CWE-22
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
Description
The product uses external input to construct a pathname that is intended to identify a file or directory that is located underneath a restricted parent directory, but the product does not properly neutralize special elements within the pathname that can cause the pathname to resolve to a location that is outside of the restricted directory.
Hierarchy (View 1000)
Related attack patterns (CAPEC)
CAPEC-126 · CAPEC-64 · CAPEC-76 · CAPEC-78 · CAPEC-79
CVEs mapped to this weakness (10,395)
page 166 of 520| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2021-33555 | Hig | 0.49 | 7.5 | 0.01 | Aug 31, 2021 | In PEPPERL+FUCHS WirelessHART-Gateway <= 3.0.7 the filename parameter is vulnerable to unauthenticated path traversal attacks, enabling read access to arbitrary files on the server. | ||
| CVE-2021-38612 | Hig | 0.49 | 7.5 | 0.02 | Aug 24, 2021 | In NASCENT RemKon Device Manager 4.0.0.0, a Directory Traversal vulnerability in a log-reading function in maintenance/readLog.php allows an attacker to read any file via a specialized URL. | ||
| CVE-2021-23430 | Hig | 0.49 | 7.5 | 0.02 | Aug 24, 2021 | All versions of package startserver are vulnerable to Directory Traversal due to missing sanitization. | ||
| CVE-2021-38758 | Hig | 0.49 | 7.5 | 0.02 | Aug 16, 2021 | Directory traversal vulnerability in Online Catering Reservation System 1.0 exists due to lack of validation in index.php. | ||
| CVE-2015-2074 | Hig | 0.49 | 7.5 | 0.04 | Aug 9, 2021 | The File Repository Server (FRS) CORBA listener in SAP BussinessObjects Edge 4.0 allows remote attackers to write to arbitrary files via a full pathname, aka SAP Note 2018681. | ||
| CVE-2015-2073 | Hig | 0.49 | 7.5 | 0.04 | Aug 9, 2021 | The File RepositoRy Server (FRS) CORBA listener in SAP BussinessObjects Edge 4.0 allows remote attackers to read arbitrary files via a full pathname, aka SAP Note 2018682. | ||
| CVE-2021-35397 | Hig | 0.49 | 7.5 | 0.04 | Aug 4, 2021 | A path traversal vulnerability in the static router for Drogon from 1.0.0-beta14 to 1.6.0 could allow an unauthenticated, remote attacker to arbitrarily read files. The vulnerability is due to lack of proper input validation for requested path. An attacker could exploit this… | ||
| CVE-2020-19304 | Hig | 0.49 | 7.5 | 0.02 | Aug 3, 2021 | An issue in /admin/index.php?n=system&c=filept&a=doGetFileList of Metinfo v7.0.0 allows attackers to perform a directory traversal and access sensitive information. | ||
| CVE-2021-35054 | Hig | 0.49 | 7.5 | 0.01 | Jul 20, 2021 | Minecraft before 1.17.1, when online-mode=false is configured, allows path traversal for deletion of arbitrary JSON files. | ||
| CVE-2021-34820 | Hig | 0.49 | 7.5 | 0.04 | Jul 19, 2021 | Web Path Directory Traversal in the Novus HTTP Server. The Novus HTTP Server is affected by the Directory Traversal for Arbitrary File Access vulnerability. A remote, unauthenticated attacker using an HTTP GET request may be able to exploit this issue to access sensitive data.… | ||
| CVE-2021-35962 | Hig | 0.49 | 7.5 | 0.02 | Jul 16, 2021 | Specific page parameters in Dr. ID Door Access Control and Personnel Attendance Management system does not filter special characters. Remote attackers can apply Path Traversal means to download credential files from the system without permission. | ||
| CVE-2021-32532 | Hig | 0.49 | 7.5 | 0.02 | Jul 7, 2021 | Path traversal vulnerability in back-end analysis function in QSAN XEVO allows remote attackers to download arbitrary files without permissions. The referred vulnerability has been solved with the updated version of QSAN XEVO v2.1.0. | ||
| CVE-2021-32527 | Hig | 0.49 | 7.5 | 0.02 | Jul 7, 2021 | Path traversal vulnerability in QSAN Storage Manager allows remote unauthenticated attackers to download arbitrary files thru injecting file path in download function. Suggest contacting with QSAN and refer to recommendations in QSAN Document. | ||
| CVE-2021-32516 | Hig | 0.49 | 7.5 | 0.02 | Jul 7, 2021 | Path traversal vulnerability in share_link in QSAN Storage Manager allows remote attackers to download arbitrary files. The referred vulnerability has been solved with the updated version of QSAN Storage Manager v3.3.3. | ||
| CVE-2020-24143 | Hig | 0.49 | 7.5 | 0.02 | Jul 7, 2021 | Directory traversal in the Video Downloader for TikTok (aka downloader-tiktok) plugin 1.3 for WordPress lets an attacker get access to files that are stored outside the web root folder via the njt-tk-download-video parameter. | ||
| CVE-2021-29157 | Hig | 0.49 | 7.5 | 0.00 | Jun 28, 2021 | Dovecot before 2.3.15 allows ../ Path Traversal. An attacker with access to the local filesystem can trick OAuth2 authentication into using an HS256 validation key from an attacker-controlled location. This occurs during use of local JWT validation with the posix fs driver. | ||
| CVE-2021-29087 | Hig | 0.49 | 7.5 | 0.01 | Jun 23, 2021 | Improper limitation of a pathname to a restricted directory ('Path Traversal') vulnerability in webapi component in Synology DiskStation Manager (DSM) before 6.2.3-25426-3 allows remote attackers to write arbitrary files via unspecified vectors. | ||
| CVE-2021-31538 | Hig | 0.49 | 7.5 | 0.01 | Jun 10, 2021 | LANCOM R&S Unified Firewall (UF) devices running LCOS FX 10.5 allow Relative Path Traversal. | ||
| CVE-2021-30465 | Hig | 0.49 | 8.5 | 0.07 | May 27, 2021 | runc before 1.0.0-rc95 allows a Container Filesystem Breakout via Directory Traversal. To exploit the vulnerability, an attacker must be able to create multiple containers with a fairly specific mount configuration. The problem occurs via a symlink-exchange attack that relies on… | ||
| CVE-2021-22736 | Hig | 0.49 | 7.5 | 0.01 | May 26, 2021 | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability exists in homeLYnk (Wiser For KNX) and spaceLYnk V2.60 and prior which could cause a denial of service when an unauthorized file is uploaded. |
- risk 0.49cvss 7.5epss 0.01
In PEPPERL+FUCHS WirelessHART-Gateway <= 3.0.7 the filename parameter is vulnerable to unauthenticated path traversal attacks, enabling read access to arbitrary files on the server.
