CWE-22
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
Description
The product uses external input to construct a pathname that is intended to identify a file or directory that is located underneath a restricted parent directory, but the product does not properly neutralize special elements within the pathname that can cause the pathname to resolve to a location that is outside of the restricted directory.
Hierarchy (View 1000)
Related attack patterns (CAPEC)
CAPEC-126 · CAPEC-64 · CAPEC-76 · CAPEC-78 · CAPEC-79
CVEs mapped to this weakness (10,395)
page 161 of 520| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2021-38399 | Hig | 0.49 | 7.5 | 0.01 | Oct 28, 2022 | Honeywell Experion PKS C200, C200E, C300, and ACE controllers are vulnerable to relative path traversal, which may allow an attacker access to unauthorized files and directories. | ||
| CVE-2022-42188 | Hig | 0.49 | 7.5 | 0.01 | Oct 18, 2022 | In Lavalite 9.0.0, the XSRF-TOKEN cookie is vulnerable to path traversal attacks, enabling read access to arbitrary files on the server. | ||
| CVE-2022-39058 | Hig | 0.49 | 7.5 | 0.02 | Oct 18, 2022 | RAVA certification validation system has a path traversal vulnerability. An unauthenticated remote attacker can exploit this vulnerability to bypass authentication and access arbitrary system files. | ||
| CVE-2021-20030 | Hig | 0.49 | 7.5 | 0.01 | Oct 13, 2022 | SonicWall GMS is vulnerable to file path manipulation resulting that an unauthenticated attacker can gain access to web directory containing application's binaries and configuration files. | ||
| CVE-2022-39802 | Hig | 0.49 | 7.5 | 0.07 | Oct 11, 2022 | SAP Manufacturing Execution - versions 15.1, 15.2, 15.3, allows an attacker to exploit insufficient validation of a file path request parameter. The intended file path can be manipulated to allow arbitrary traversal of directories on the remote server. The file content within… | ||
| CVE-2022-39296 | Hig | 0.49 | 8.6 | 0.02 | Oct 11, 2022 | MelisAssetManager provides deliveries of Melis Platform's assets located in every module's public folder. Attackers can read arbitrary files on affected versions of `melisplatform/melis-asset-manager`, leading to the disclosure of sensitive information. Conducting this attack… | ||
| CVE-2022-34026 | Hig | 0.49 | 7.5 | 0.02 | Sep 22, 2022 | ICEcoder v8.1 allows attackers to execute a directory traversal. | ||
| CVE-2022-28981 | Hig | 0.49 | 7.5 | 0.01 | Sep 22, 2022 | Path traversal vulnerability in the Hypermedia REST APIs module in Liferay Portal 7.4.0 through 7.4.2 allows remote attackers to access files outside of com.liferay.headless.discovery.web/META-INF/resources via the `parameter` parameter. | ||
| CVE-2022-2265 | Hig | 0.49 | 7.5 | 0.01 | Sep 21, 2022 | The Identity and Directory Management System developed by Çekino Bilgi Teknolojileri before version 2.1.25 has an unauthenticated Path traversal vulnerability. This has been fixed in the version 2.1.25 | ||
| CVE-2022-40608 | Hig | 0.49 | 7.5 | 0.02 | Sep 19, 2022 | IBM Spectrum Protect Plus 10.1.6 through 10.1.11 Microsoft File Systems restore operation can download any file on the target machine by manipulating the URL with a directory traversal attack. This results in the restore operation gaining access to files which the operator… | ||
| CVE-2022-37700 | Hig | 0.49 | 7.5 | 0.03 | Sep 19, 2022 | Zentao Demo15 is vulnerable to Directory Traversal. The impact is: obtain sensitive information (remote). The component is: URL : view-source:https://demo15.zentao.pm/user-login.html/zentao/index.php?mode=getconfig. | ||
| CVE-2022-39001 | Hig | 0.49 | 7.5 | 0.01 | Sep 16, 2022 | The number identification module has a path traversal vulnerability. Successful exploitation of this vulnerability may cause data disclosure. | ||
| CVE-2022-38614 | Hig | 0.49 | 7.5 | 0.01 | Sep 9, 2022 | An issue in the IGB Files and OutfileService features of SmartVista Cardgen v3.28.0 allows attackers to list and download arbitrary files via modifying the PATH parameter. | ||
| CVE-2022-37681 | Hig | 0.49 | 7.5 | 0.01 | Aug 29, 2022 | Hitachi Kokusai Electric Newtork products for monitoring system (Camera, Decoder and Encoder) and below allows attckers to perform a directory traversal via a crafted GET request to the endpoint /ptippage.cgi. Security information ID hitachi-sec-2022-001 contains fixes for the… | ||
| CVE-2022-38794 | Hig | 0.49 | 7.5 | 0.04 | Aug 27, 2022 | Zaver through 2020-12-15 allows directory traversal via the GET /.. substring. | ||
| CVE-2022-37422 | Hig | 0.49 | 7.5 | 0.01 | Aug 18, 2022 | Payara through 5.2022.2 allows directory traversal without authentication. This affects Payara Server, Payara Micro, and Payara Server Embedded. | ||
| CVE-2021-42052 | Hig | 0.49 | 7.5 | 0.01 | Aug 16, 2022 | IPESA e-Flow 3.3.6 allows path traversal for reading any file within the web root directory via the lib/js/build/STEResource.res path and the R query parameter. | ||
| CVE-2020-21365 | Hig | 0.49 | 7.5 | 0.02 | Aug 15, 2022 | Directory traversal vulnerability in wkhtmltopdf through 0.12.5 allows remote attackers to read local files and disclose sensitive information via a crafted html file running with the default configurations. | ||
| CVE-2022-29804 | Hig | 0.49 | 7.5 | 0.02 | Aug 10, 2022 | Incorrect conversion of certain invalid paths to valid, absolute paths in Clean in path/filepath before Go 1.17.11 and Go 1.18.3 on Windows allows potential directory traversal attack. | ||
| CVE-2022-31662 | Hig | 0.49 | 7.5 | 0.01 | Aug 5, 2022 | VMware Workspace ONE Access, Identity Manager, Connectors and vRealize Automation contain a path traversal vulnerability. A malicious actor with network access may be able to access arbitrary files. |
- risk 0.49cvss 7.5epss 0.01
Honeywell Experion PKS C200, C200E, C300, and ACE controllers are vulnerable to relative path traversal, which may allow an attacker access to unauthorized files and directories.
