CWE-22
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
Description
The product uses external input to construct a pathname that is intended to identify a file or directory that is located underneath a restricted parent directory, but the product does not properly neutralize special elements within the pathname that can cause the pathname to resolve to a location that is outside of the restricted directory.
Hierarchy (View 1000)
Related attack patterns (CAPEC)
CAPEC-126 · CAPEC-64 · CAPEC-76 · CAPEC-78 · CAPEC-79
CVEs mapped to this weakness (10,395)
page 164 of 520| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2021-46104 | Hig | 0.49 | 7.5 | 0.05 | Jan 19, 2022 | An issue was discovered in webp_server_go 0.4.0. There is a directory traversal vulnerability that can read arbitrary file information on the server. | ||
| CVE-2021-44586 | Hig | 0.49 | 7.5 | 0.01 | Jan 10, 2022 | An issue was discovered in dst-admin v1.3.0. The product has an unauthorized arbitrary file download vulnerability that can expose sensitive information. | ||
| CVE-2020-29050 | Hig | 0.49 | 7.5 | 0.02 | Jan 10, 2022 | SphinxSearch in Sphinx Technologies Sphinx through 3.1.1 allows directory traversal (in conjunction with CVE-2019-14511) because the mysql client can be used for CALL SNIPPETS and load_file operations on a full pathname (e.g., a file in the /etc directory). NOTE: this is… | ||
| CVE-2021-44351 | Hig | 0.49 | 7.5 | 0.02 | Jan 6, 2022 | An arbitrary file read vulnerability exists in NavigateCMS 2.9 via /navigate/navigate_download.php id parameter. | ||
| CVE-2021-39970 | Hig | 0.49 | 7.5 | 0.01 | Jan 3, 2022 | HwPCAssistant has a Improper Input Validation vulnerability.Successful exploitation of this vulnerability may create any file with the system app permission. | ||
| CVE-2021-37126 | Hig | 0.49 | 7.5 | 0.01 | Jan 3, 2022 | Arbitrary file has a Exposure of Sensitive Information to an Unauthorized Actor vulnerability .Successful exploitation of this vulnerability may cause the directory is traversed. | ||
| CVE-2021-45712 | Hig | 0.49 | 7.5 | 0.02 | Dec 26, 2021 | An issue was discovered in the rust-embed crate before 6.3.0 for Rust. A ../ directory traversal can sometimes occur in debug mode. | ||
| CVE-2021-44162 | Hig | 0.49 | 7.5 | 0.02 | Dec 20, 2021 | Chain Sea ai chatbot system’s specific file download function has path traversal vulnerability. The function has improper filtering of special characters in URL parameters, which allows a remote attacker to download arbitrary system files without authentication. | ||
| CVE-2021-23797 | Hig | 0.49 | 7.5 | 0.02 | Dec 17, 2021 | All versions of package http-server-node are vulnerable to Directory Traversal via use of --path-as-is. | ||
| CVE-2021-44965 | Hig | 0.49 | 7.5 | 0.02 | Dec 13, 2021 | Directory traversal vulnerability in /admin/includes/* directory for PHPGURUKUL Employee Record Management System 1.2 The attacker can retrieve and download sensitive information from the vulnerable server. | ||
| CVE-2021-41024 | Hig | 0.49 | 7.5 | 0.02 | Dec 8, 2021 | A relative path traversal [CWE-23] vulnerabiltiy in FortiOS versions 7.0.0 and 7.0.1 and FortiProxy verison 7.0.0 may allow an unauthenticated, unauthorized attacker to inject path traversal character sequences to disclose sensitive information of the server via the GET request… | ||
| CVE-2021-44725 | Hig | 0.49 | 7.5 | 0.02 | Dec 8, 2021 | KNIME Server before 4.13.4 allows directory traversal in a request for a client profile. | ||
| CVE-2021-43358 | Hig | 0.49 | 7.5 | 0.02 | Dec 1, 2021 | Sunnet eHRD has inadequate filtering for special characters in URLs, which allows a remote attacker to perform path traversal attacks without authentication, access restricted paths and download system files. | ||
| CVE-2021-43775 | Hig | 0.49 | 8.6 | 0.02 | Nov 23, 2021 | Aim is an open-source, self-hosted machine learning experiment tracking tool. Versions of Aim prior to 3.1.0 are vulnerable to a path traversal attack. By manipulating variables that reference files with “dot-dot-slash (../)” sequences and its variations or by using absolute… | ||
| CVE-2021-24644 | Hig | 0.49 | 7.5 | 0.05 | Nov 23, 2021 | The Images to WebP WordPress plugin before 1.9 does not validate or sanitise the tab parameter before passing it to the include() function, which could lead to a Local File Inclusion issue | ||
| CVE-2020-7882 | Hig | 0.49 | 7.5 | 0.01 | Nov 22, 2021 | Using the parameter of getPFXFolderList function, attackers can see the information of authorization certification and delete the files. It occurs because the parameter contains path traversal characters(ie. '../../../') | ||
| CVE-2021-40745 | Hig | 0.49 | 7.5 | 0.04 | Nov 17, 2021 | Adobe Campaign version 21.2.1 (and earlier) is affected by a Path Traversal vulnerability that could lead to reading arbitrary server files. By leveraging an exposed XML file, an unauthenticated attacker can enumerate other files on the server. | ||
| CVE-2021-43495 | Hig | 0.49 | 7.5 | 0.09 | Nov 15, 2021 | AlquistManager branch as of commit 280d99f43b11378212652e75f6f3159cde9c1d36 is affected by a directory traversal vulnerability in alquist/IO/input.py. This attack can cause the disclosure of critical secrets stored anywhere on the system and can significantly aid in getting… | ||
| CVE-2021-43493 | Hig | 0.49 | 7.5 | 0.02 | Nov 12, 2021 | ServerManagement master branch as of commit 49491cc6f94980e6be7791d17be947c27071eb56 is affected by a directory traversal vulnerability. This vulnerability can be used to extract credentials which can in turn be used to execute code. | ||
| CVE-2021-43492 | Hig | 0.49 | 7.5 | 0.04 | Nov 12, 2021 | AlquistManager branch as of commit 280d99f43b11378212652e75f6f3159cde9c1d36 is affected by a directory traversal vulnerability. This attack can cause the disclosure of critical secrets stored anywhere on the system andcan significantly aid in getting remote code access. |
- risk 0.49cvss 7.5epss 0.05
An issue was discovered in webp_server_go 0.4.0. There is a directory traversal vulnerability that can read arbitrary file information on the server.
