CWE-22
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
Description
The product uses external input to construct a pathname that is intended to identify a file or directory that is located underneath a restricted parent directory, but the product does not properly neutralize special elements within the pathname that can cause the pathname to resolve to a location that is outside of the restricted directory.
Hierarchy (View 1000)
Related attack patterns (CAPEC)
CAPEC-126 · CAPEC-64 · CAPEC-76 · CAPEC-78 · CAPEC-79
CVEs mapped to this weakness (10,395)
page 157 of 520| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2023-33510 | Hig | 0.49 | 7.5 | 0.04 | Jun 7, 2023 | Jeecg P3 Biz Chat 1.0.5 allows remote attackers to read arbitrary files through specific parameters. | ||
| CVE-2023-34407 | Hig | 0.49 | 7.5 | 0.01 | Jun 5, 2023 | OfflinePlayerService.exe in Harbinger Offline Player 4.0.6.0.2 allows directory traversal as LocalSystem via ..\ in a URL. | ||
| CVE-2023-27640 | Hig | 0.49 | 7.5 | 0.04 | Jun 1, 2023 | An issue was discovered in the tshirtecommerce (aka Custom Product Designer) component 2.1.4 for PrestaShop. An HTTP request can be forged with the POST parameter type in the /tshirtecommerce/fonts.php endpoint, to allow a remote attacker to traverse directories on the system in… | ||
| CVE-2023-27639 | Hig | 0.49 | 7.5 | 0.04 | Jun 1, 2023 | An issue was discovered in the tshirtecommerce (aka Custom Product Designer) component 2.1.4 for PrestaShop. An HTTP request can be forged with the POST parameter file_name in the tshirtecommerce/ajax.php?type=svg endpoint, to allow a remote attacker to traverse directories on… | ||
| CVE-2023-30197 | Hig | 0.49 | 7.5 | 0.01 | May 31, 2023 | Incorrect Access Control in the module "My inventory" (myinventory) <= 1.6.6 from Webbax for PrestaShop, allows a guest to download personal information without restriction by performing a path traversal attack. | ||
| CVE-2023-30196 | Hig | 0.49 | 7.5 | 0.01 | May 30, 2023 | Prestashop salesbooster <= 1.10.4 is vulnerable to Incorrect Access Control via modules/salesbooster/downloads/download.php. | ||
| CVE-2023-29380 | Hig | 0.49 | 7.5 | 0.02 | May 29, 2023 | Warpinator before 1.6.0 allows remote file deletion via directory traversal in top_dir_basenames. | ||
| CVE-2023-31861 | Hig | 0.49 | 7.5 | 0.01 | May 25, 2023 | ZLMediaKit 4.0 is vulnerable to Directory Traversal. | ||
| CVE-2023-27067 | Hig | 0.49 | 7.5 | 0.02 | May 22, 2023 | Directory Traversal vulnerability in Sitecore Experience Platform through 10.2 allows remote attackers to download arbitrary files via crafted command to download.aspx | ||
| CVE-2023-30199 | Hig | 0.49 | 7.5 | 0.01 | May 19, 2023 | Prestashop customexporter <= 1.7.20 is vulnerable to Incorrect Access Control via modules/customexporter/downloads/download.php. | ||
| CVE-2023-32767 | Hig | 0.49 | 7.5 | 0.01 | May 17, 2023 | The web interface of Symcon IP-Symcon before 6.3 (i.e., before 2023-05-12) allows a remote attacker to read sensitive files via .. directory-traversal sequences in the URL. | ||
| CVE-2023-31904 | Hig | 0.49 | 7.5 | 0.01 | May 17, 2023 | savysoda Wifi HD Wireless Disk Drive 11 is vulnerable to Local File Inclusion. | ||
| CVE-2023-31477 | Hig | 0.49 | 7.5 | 0.01 | May 11, 2023 | A path traversal issue was discovered on GL.iNet devices before 3.216. Through the file sharing feature, it is possible to share an arbitrary directory, such as /tmp or /etc, because there is no server-side restriction to limit sharing to the USB path. | ||
| CVE-2023-26126 | Hig | 0.49 | 7.5 | 0.01 | May 10, 2023 | All versions of the package m.static are vulnerable to Directory Traversal due to improper input sanitization of the path being requested via the requestFile function. | ||
| CVE-2023-31181 | Hig | 0.49 | 7.5 | 0.01 | May 8, 2023 | WJJ Software - InnoKB Server, InnoKB/Console 2.2.1 - CWE-22: Path Traversal | ||
| CVE-2017-20184 | Hig | 0.49 | 7.5 | 0.03 | May 4, 2023 | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Carlo Gavazzi Powersoft up to version 2.1.1.1 allows an unauthenticated, remote attacker to download any file from the affected device. | ||
| CVE-2022-48483 | — | Hig | 0.49 | 7.5 | 0.02 | May 2, 2023 | 3CX before 18 Hotfix 1 build 18.0.3.461 on Windows allows unauthenticated remote attackers to read %WINDIR%\system32 files via /Electron/download directory traversal in conjunction with a path component that has a drive letter and uses backslash characters. NOTE: this issue… | |
| CVE-2022-48482 | — | Hig | 0.49 | 7.5 | 0.02 | May 2, 2023 | 3CX before 18 Update 2 Security Hotfix build 18.0.2.315 on Windows allows unauthenticated remote attackers to read certain files via /Electron/download directory traversal. Files may have credentials, full backups, call recordings, and chat logs. | |
| CVE-2023-31483 | Hig | 0.49 | 7.5 | 0.01 | Apr 28, 2023 | tar/TarFileReader.cpp in Cauldron cbang before bastet-v8.1.17 has a directory traversal during extraction that allows the attacker to create or write to files outside the current directory via a crafted tar archive. | ||
| CVE-2023-30380 | Hig | 0.49 | 7.5 | 0.01 | Apr 27, 2023 | An issue in the component /dialog/select_media.php of DedeCMS v5.7.107 allows attackers to execute a directory traversal. |
- risk 0.49cvss 7.5epss 0.04
Jeecg P3 Biz Chat 1.0.5 allows remote attackers to read arbitrary files through specific parameters.
