path to a file that will subsequently be…
- risk 0.50cvss 7.6epss 0.02
A relative path traversal attack in the B. Braun Melsungen AG SpaceCom Version L81/U61 and earlier, and the Data module compactplus Versions A10 and A11 allows attackers with service user privileges to upload arbitrary files. By uploading a specially crafted tar file an attacker…
- risk 0.50cvss 7.5epss 0.12
There is a Directory traversal vulnerability in Caucho Resin, as distributed in Resin 4.0.52 - 4.0.56, which allows remote attackers to read files in arbitrary directories via a ; in a pathname within an HTTP request.
- risk 0.50cvss 7.5epss 0.15
Barco Control Room Management through Suite 2.9 Build 0275 was discovered to be vulnerable to directory traversal, allowing attackers to access sensitive information and components. Requests must begin with the "GET /..\.." substring.
- risk 0.50cvss 7.7epss 0.01
Argo CD is a declarative, GitOps continuous delivery tool for Kubernetes. Argo CD starting with version 1.3.0 but before versions 2.1.11, 2.2.6, and 2.3.0 is vulnerable to a path traversal bug, compounded by an improper access control bug, allowing a malicious user with…
- risk 0.50cvss 7.7epss 0.03
The parsing mechanism that processes certain file types does not provide input sanitization for file paths. This may allow an attacker to craft malicious files that, when opened by Rockwell Automation Connected Components Workbench v12.00.00 and prior, can traverse the file…
- risk 0.50cvss 7.5epss 0.13
BigAnt Software BigAnt Server v5.6.06 was discovered to be vulnerable to directory traversal attacks.
- risk 0.50cvss 7.5epss 0.13
An absolute path traversal vulnerability allows a remote attacker to download any file on the Windows file system for which the user account running DVDFab 12 Player (recently renamed PlayerFab) has read-access, by means of an HTTP GET request to…
- risk 0.50cvss 7.5epss 0.16
A Directory Traversal vulnerability exits in Processwire CMS before 2.7.1 via the download parameter to index.php.
- risk 0.50cvss 7.5epss 0.11
kkFileview v4.0.0 has arbitrary file read through a directory traversal vulnerability which may lead to sensitive file leak on related host.
- risk 0.50cvss 7.7epss 0.01
SAF-T Framework Transaction SAFTN_G allows an attacker to exploit insufficient validation of path information provided by normal user, leading to full server directory access. The attacker can see the whole filesystem structure but cannot overwrite, delete, or corrupt arbitrary…
- risk 0.50cvss 7.5epss 0.12
The File Download API in Wipro Holmes Orchestrator 20.4.1 (20.4.1_02_11_2020) allows remote attackers to read arbitrary files via absolute path traversal in the SearchString JSON field in /home/download POST data.
- risk 0.50cvss 7.3epss 0.38
mySCADA myDESIGNER Versions 8.20.0 and prior fails to properly validate contents of an imported project file, which may make the product vulnerable to a path traversal payload. This vulnerability may allow an attacker to plant files on the file system in arbitrary locations or…
- risk 0.50cvss 7.5epss 0.16
Clustering master branch as of commit 53e663e259bcfc8cdecb56c0bb255bd70bfcaa70 is affected by a directory traversal vulnerability. This attack can cause the disclosure of critical secrets stored anywhere on the system and can significantly aid in getting remote code access.