CWE-22
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
Description
The product uses external input to construct a pathname that is intended to identify a file or directory that is located underneath a restricted parent directory, but the product does not properly neutralize special elements within the pathname that can cause the pathname to resolve to a location that is outside of the restricted directory.
Hierarchy (View 1000)
Related attack patterns (CAPEC)
CAPEC-126 · CAPEC-64 · CAPEC-76 · CAPEC-78 · CAPEC-79
CVEs mapped to this weakness (10,395)
page 163 of 520| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2022-28444 | Hig | 0.49 | 7.5 | 0.02 | Apr 21, 2022 | UCMS v1.6 was discovered to contain an arbitrary file read vulnerability. | ||
| CVE-2022-27043 | Hig | 0.49 | 7.5 | 0.06 | Apr 15, 2022 | Yearning versions 2.3.1 and 2.3.2 Interstellar GA and 2.3.4 - 2.3.6 Neptune is vulnerable to Directory Traversal. | ||
| CVE-2022-24843 | Hig | 0.49 | 7.5 | 0.02 | Apr 13, 2022 | Gin-vue-admin is a backstage management system based on vue and gin, which separates the front and rear of the full stack. Gin-vue-admin 2.50 has arbitrary file read vulnerability due to a lack of parameter validation. This has been resolved in version 2.5.1. There are no known… | ||
| CVE-2022-27279 | Hig | 0.49 | 7.5 | 0.02 | Apr 10, 2022 | InHand Networks InRouter 900 Industrial 4G Router before v1.0.0.r11700 was discovered to contain an arbitrary file read via the function sub_177E0. | ||
| CVE-2022-26675 | Hig | 0.49 | 7.5 | 0.02 | Apr 7, 2022 | aEnrich a+HRD has inadequate filtering for special characters in URLs. An unauthenticated remote attacker can bypass authentication and perform path traversal attacks to access arbitrary files under website root directory. | ||
| CVE-2022-28380 | Hig | 0.49 | 7.5 | 0.02 | Apr 3, 2022 | The rc-httpd component through 2022-03-31 for 9front (Plan 9 fork) allows ..%2f directory traversal if serve-static is used. | ||
| CVE-2021-32949 | Hig | 0.49 | 7.5 | 0.01 | Apr 1, 2022 | An attacker could utilize a function in MDT AutoSave versions prior to v6.02.06 that permits changing a designated path to another path and traversing the directory, allowing the replacement of an existing file with a malicious file. | ||
| CVE-2022-23793 | Hig | 0.49 | 7.5 | 0.02 | Mar 30, 2022 | An issue was discovered in Joomla! 3.0.0 through 3.10.6 & 4.0.0 through 4.1.0. Extracting an specifilcy crafted tar package could write files outside of the intended path. | ||
| CVE-2021-44124 | Hig | 0.49 | 7.5 | 0.02 | Mar 28, 2022 | Hiby Music Hiby OS R3 Pro 1.5 and 1.6 is vulnerable to Directory Traversal. The HTTP Server does not have enough input data sanitization when shown data from SD Card, an attacker can navigate through the device's File System over HTTP. | ||
| CVE-2022-25249 | Hig | 0.49 | 7.5 | 0.02 | Mar 16, 2022 | When connecting to a certain port Axeda agent (All versions) and Axeda Desktop Server for Windows (All versions) (disregarding Axeda agent v6.9.2 and v6.9.3) is vulnerable to directory traversal, which could allow a remote unauthenticated attacker to obtain file system read… | ||
| CVE-2022-25634 | Hig | 0.49 | 7.5 | 0.02 | Mar 2, 2022 | Qt through 5.15.8 and 6.x through 6.2.3 can load system library files from an unintended working directory. | ||
| CVE-2022-24718 | Hig | 0.49 | 7.6 | 0.01 | Mar 1, 2022 | ssr-pages is an HTML page builder for the purpose of server-side rendering (SSR). In versions prior to 0.1.4, a path traversal issue can occur when providing untrusted input to the `svg` property as an argument to the `build(MessagePageOptions)` function. While there is no known… | ||
| CVE-2021-45746 | Hig | 0.49 | 7.5 | 0.02 | Feb 24, 2022 | A Directory Traversal vulnerability exists in WeBankPartners wecube-platform 3.2.1 via the file variable in PluginPackageController.java. | ||
| CVE-2022-22914 | Hig | 0.49 | 7.5 | 0.01 | Feb 17, 2022 | An incorrect access control issue in the component FileManager of Ovidentia CMS 6.0 allows authenticated attackers to to view and download content in the upload directory via path traversal. | ||
| CVE-2022-24983 | Hig | 0.49 | 7.5 | 0.03 | Feb 16, 2022 | Forms generated by JQueryForm.com before 2022-02-05 allow remote attackers to obtain the URI to any uploaded file by capturing the POST response. When chained with CVE-2022-24984, this could lead to unauthenticated remote code execution on the underlying web server. This occurs… | ||
| CVE-2021-22804 | Hig | 0.49 | 7.5 | 0.01 | Feb 11, 2022 | A CWE-22: Improper Limitation of a Pathname to a Restricted Directory vulnerability exists that could cause disclosure of arbitrary files being read in the context of the user running IGSS, due to missing validation of user supplied data in network messages. Affected Product:… | ||
| CVE-2022-21193 | Hig | 0.49 | 7.5 | 0.02 | Feb 8, 2022 | Directory traversal vulnerability in TransmitMail 2.5.0 to 2.6.1 allows a remote unauthenticated attacker to obtain an arbitrary file on the server via unspecified vectors. | ||
| CVE-2021-29395 | Hig | 0.49 | 7.5 | 0.02 | Feb 4, 2022 | Directory travesal in /northstar/filemanager/download.jsp in Northstar Technologies Inc NorthStar Club Management 6.3 allows remote unauthenticated users to download arbitrary files, including JSP source code, across the filesystem of the host of the web application. | ||
| CVE-2021-44977 | Hig | 0.49 | 7.5 | 0.02 | Feb 4, 2022 | In iCMS <=8.0.0, a directory traversal vulnerability allows an attacker to read arbitrary files. | ||
| CVE-2021-23631 | Hig | 0.49 | 7.5 | 0.02 | Jan 21, 2022 | This affects all versions of package convert-svg-core; all versions of package convert-svg-to-png; all versions of package convert-svg-to-jpeg. Using a specially crafted SVG file, an attacker could read arbitrary files from the file system and then show the file content as a… |
- risk 0.49cvss 7.5epss 0.02
UCMS v1.6 was discovered to contain an arbitrary file read vulnerability.
