CWE-22
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
Description
The product uses external input to construct a pathname that is intended to identify a file or directory that is located underneath a restricted parent directory, but the product does not properly neutralize special elements within the pathname that can cause the pathname to resolve to a location that is outside of the restricted directory.
Hierarchy (View 1000)
Related attack patterns (CAPEC)
CAPEC-126 · CAPEC-64 · CAPEC-76 · CAPEC-78 · CAPEC-79
CVEs mapped to this weakness (10,395)
page 158 of 520| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2022-48476 | Hig | 0.49 | 7.5 | 0.01 | Apr 24, 2023 | In JetBrains Ktor before 2.3.0 path traversal in the `resolveResource` method was possible | ||
| CVE-2023-31059 | Hig | 0.49 | 7.5 | 0.06 | Apr 24, 2023 | Repetier Server through 1.4.10 allows ..%5c directory traversal for reading files that contain credentials, as demonstrated by connectionLost.php. | ||
| CVE-2023-26101 | Hig | 0.49 | 7.5 | 0.01 | Apr 21, 2023 | In Progress Flowmon Packet Investigator before 12.1.0, a Flowmon user with access to Flowmon Packet Investigator could leverage a path-traversal vulnerability to retrieve files on the Flowmon appliance's local filesystem. | ||
| CVE-2023-29887 | Hig | 0.49 | 7.5 | 0.05 | Apr 18, 2023 | A Local File inclusion vulnerability in test.php in spreadsheet-reader 0.5.11 allows remote attackers to include arbitrary files via the File parameter. | ||
| CVE-2022-34126 | Hig | 0.49 | 7.5 | 0.01 | Apr 16, 2023 | The Activity plugin before 3.1.1 for GLPI allows reading local files via directory traversal in the front/cra.send.php file parameter. | ||
| CVE-2023-26969 | Hig | 0.49 | 7.5 | 0.01 | Apr 14, 2023 | Atropim 1.5.26 is vulnerable to Directory Traversal. | ||
| CVE-2023-26820 | Hig | 0.49 | 7.5 | 0.01 | Apr 7, 2023 | siteproxy v1.0 was discovered to contain a path traversal vulnerability via the component index.js. | ||
| CVE-2023-1142 | Hig | 0.49 | 7.5 | 0.01 | Mar 27, 2023 | In Delta Electronics InfraSuite Device Master versions prior to 1.0.5, an attacker could use URL decoding to retrieve system files, credentials, and bypass authentication resulting in privilege escalation. | ||
| CVE-2023-27055 | Hig | 0.49 | 7.5 | 0.01 | Mar 24, 2023 | Aver Information Inc PTZApp2 v20.01044.48 allows attackers to access sensitive files via a crafted GET request. | ||
| CVE-2023-25345 | Hig | 0.49 | 7.5 | 0.01 | Mar 15, 2023 | Directory traversal vulnerability in swig-templates thru 2.0.4 and swig thru 1.4.2, allows attackers to read arbitrary files via the include or extends tags. | ||
| CVE-2023-25804 | Hig | 0.49 | 7.5 | 0.01 | Mar 15, 2023 | Roxy-WI is a Web interface for managing Haproxy, Nginx, Apache, and Keepalived servers. Versions prior to 6.3.5.0 have a limited path traversal vulnerability. An SSH key can be saved into an unintended location, for example the `/tmp` folder using a payload… | ||
| CVE-2023-25803 | Hig | 0.49 | 7.5 | 0.01 | Mar 13, 2023 | Roxy-WI is a Web interface for managing Haproxy, Nginx, Apache, and Keepalived servers. Versions prior to 6.3.5.0 have a directory traversal vulnerability that allows the inclusion of server-side files. This issue is fixed in version 6.3.5.0. | ||
| CVE-2023-26111 | Hig | 0.49 | 7.5 | 0.01 | Mar 6, 2023 | All versions of the package @nubosoftware/node-static; all versions of the package node-static are vulnerable to Directory Traversal due to improper file path sanitization in the startsWith() method in the servePath function. | ||
| CVE-2022-41722 | Hig | 0.49 | 7.5 | 0.02 | Feb 28, 2023 | A path traversal vulnerability exists in filepath.Clean on Windows. On Windows, the filepath.Clean function could transform an invalid path such as "a/../c:/b" into the valid path "c:\b". This transformation of a relative (if invalid) path into an absolute path could enable a… | ||
| CVE-2023-25265 | Hig | 0.49 | 7.5 | 0.01 | Feb 28, 2023 | Docmosis Tornado <= 2.9.4 is vulnerable to Directory Traversal leading to the disclosure of arbitrary content on the file system. | ||
| CVE-2023-26758 | Hig | 0.49 | 7.5 | 0.01 | Feb 27, 2023 | Sme.UP TOKYO V6R1M220406 was discovered to contain an arbitrary file download vulnerabilty via the component /ResourceService. | ||
| CVE-2023-23063 | Hig | 0.49 | 7.5 | 0.02 | Feb 22, 2023 | Cellinx NVT v1.0.6.002b was discovered to contain a local file disclosure vulnerability via the component /cgi-bin/GetFileContent.cgi. | ||
| CVE-2023-24960 | Hig | 0.49 | 7.5 | 0.01 | Feb 17, 2023 | IBM InfoSphere Information Server 11.7 could allow a remote attacker to traverse directories on the system. An attacker could send a specially crafted URL request containing "dot dot" sequences (/../) to view arbitrary files on the system. IBM X-Force ID: 246333 | ||
| CVE-2022-47762 | Hig | 0.49 | 7.5 | 0.01 | Feb 3, 2023 | In gin-vue-admin < 2.5.5, the download module has a Path Traversal vulnerability. | ||
| CVE-2022-47768 | Hig | 0.49 | 7.5 | 0.01 | Feb 1, 2023 | Serenissima Informatica Fast Checkin 1.0 is vulnerable to Directory Traversal. |
- risk 0.49cvss 7.5epss 0.01
In JetBrains Ktor before 2.3.0 path traversal in the `resolveResource` method was possible
- risk 0.49cvss 7.5epss 0.06
Repetier Server through 1.4.10 allows ..%5c directory traversal for reading files that contain credentials, as demonstrated by connectionLost.php.