- risk 0.49cvss 7.5epss 0.02
In NASCENT RemKon Device Manager 4.0.0.0, a Directory Traversal vulnerability in a log-reading function in maintenance/readLog.php allows an attacker to read any file via a specialized URL.
- risk 0.49cvss 7.5epss 0.02
All versions of package startserver are vulnerable to Directory Traversal due to missing sanitization.
- risk 0.49cvss 7.5epss 0.02
Directory traversal vulnerability in Online Catering Reservation System 1.0 exists due to lack of validation in index.php.
- risk 0.49cvss 7.5epss 0.04
The File Repository Server (FRS) CORBA listener in SAP BussinessObjects Edge 4.0 allows remote attackers to write to arbitrary files via a full pathname, aka SAP Note 2018681.
- risk 0.49cvss 7.5epss 0.04
The File RepositoRy Server (FRS) CORBA listener in SAP BussinessObjects Edge 4.0 allows remote attackers to read arbitrary files via a full pathname, aka SAP Note 2018682.
- risk 0.49cvss 7.5epss 0.04
A path traversal vulnerability in the static router for Drogon from 1.0.0-beta14 to 1.6.0 could allow an unauthenticated, remote attacker to arbitrarily read files. The vulnerability is due to lack of proper input validation for requested path. An attacker could exploit this…
- risk 0.49cvss 7.5epss 0.02
An issue in /admin/index.php?n=system&c=filept&a=doGetFileList of Metinfo v7.0.0 allows attackers to perform a directory traversal and access sensitive information.
- risk 0.49cvss 7.5epss 0.01
Minecraft before 1.17.1, when online-mode=false is configured, allows path traversal for deletion of arbitrary JSON files.
- risk 0.49cvss 7.5epss 0.04
Web Path Directory Traversal in the Novus HTTP Server. The Novus HTTP Server is affected by the Directory Traversal for Arbitrary File Access vulnerability. A remote, unauthenticated attacker using an HTTP GET request may be able to exploit this issue to access sensitive data.…
- risk 0.49cvss 7.5epss 0.02
Specific page parameters in Dr. ID Door Access Control and Personnel Attendance Management system does not filter special characters. Remote attackers can apply Path Traversal means to download credential files from the system without permission.
- risk 0.49cvss 7.5epss 0.02
Path traversal vulnerability in back-end analysis function in QSAN XEVO allows remote attackers to download arbitrary files without permissions. The referred vulnerability has been solved with the updated version of QSAN XEVO v2.1.0.
- risk 0.49cvss 7.5epss 0.02
Path traversal vulnerability in QSAN Storage Manager allows remote unauthenticated attackers to download arbitrary files thru injecting file path in download function. Suggest contacting with QSAN and refer to recommendations in QSAN Document.
- risk 0.49cvss 7.5epss 0.02
Path traversal vulnerability in share_link in QSAN Storage Manager allows remote attackers to download arbitrary files. The referred vulnerability has been solved with the updated version of QSAN Storage Manager v3.3.3.
- risk 0.49cvss 7.5epss 0.02
Directory traversal in the Video Downloader for TikTok (aka downloader-tiktok) plugin 1.3 for WordPress lets an attacker get access to files that are stored outside the web root folder via the njt-tk-download-video parameter.
- risk 0.49cvss 7.5epss 0.00
Dovecot before 2.3.15 allows ../ Path Traversal. An attacker with access to the local filesystem can trick OAuth2 authentication into using an HS256 validation key from an attacker-controlled location. This occurs during use of local JWT validation with the posix fs driver.
- risk 0.49cvss 7.5epss 0.01
Improper limitation of a pathname to a restricted directory ('Path Traversal') vulnerability in webapi component in Synology DiskStation Manager (DSM) before 6.2.3-25426-3 allows remote attackers to write arbitrary files via unspecified vectors.
- risk 0.49cvss 7.5epss 0.01
LANCOM R&S Unified Firewall (UF) devices running LCOS FX 10.5 allow Relative Path Traversal.
- risk 0.49cvss 8.5epss 0.07
runc before 1.0.0-rc95 allows a Container Filesystem Breakout via Directory Traversal. To exploit the vulnerability, an attacker must be able to create multiple containers with a fairly specific mount configuration. The problem occurs via a symlink-exchange attack that relies on…
- risk 0.49cvss 7.5epss 0.01
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability exists in homeLYnk (Wiser For KNX) and spaceLYnk V2.60 and prior which could cause a denial of service when an unauthorized file is uploaded.