- risk 0.49cvss 7.5epss 0.06
Yearning versions 2.3.1 and 2.3.2 Interstellar GA and 2.3.4 - 2.3.6 Neptune is vulnerable to Directory Traversal.
- risk 0.49cvss 7.5epss 0.02
Gin-vue-admin is a backstage management system based on vue and gin, which separates the front and rear of the full stack. Gin-vue-admin 2.50 has arbitrary file read vulnerability due to a lack of parameter validation. This has been resolved in version 2.5.1. There are no known…
- risk 0.49cvss 7.5epss 0.02
InHand Networks InRouter 900 Industrial 4G Router before v1.0.0.r11700 was discovered to contain an arbitrary file read via the function sub_177E0.
- risk 0.49cvss 7.5epss 0.02
aEnrich a+HRD has inadequate filtering for special characters in URLs. An unauthenticated remote attacker can bypass authentication and perform path traversal attacks to access arbitrary files under website root directory.
- risk 0.49cvss 7.5epss 0.02
The rc-httpd component through 2022-03-31 for 9front (Plan 9 fork) allows ..%2f directory traversal if serve-static is used.
- risk 0.49cvss 7.5epss 0.01
An attacker could utilize a function in MDT AutoSave versions prior to v6.02.06 that permits changing a designated path to another path and traversing the directory, allowing the replacement of an existing file with a malicious file.
- risk 0.49cvss 7.5epss 0.02
An issue was discovered in Joomla! 3.0.0 through 3.10.6 & 4.0.0 through 4.1.0. Extracting an specifilcy crafted tar package could write files outside of the intended path.
- risk 0.49cvss 7.5epss 0.02
Hiby Music Hiby OS R3 Pro 1.5 and 1.6 is vulnerable to Directory Traversal. The HTTP Server does not have enough input data sanitization when shown data from SD Card, an attacker can navigate through the device's File System over HTTP.
- risk 0.49cvss 7.5epss 0.02
When connecting to a certain port Axeda agent (All versions) and Axeda Desktop Server for Windows (All versions) (disregarding Axeda agent v6.9.2 and v6.9.3) is vulnerable to directory traversal, which could allow a remote unauthenticated attacker to obtain file system read…
- risk 0.49cvss 7.5epss 0.02
Qt through 5.15.8 and 6.x through 6.2.3 can load system library files from an unintended working directory.
- risk 0.49cvss 7.6epss 0.01
ssr-pages is an HTML page builder for the purpose of server-side rendering (SSR). In versions prior to 0.1.4, a path traversal issue can occur when providing untrusted input to the `svg` property as an argument to the `build(MessagePageOptions)` function. While there is no known…
- risk 0.49cvss 7.5epss 0.02
A Directory Traversal vulnerability exists in WeBankPartners wecube-platform 3.2.1 via the file variable in PluginPackageController.java.
- risk 0.49cvss 7.5epss 0.01
An incorrect access control issue in the component FileManager of Ovidentia CMS 6.0 allows authenticated attackers to to view and download content in the upload directory via path traversal.
- risk 0.49cvss 7.5epss 0.03
Forms generated by JQueryForm.com before 2022-02-05 allow remote attackers to obtain the URI to any uploaded file by capturing the POST response. When chained with CVE-2022-24984, this could lead to unauthenticated remote code execution on the underlying web server. This occurs…
- risk 0.49cvss 7.5epss 0.01
A CWE-22: Improper Limitation of a Pathname to a Restricted Directory vulnerability exists that could cause disclosure of arbitrary files being read in the context of the user running IGSS, due to missing validation of user supplied data in network messages. Affected Product:…
- risk 0.49cvss 7.5epss 0.02
Directory traversal vulnerability in TransmitMail 2.5.0 to 2.6.1 allows a remote unauthenticated attacker to obtain an arbitrary file on the server via unspecified vectors.
- risk 0.49cvss 7.5epss 0.02
Directory travesal in /northstar/filemanager/download.jsp in Northstar Technologies Inc NorthStar Club Management 6.3 allows remote unauthenticated users to download arbitrary files, including JSP source code, across the filesystem of the host of the web application.
- risk 0.49cvss 7.5epss 0.02
In iCMS <=8.0.0, a directory traversal vulnerability allows an attacker to read arbitrary files.
- risk 0.49cvss 7.5epss 0.02
This affects all versions of package convert-svg-core; all versions of package convert-svg-to-png; all versions of package convert-svg-to-jpeg. Using a specially crafted SVG file, an attacker could read arbitrary files from the file system and then show the file content as a…