CWE-22
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
Description
The product uses external input to construct a pathname that is intended to identify a file or directory that is located underneath a restricted parent directory, but the product does not properly neutralize special elements within the pathname that can cause the pathname to resolve to a location that is outside of the restricted directory.
Hierarchy (View 1000)
Related attack patterns (CAPEC)
CAPEC-126 · CAPEC-64 · CAPEC-76 · CAPEC-78 · CAPEC-79
CVEs mapped to this weakness (10,395)
page 148 of 520| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2024-47559 | Hig | 0.49 | 7.6 | 0.01 | Oct 7, 2024 | Authenticated RCE via Path Traversal | ||
| CVE-2024-47558 | Hig | 0.49 | 7.6 | 0.01 | Oct 7, 2024 | Authenticated RCE via Path Traversal | ||
| CVE-2024-44034 | Hig | 0.49 | 7.5 | 0.01 | Oct 5, 2024 | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Martin Greenwood WPSPX wpspx allows PHP Local File Inclusion.This issue affects WPSPX: from n/a through <= 1.0.2. | ||
| CVE-2024-44018 | Hig | 0.49 | 7.5 | 0.01 | Oct 5, 2024 | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in istmoplugins Instant Chat Floating Button for WordPress Websites instant-chat-wp allows PHP Local File Inclusion.This issue affects Instant Chat Floating Button for WordPress… | ||
| CVE-2024-44016 | Hig | 0.49 | 7.5 | 0.01 | Oct 5, 2024 | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in amarksteadman Podiant podiant allows PHP Local File Inclusion.This issue affects Podiant: from n/a through <= 1.1. | ||
| CVE-2024-44015 | Hig | 0.49 | 7.5 | 0.01 | Oct 5, 2024 | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in istmoplugins Users Control users-control allows PHP Local File Inclusion.This issue affects Users Control: from n/a through <= 1.0.16. | ||
| CVE-2024-44013 | Hig | 0.49 | 7.5 | 0.01 | Oct 5, 2024 | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Innate Images LLC VR Calendar vr-calendar-sync allows PHP Local File Inclusion.This issue affects VR Calendar: from n/a through <= 2.4.0. | ||
| CVE-2024-44012 | Hig | 0.49 | 7.5 | 0.01 | Oct 5, 2024 | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in wpdev33 WP Newsletter Subscription wp-newsletter-subscription allows PHP Local File Inclusion.This issue affects WP Newsletter Subscription: from n/a through <= 1.1. | ||
| CVE-2024-44011 | Hig | 0.49 | 7.5 | 0.01 | Oct 5, 2024 | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in ExpressTech Systems WP Ticket Ultra Help Desk & Support Plugin wp-ticket-ultra allows PHP Local File Inclusion.This issue affects WP Ticket Ultra Help Desk & Support Plugin: from n/a… | ||
| CVE-2024-41922 | Hig | 0.49 | 7.5 | 0.08 | Oct 3, 2024 | A directory traversal vulnerability exists in the log files download functionality of Veertu Anka Build 1.42.0. A specially crafted HTTP request can lead to a disclosure of sensitive information. An attacker can make an unauthenticated HTTP request to trigger this vulnerability. | ||
| CVE-2024-8352 | Hig | 0.49 | 7.5 | 0.01 | Oct 3, 2024 | The Social Web Suite – Social Media Auto Post, Social Media Auto Publish plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 4.1.11 via the download_log function. This makes it possible for unauthenticated attackers to read the… | ||
| CVE-2024-44017 | Hig | 0.49 | 7.5 | 0.01 | Oct 2, 2024 | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in MinHyeong Lim MH Board mh-board allows PHP Local File Inclusion.This issue affects MH Board: from n/a through <= 1.3.2.1. | ||
| CVE-2024-9301 | Hig | 0.49 | 7.5 | 0.01 | Sep 27, 2024 | A path traversal issue in E2Nest prior to commit 8a41948e553c89c56b14410c6ed395e9cfb9250a | ||
| CVE-2024-44825 | Hig | 0.49 | 7.5 | 0.01 | Sep 25, 2024 | Directory Traversal vulnerability in Centro de Tecnologia da Informaco Renato Archer InVesalius3 v3.1.99995 allows attackers to write arbitrary files unto the system via a crafted .inv3 file. | ||
| CVE-2024-8941 | Hig | 0.49 | 7.5 | 0.01 | Sep 25, 2024 | Path traversal vulnerability in Scriptcase version 9.4.019, in /scriptcase/devel/compat/nm_edit_php_edit.php (in the “subpage” parameter), which allows unauthenticated remote users to bypass SecurityManager's intended restrictions and list and/or read a parent directory via… | ||
| CVE-2024-46649 | Hig | 0.49 | 7.5 | 0.01 | Sep 20, 2024 | eNMS up to 4.7.1 is vulnerable to Directory Traversal via download/folder. | ||
| CVE-2024-46648 | Hig | 0.49 | 7.5 | 0.01 | Sep 20, 2024 | eNMS 4.4.0 to 4.7.1 is vulnerable to Directory Traversal via scan_folder. | ||
| CVE-2024-46645 | Hig | 0.49 | 7.5 | 0.01 | Sep 20, 2024 | eNMS 4.0.0 is vulnerable to Directory Traversal via get_tree_files. | ||
| CVE-2024-7609 | Hig | 0.49 | 7.5 | 0.01 | Sep 11, 2024 | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Vidco Software VOC TESTER allows Path Traversal. This issue affects VOC TESTER: before 12.34.8. | ||
| CVE-2024-44867 | Hig | 0.49 | 7.5 | 0.01 | Sep 10, 2024 | phpok v3.0 was discovered to contain an arbitrary file read vulnerability via the component /autoload/file.php. |
- risk 0.49cvss 7.6epss 0.01
Authenticated RCE via Path Traversal
- risk 0.49cvss 7.6epss 0.01
Authenticated RCE via Path Traversal
- risk 0.49cvss 7.5epss 0.01
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Martin Greenwood WPSPX wpspx allows PHP Local File Inclusion.This issue affects WPSPX: from n/a through <= 1.0.2.