- risk 0.49cvss 7.5epss 0.01
An issue was discovered in dst-admin v1.3.0. The product has an unauthorized arbitrary file download vulnerability that can expose sensitive information.
- risk 0.49cvss 7.5epss 0.02
SphinxSearch in Sphinx Technologies Sphinx through 3.1.1 allows directory traversal (in conjunction with CVE-2019-14511) because the mysql client can be used for CALL SNIPPETS and load_file operations on a full pathname (e.g., a file in the /etc directory). NOTE: this is…
- risk 0.49cvss 7.5epss 0.02
An arbitrary file read vulnerability exists in NavigateCMS 2.9 via /navigate/navigate_download.php id parameter.
- risk 0.49cvss 7.5epss 0.01
HwPCAssistant has a Improper Input Validation vulnerability.Successful exploitation of this vulnerability may create any file with the system app permission.
- risk 0.49cvss 7.5epss 0.01
Arbitrary file has a Exposure of Sensitive Information to an Unauthorized Actor vulnerability .Successful exploitation of this vulnerability may cause the directory is traversed.
- risk 0.49cvss 7.5epss 0.02
An issue was discovered in the rust-embed crate before 6.3.0 for Rust. A ../ directory traversal can sometimes occur in debug mode.
- risk 0.49cvss 7.5epss 0.02
Chain Sea ai chatbot system’s specific file download function has path traversal vulnerability. The function has improper filtering of special characters in URL parameters, which allows a remote attacker to download arbitrary system files without authentication.
- risk 0.49cvss 7.5epss 0.02
All versions of package http-server-node are vulnerable to Directory Traversal via use of --path-as-is.
- risk 0.49cvss 7.5epss 0.02
Directory traversal vulnerability in /admin/includes/* directory for PHPGURUKUL Employee Record Management System 1.2 The attacker can retrieve and download sensitive information from the vulnerable server.
- risk 0.49cvss 7.5epss 0.02
A relative path traversal [CWE-23] vulnerabiltiy in FortiOS versions 7.0.0 and 7.0.1 and FortiProxy verison 7.0.0 may allow an unauthenticated, unauthorized attacker to inject path traversal character sequences to disclose sensitive information of the server via the GET request…
- risk 0.49cvss 7.5epss 0.02
KNIME Server before 4.13.4 allows directory traversal in a request for a client profile.
- risk 0.49cvss 7.5epss 0.02
Sunnet eHRD has inadequate filtering for special characters in URLs, which allows a remote attacker to perform path traversal attacks without authentication, access restricted paths and download system files.
- risk 0.49cvss 8.6epss 0.02
Aim is an open-source, self-hosted machine learning experiment tracking tool. Versions of Aim prior to 3.1.0 are vulnerable to a path traversal attack. By manipulating variables that reference files with “dot-dot-slash (../)” sequences and its variations or by using absolute…
- risk 0.49cvss 7.5epss 0.05
The Images to WebP WordPress plugin before 1.9 does not validate or sanitise the tab parameter before passing it to the include() function, which could lead to a Local File Inclusion issue
- risk 0.49cvss 7.5epss 0.01
Using the parameter of getPFXFolderList function, attackers can see the information of authorization certification and delete the files. It occurs because the parameter contains path traversal characters(ie. '../../../')
- risk 0.49cvss 7.5epss 0.04
Adobe Campaign version 21.2.1 (and earlier) is affected by a Path Traversal vulnerability that could lead to reading arbitrary server files. By leveraging an exposed XML file, an unauthenticated attacker can enumerate other files on the server.
- risk 0.49cvss 7.5epss 0.09
AlquistManager branch as of commit 280d99f43b11378212652e75f6f3159cde9c1d36 is affected by a directory traversal vulnerability in alquist/IO/input.py. This attack can cause the disclosure of critical secrets stored anywhere on the system and can significantly aid in getting…
- risk 0.49cvss 7.5epss 0.02
ServerManagement master branch as of commit 49491cc6f94980e6be7791d17be947c27071eb56 is affected by a directory traversal vulnerability. This vulnerability can be used to extract credentials which can in turn be used to execute code.
- risk 0.49cvss 7.5epss 0.04
AlquistManager branch as of commit 280d99f43b11378212652e75f6f3159cde9c1d36 is affected by a directory traversal vulnerability. This attack can cause the disclosure of critical secrets stored anywhere on the system andcan significantly aid in getting remote code access.