CWE-22
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
Description
The product uses external input to construct a pathname that is intended to identify a file or directory that is located underneath a restricted parent directory, but the product does not properly neutralize special elements within the pathname that can cause the pathname to resolve to a location that is outside of the restricted directory.
Hierarchy (View 1000)
Related attack patterns (CAPEC)
CAPEC-126 · CAPEC-64 · CAPEC-76 · CAPEC-78 · CAPEC-79
CVEs mapped to this weakness (10,395)
page 129 of 520| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2019-18665 | Hig | 0.50 | 7.5 | 0.15 | Nov 2, 2019 | The Log module in SECUDOS DOMOS before 5.6 allows local file inclusion. | ||
| CVE-2019-16279 | Hig | 0.50 | 7.5 | 0.20 | Oct 14, 2019 | A memory error in the function SSL_accept in nostromo nhttpd through 1.9.6 allows an attacker to trigger a denial of service via a crafted HTTP request. | ||
| CVE-2019-17538 | Hig | 0.50 | 7.5 | 0.11 | Oct 13, 2019 | Jiangnan Online Judge (aka jnoj) 0.8.0 has Directory Traversal for file reading via the web/polygon/problem/viewfile?id=1&name=../ substring. | ||
| CVE-2015-9480 | Hig | 0.50 | 7.5 | 0.13 | Oct 10, 2019 | The RobotCPA plugin 5 for WordPress has directory traversal via the f.php l parameter. | ||
| CVE-2019-17187 | Hig | 0.50 | 7.5 | 0.11 | Oct 8, 2019 | /var/WEB-GUI/cgi-bin/downloadfile.cgi on FiberHome HG2201T 1.00.M5007_JS_201804 devices allows pre-authentication Directory Traversal for reading arbitrary files. | ||
| CVE-2019-16123 | Hig | 0.50 | 7.5 | 0.17 | Sep 9, 2019 | In Kartatopia PilusCart 1.4.1, the parameter filename in the file catalog.php is mishandled, leading to ../ Local File Disclosure. | ||
| CVE-2016-10924 | Hig | 0.50 | 7.5 | 0.12 | Aug 22, 2019 | The ebook-download plugin before 1.2 for WordPress has directory traversal. | ||
| CVE-2018-14918 | Hig | 0.50 | 7.5 | 0.19 | Jun 28, 2019 | LOYTEC LGATE-902 6.3.2 devices allow Directory Traversal. | ||
| CVE-2019-7315 | Hig | 0.50 | 7.5 | 0.11 | Jun 17, 2019 | Genie Access WIP3BVAF WISH IP 3MP IR Auto Focus Bullet Camera devices through 3.x are vulnerable to directory traversal via the web interface, as demonstrated by reading /etc/shadow. NOTE: this product is discontinued, and its final firmware version has this vulnerability (4.x… | ||
| CVE-2019-1717 | Hig | 0.50 | 7.5 | 0.10 | May 15, 2019 | A vulnerability in the web-based management interface of Cisco Video Surveillance Manager could allow an unauthenticated, remote attacker to access sensitive information. The vulnerability is due to improper validation of parameters handled by the web-based management interface.… | ||
| CVE-2019-9726 | Hig | 0.50 | 7.5 | 0.16 | May 13, 2019 | Directory Traversal / Arbitrary File Read in eQ-3 AG Homematic CCU3 3.43.15 and earlier allows remote attackers to read arbitrary files of the device's filesystem. This vulnerability can be exploited by unauthenticated attackers with access to the web interface. | ||
| CVE-2018-1618 | Hig | 0.50 | 7.7 | 0.03 | Apr 2, 2019 | IBM Security Privileged Identity Manager Virtual Appliance 2.2.1 could allow a remote attacker to traverse directories on the system. An attacker could send a specially-crafted URL request containing "dot dot" sequences (/../) to view arbitrary files on the system. IBM X-Force… | ||
| CVE-2019-9922 | Hig | 0.50 | 7.5 | 0.11 | Mar 29, 2019 | An issue was discovered in the Harmis JE Messenger component 1.2.2 for Joomla!. Directory Traversal allows read access to arbitrary files. | ||
| CVE-2019-3816 | Hig | 0.50 | 7.5 | 0.15 | Mar 14, 2019 | Openwsman, versions up to and including 2.6.9, are vulnerable to arbitrary file disclosure because the working directory of openwsmand daemon was set to root directory. A remote, unauthenticated attacker can exploit this vulnerability by sending a specially crafted HTTP request… | ||
| CVE-2018-15782 | Hig | 0.50 | 7.7 | 0.00 | Jan 16, 2019 | The Quick Setup component of RSA Authentication Manager versions prior to 8.4 is vulnerable to a relative path traversal vulnerability. A local attacker could potentially provide an administrator with a crafted license that if used during the quick setup deployment of the… | ||
| CVE-2018-20463 | Hig | 0.50 | 7.5 | 0.13 | Dec 25, 2018 | An issue was discovered in the JSmol2WP plugin 1.07 for WordPress. There is an arbitrary file read vulnerability via ../ directory traversal in query=php://filter/resource= in the jsmol.php query string. This can also be used for SSRF. | ||
| CVE-2018-19753 | Hig | 0.50 | 7.5 | 0.17 | Dec 5, 2018 | Tarantella Enterprise before 3.11 allows Directory Traversal. | ||
| CVE-2018-19326 | Hig | 0.50 | 7.5 | 0.10 | Nov 17, 2018 | Zyxel VMG1312-B10D devices before 5.13(AAXA.8)C0 allow ../ Directory Traversal, as demonstrated by reading /etc/passwd. | ||
| CVE-2018-1744 | Hig | 0.50 | 7.7 | 0.03 | Oct 15, 2018 | IBM Security Key Lifecycle Manager 2.5, 2.6, 2.7, and 3.0 could allow a remote attacker to traverse directories on the system. An attacker could send a specially-crafted URL request containing "dot dot" sequences (/../) to view arbitrary files on the system. IBM X-Force ID:… | ||
| CVE-2018-1649 | Hig | 0.50 | 7.7 | 0.03 | Oct 5, 2018 | IBM QRadar Incident Forensics 7.2 and 7.3 could allow a remote attacker to traverse directories on the system. An attacker could send a specially-crafted URL request containing "dot dot" sequences (/../) to view arbitrary files on the system. IBM X-Force ID: 144655. |
- risk 0.50cvss 7.5epss 0.15
The Log module in SECUDOS DOMOS before 5.6 allows local file inclusion.