- risk 0.49cvss 7.5epss 0.01
In Progress Flowmon Packet Investigator before 12.1.0, a Flowmon user with access to Flowmon Packet Investigator could leverage a path-traversal vulnerability to retrieve files on the Flowmon appliance's local filesystem.
- risk 0.49cvss 7.5epss 0.05
A Local File inclusion vulnerability in test.php in spreadsheet-reader 0.5.11 allows remote attackers to include arbitrary files via the File parameter.
- risk 0.49cvss 7.5epss 0.01
The Activity plugin before 3.1.1 for GLPI allows reading local files via directory traversal in the front/cra.send.php file parameter.
- risk 0.49cvss 7.5epss 0.01
Atropim 1.5.26 is vulnerable to Directory Traversal.
- risk 0.49cvss 7.5epss 0.01
siteproxy v1.0 was discovered to contain a path traversal vulnerability via the component index.js.
- risk 0.49cvss 7.5epss 0.01
In Delta Electronics InfraSuite Device Master versions prior to 1.0.5, an attacker could use URL decoding to retrieve system files, credentials, and bypass authentication resulting in privilege escalation.
- risk 0.49cvss 7.5epss 0.01
Aver Information Inc PTZApp2 v20.01044.48 allows attackers to access sensitive files via a crafted GET request.
- risk 0.49cvss 7.5epss 0.01
Directory traversal vulnerability in swig-templates thru 2.0.4 and swig thru 1.4.2, allows attackers to read arbitrary files via the include or extends tags.
- risk 0.49cvss 7.5epss 0.01
Roxy-WI is a Web interface for managing Haproxy, Nginx, Apache, and Keepalived servers. Versions prior to 6.3.5.0 have a limited path traversal vulnerability. An SSH key can be saved into an unintended location, for example the `/tmp` folder using a payload…
- risk 0.49cvss 7.5epss 0.01
Roxy-WI is a Web interface for managing Haproxy, Nginx, Apache, and Keepalived servers. Versions prior to 6.3.5.0 have a directory traversal vulnerability that allows the inclusion of server-side files. This issue is fixed in version 6.3.5.0.
- risk 0.49cvss 7.5epss 0.01
All versions of the package @nubosoftware/node-static; all versions of the package node-static are vulnerable to Directory Traversal due to improper file path sanitization in the startsWith() method in the servePath function.
- risk 0.49cvss 7.5epss 0.02
A path traversal vulnerability exists in filepath.Clean on Windows. On Windows, the filepath.Clean function could transform an invalid path such as "a/../c:/b" into the valid path "c:\b". This transformation of a relative (if invalid) path into an absolute path could enable a…
- risk 0.49cvss 7.5epss 0.01
Docmosis Tornado <= 2.9.4 is vulnerable to Directory Traversal leading to the disclosure of arbitrary content on the file system.
- risk 0.49cvss 7.5epss 0.01
Sme.UP TOKYO V6R1M220406 was discovered to contain an arbitrary file download vulnerabilty via the component /ResourceService.
- risk 0.49cvss 7.5epss 0.02
Cellinx NVT v1.0.6.002b was discovered to contain a local file disclosure vulnerability via the component /cgi-bin/GetFileContent.cgi.
- risk 0.49cvss 7.5epss 0.01
IBM InfoSphere Information Server 11.7 could allow a remote attacker to traverse directories on the system. An attacker could send a specially crafted URL request containing "dot dot" sequences (/../) to view arbitrary files on the system. IBM X-Force ID: 246333
- risk 0.49cvss 7.5epss 0.01
In gin-vue-admin < 2.5.5, the download module has a Path Traversal vulnerability.
- risk 0.49cvss 7.5epss 0.01
Serenissima Informatica Fast Checkin 1.0 is vulnerable to Directory Traversal.