- risk 0.49cvss 7.5epss 0.01
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in istmoplugins Instant Chat Floating Button for WordPress Websites instant-chat-wp allows PHP Local File Inclusion.This issue affects Instant Chat Floating Button for WordPress…
- risk 0.49cvss 7.5epss 0.01
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in amarksteadman Podiant podiant allows PHP Local File Inclusion.This issue affects Podiant: from n/a through <= 1.1.
- risk 0.49cvss 7.5epss 0.01
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in istmoplugins Users Control users-control allows PHP Local File Inclusion.This issue affects Users Control: from n/a through <= 1.0.16.
- risk 0.49cvss 7.5epss 0.01
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Innate Images LLC VR Calendar vr-calendar-sync allows PHP Local File Inclusion.This issue affects VR Calendar: from n/a through <= 2.4.0.
- risk 0.49cvss 7.5epss 0.01
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in wpdev33 WP Newsletter Subscription wp-newsletter-subscription allows PHP Local File Inclusion.This issue affects WP Newsletter Subscription: from n/a through <= 1.1.
- risk 0.49cvss 7.5epss 0.01
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in ExpressTech Systems WP Ticket Ultra Help Desk & Support Plugin wp-ticket-ultra allows PHP Local File Inclusion.This issue affects WP Ticket Ultra Help Desk & Support Plugin: from n/a…
- risk 0.49cvss 7.5epss 0.08
A directory traversal vulnerability exists in the log files download functionality of Veertu Anka Build 1.42.0. A specially crafted HTTP request can lead to a disclosure of sensitive information. An attacker can make an unauthenticated HTTP request to trigger this vulnerability.
- risk 0.49cvss 7.5epss 0.01
The Social Web Suite – Social Media Auto Post, Social Media Auto Publish plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 4.1.11 via the download_log function. This makes it possible for unauthenticated attackers to read the…
- risk 0.49cvss 7.5epss 0.01
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in MinHyeong Lim MH Board mh-board allows PHP Local File Inclusion.This issue affects MH Board: from n/a through <= 1.3.2.1.
- risk 0.49cvss 7.5epss 0.01
A path traversal issue in E2Nest prior to commit 8a41948e553c89c56b14410c6ed395e9cfb9250a
- risk 0.49cvss 7.5epss 0.01
Directory Traversal vulnerability in Centro de Tecnologia da Informaco Renato Archer InVesalius3 v3.1.99995 allows attackers to write arbitrary files unto the system via a crafted .inv3 file.
- risk 0.49cvss 7.5epss 0.01
Path traversal vulnerability in Scriptcase version 9.4.019, in /scriptcase/devel/compat/nm_edit_php_edit.php (in the “subpage” parameter), which allows unauthenticated remote users to bypass SecurityManager's intended restrictions and list and/or read a parent directory via…
- risk 0.49cvss 7.5epss 0.01
eNMS up to 4.7.1 is vulnerable to Directory Traversal via download/folder.
- risk 0.49cvss 7.5epss 0.01
eNMS 4.4.0 to 4.7.1 is vulnerable to Directory Traversal via scan_folder.
- risk 0.49cvss 7.5epss 0.01
eNMS 4.0.0 is vulnerable to Directory Traversal via get_tree_files.
- risk 0.49cvss 7.5epss 0.01
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Vidco Software VOC TESTER allows Path Traversal. This issue affects VOC TESTER: before 12.34.8.
- risk 0.49cvss 7.5epss 0.01
phpok v3.0 was discovered to contain an arbitrary file read vulnerability via the component /autoload/file.php.