- risk 0.50cvss 7.5epss 0.20
A memory error in the function SSL_accept in nostromo nhttpd through 1.9.6 allows an attacker to trigger a denial of service via a crafted HTTP request.
- risk 0.50cvss 7.5epss 0.11
Jiangnan Online Judge (aka jnoj) 0.8.0 has Directory Traversal for file reading via the web/polygon/problem/viewfile?id=1&name=../ substring.
- risk 0.50cvss 7.5epss 0.13
The RobotCPA plugin 5 for WordPress has directory traversal via the f.php l parameter.
- risk 0.50cvss 7.5epss 0.11
/var/WEB-GUI/cgi-bin/downloadfile.cgi on FiberHome HG2201T 1.00.M5007_JS_201804 devices allows pre-authentication Directory Traversal for reading arbitrary files.
- risk 0.50cvss 7.5epss 0.17
In Kartatopia PilusCart 1.4.1, the parameter filename in the file catalog.php is mishandled, leading to ../ Local File Disclosure.
- risk 0.50cvss 7.5epss 0.12
The ebook-download plugin before 1.2 for WordPress has directory traversal.
- risk 0.50cvss 7.5epss 0.19
LOYTEC LGATE-902 6.3.2 devices allow Directory Traversal.
- risk 0.50cvss 7.5epss 0.11
Genie Access WIP3BVAF WISH IP 3MP IR Auto Focus Bullet Camera devices through 3.x are vulnerable to directory traversal via the web interface, as demonstrated by reading /etc/shadow. NOTE: this product is discontinued, and its final firmware version has this vulnerability (4.x…
- risk 0.50cvss 7.5epss 0.10
A vulnerability in the web-based management interface of Cisco Video Surveillance Manager could allow an unauthenticated, remote attacker to access sensitive information. The vulnerability is due to improper validation of parameters handled by the web-based management interface.…
- risk 0.50cvss 7.5epss 0.16
Directory Traversal / Arbitrary File Read in eQ-3 AG Homematic CCU3 3.43.15 and earlier allows remote attackers to read arbitrary files of the device's filesystem. This vulnerability can be exploited by unauthenticated attackers with access to the web interface.
- risk 0.50cvss 7.7epss 0.03
IBM Security Privileged Identity Manager Virtual Appliance 2.2.1 could allow a remote attacker to traverse directories on the system. An attacker could send a specially-crafted URL request containing "dot dot" sequences (/../) to view arbitrary files on the system. IBM X-Force…
- risk 0.50cvss 7.5epss 0.11
An issue was discovered in the Harmis JE Messenger component 1.2.2 for Joomla!. Directory Traversal allows read access to arbitrary files.
- risk 0.50cvss 7.5epss 0.15
Openwsman, versions up to and including 2.6.9, are vulnerable to arbitrary file disclosure because the working directory of openwsmand daemon was set to root directory. A remote, unauthenticated attacker can exploit this vulnerability by sending a specially crafted HTTP request…
- risk 0.50cvss 7.7epss 0.00
The Quick Setup component of RSA Authentication Manager versions prior to 8.4 is vulnerable to a relative path traversal vulnerability. A local attacker could potentially provide an administrator with a crafted license that if used during the quick setup deployment of the…
- risk 0.50cvss 7.5epss 0.13
An issue was discovered in the JSmol2WP plugin 1.07 for WordPress. There is an arbitrary file read vulnerability via ../ directory traversal in query=php://filter/resource= in the jsmol.php query string. This can also be used for SSRF.
- risk 0.50cvss 7.5epss 0.17
Tarantella Enterprise before 3.11 allows Directory Traversal.
- risk 0.50cvss 7.5epss 0.10
Zyxel VMG1312-B10D devices before 5.13(AAXA.8)C0 allow ../ Directory Traversal, as demonstrated by reading /etc/passwd.
- risk 0.50cvss 7.7epss 0.03
IBM Security Key Lifecycle Manager 2.5, 2.6, 2.7, and 3.0 could allow a remote attacker to traverse directories on the system. An attacker could send a specially-crafted URL request containing "dot dot" sequences (/../) to view arbitrary files on the system. IBM X-Force ID:…
- risk 0.50cvss 7.7epss 0.03
IBM QRadar Incident Forensics 7.2 and 7.3 could allow a remote attacker to traverse directories on the system. An attacker could send a specially-crafted URL request containing "dot dot" sequences (/../) to view arbitrary files on the system. IBM X-Force ID: 144655.