- risk 0.49cvss 7.5epss 0.01
In Lavalite 9.0.0, the XSRF-TOKEN cookie is vulnerable to path traversal attacks, enabling read access to arbitrary files on the server.
- risk 0.49cvss 7.5epss 0.02
RAVA certification validation system has a path traversal vulnerability. An unauthenticated remote attacker can exploit this vulnerability to bypass authentication and access arbitrary system files.
- risk 0.49cvss 7.5epss 0.01
SonicWall GMS is vulnerable to file path manipulation resulting that an unauthenticated attacker can gain access to web directory containing application's binaries and configuration files.
- risk 0.49cvss 7.5epss 0.07
SAP Manufacturing Execution - versions 15.1, 15.2, 15.3, allows an attacker to exploit insufficient validation of a file path request parameter. The intended file path can be manipulated to allow arbitrary traversal of directories on the remote server. The file content within…
- risk 0.49cvss 8.6epss 0.02
MelisAssetManager provides deliveries of Melis Platform's assets located in every module's public folder. Attackers can read arbitrary files on affected versions of `melisplatform/melis-asset-manager`, leading to the disclosure of sensitive information. Conducting this attack…
- risk 0.49cvss 7.5epss 0.02
ICEcoder v8.1 allows attackers to execute a directory traversal.
- risk 0.49cvss 7.5epss 0.01
Path traversal vulnerability in the Hypermedia REST APIs module in Liferay Portal 7.4.0 through 7.4.2 allows remote attackers to access files outside of com.liferay.headless.discovery.web/META-INF/resources via the `parameter` parameter.
- risk 0.49cvss 7.5epss 0.01
The Identity and Directory Management System developed by Çekino Bilgi Teknolojileri before version 2.1.25 has an unauthenticated Path traversal vulnerability. This has been fixed in the version 2.1.25
- risk 0.49cvss 7.5epss 0.02
IBM Spectrum Protect Plus 10.1.6 through 10.1.11 Microsoft File Systems restore operation can download any file on the target machine by manipulating the URL with a directory traversal attack. This results in the restore operation gaining access to files which the operator…
- risk 0.49cvss 7.5epss 0.03
Zentao Demo15 is vulnerable to Directory Traversal. The impact is: obtain sensitive information (remote). The component is: URL : view-source:https://demo15.zentao.pm/user-login.html/zentao/index.php?mode=getconfig.
- risk 0.49cvss 7.5epss 0.01
The number identification module has a path traversal vulnerability. Successful exploitation of this vulnerability may cause data disclosure.
- risk 0.49cvss 7.5epss 0.01
An issue in the IGB Files and OutfileService features of SmartVista Cardgen v3.28.0 allows attackers to list and download arbitrary files via modifying the PATH parameter.
- risk 0.49cvss 7.5epss 0.01
Hitachi Kokusai Electric Newtork products for monitoring system (Camera, Decoder and Encoder) and below allows attckers to perform a directory traversal via a crafted GET request to the endpoint /ptippage.cgi. Security information ID hitachi-sec-2022-001 contains fixes for the…
- risk 0.49cvss 7.5epss 0.04
Zaver through 2020-12-15 allows directory traversal via the GET /.. substring.
- risk 0.49cvss 7.5epss 0.01
Payara through 5.2022.2 allows directory traversal without authentication. This affects Payara Server, Payara Micro, and Payara Server Embedded.
- risk 0.49cvss 7.5epss 0.01
IPESA e-Flow 3.3.6 allows path traversal for reading any file within the web root directory via the lib/js/build/STEResource.res path and the R query parameter.
- risk 0.49cvss 7.5epss 0.02
Directory traversal vulnerability in wkhtmltopdf through 0.12.5 allows remote attackers to read local files and disclose sensitive information via a crafted html file running with the default configurations.
- risk 0.49cvss 7.5epss 0.02
Incorrect conversion of certain invalid paths to valid, absolute paths in Clean in path/filepath before Go 1.17.11 and Go 1.18.3 on Windows allows potential directory traversal attack.
- risk 0.49cvss 7.5epss 0.01
VMware Workspace ONE Access, Identity Manager, Connectors and vRealize Automation contain a path traversal vulnerability. A malicious actor with network access may be able to access arbitrary files.