- risk 0.49cvss 7.5epss 0.01
OfflinePlayerService.exe in Harbinger Offline Player 4.0.6.0.2 allows directory traversal as LocalSystem via ..\ in a URL.
- risk 0.49cvss 7.5epss 0.04
An issue was discovered in the tshirtecommerce (aka Custom Product Designer) component 2.1.4 for PrestaShop. An HTTP request can be forged with the POST parameter type in the /tshirtecommerce/fonts.php endpoint, to allow a remote attacker to traverse directories on the system in…
- risk 0.49cvss 7.5epss 0.04
An issue was discovered in the tshirtecommerce (aka Custom Product Designer) component 2.1.4 for PrestaShop. An HTTP request can be forged with the POST parameter file_name in the tshirtecommerce/ajax.php?type=svg endpoint, to allow a remote attacker to traverse directories on…
- risk 0.49cvss 7.5epss 0.01
Incorrect Access Control in the module "My inventory" (myinventory) <= 1.6.6 from Webbax for PrestaShop, allows a guest to download personal information without restriction by performing a path traversal attack.
- risk 0.49cvss 7.5epss 0.01
Prestashop salesbooster <= 1.10.4 is vulnerable to Incorrect Access Control via modules/salesbooster/downloads/download.php.
- risk 0.49cvss 7.5epss 0.02
Warpinator before 1.6.0 allows remote file deletion via directory traversal in top_dir_basenames.
- risk 0.49cvss 7.5epss 0.01
ZLMediaKit 4.0 is vulnerable to Directory Traversal.
- risk 0.49cvss 7.5epss 0.02
Directory Traversal vulnerability in Sitecore Experience Platform through 10.2 allows remote attackers to download arbitrary files via crafted command to download.aspx
- risk 0.49cvss 7.5epss 0.01
Prestashop customexporter <= 1.7.20 is vulnerable to Incorrect Access Control via modules/customexporter/downloads/download.php.
- risk 0.49cvss 7.5epss 0.01
The web interface of Symcon IP-Symcon before 6.3 (i.e., before 2023-05-12) allows a remote attacker to read sensitive files via .. directory-traversal sequences in the URL.
- risk 0.49cvss 7.5epss 0.01
savysoda Wifi HD Wireless Disk Drive 11 is vulnerable to Local File Inclusion.
- risk 0.49cvss 7.5epss 0.01
A path traversal issue was discovered on GL.iNet devices before 3.216. Through the file sharing feature, it is possible to share an arbitrary directory, such as /tmp or /etc, because there is no server-side restriction to limit sharing to the USB path.
- risk 0.49cvss 7.5epss 0.01
All versions of the package m.static are vulnerable to Directory Traversal due to improper input sanitization of the path being requested via the requestFile function.
- risk 0.49cvss 7.5epss 0.01
WJJ Software - InnoKB Server, InnoKB/Console 2.2.1 - CWE-22: Path Traversal
- risk 0.49cvss 7.5epss 0.03
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Carlo Gavazzi Powersoft up to version 2.1.1.1 allows an unauthenticated, remote attacker to download any file from the affected device.
- risk 0.49cvss 7.5epss 0.02
3CX before 18 Hotfix 1 build 18.0.3.461 on Windows allows unauthenticated remote attackers to read %WINDIR%\system32 files via /Electron/download directory traversal in conjunction with a path component that has a drive letter and uses backslash characters. NOTE: this issue…
- risk 0.49cvss 7.5epss 0.02
3CX before 18 Update 2 Security Hotfix build 18.0.2.315 on Windows allows unauthenticated remote attackers to read certain files via /Electron/download directory traversal. Files may have credentials, full backups, call recordings, and chat logs.
- risk 0.49cvss 7.5epss 0.01
tar/TarFileReader.cpp in Cauldron cbang before bastet-v8.1.17 has a directory traversal during extraction that allows the attacker to create or write to files outside the current directory via a crafted tar archive.
- risk 0.49cvss 7.5epss 0.01
An issue in the component /dialog/select_media.php of DedeCMS v5.7.107 allows attackers to execute a directory traversal.