CWE-22
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
Description
The product uses external input to construct a pathname that is intended to identify a file or directory that is located underneath a restricted parent directory, but the product does not properly neutralize special elements within the pathname that can cause the pathname to resolve to a location that is outside of the restricted directory.
Hierarchy (View 1000)
Related attack patterns (CAPEC)
CAPEC-126 · CAPEC-64 · CAPEC-76 · CAPEC-78 · CAPEC-79
CVEs mapped to this weakness (10,395)
page 171 of 520| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2020-9353 | Hig | 0.49 | 7.5 | 0.02 | Feb 23, 2020 | An issue was discovered in SmartClient 12.0. The Remote Procedure Call (RPC) loadFile provided by the console functionality on the /tools/developerConsoleOperations.jsp (or /isomorphic/IDACall) URL is affected by unauthenticated Local File Inclusion via directory-traversal… | ||
| CVE-2020-7966 | Hig | 0.49 | 7.5 | 0.02 | Feb 5, 2020 | GitLab EE 11.11 and later through 12.7.2 allows Directory Traversal. | ||
| CVE-2014-5236 | Hig | 0.49 | 7.5 | 0.04 | Jan 31, 2020 | Multiple absolute path traversal vulnerabilities in documentconverter in Open-Xchange (OX) AppSuite before 7.4.2-rev10 and 7.6.x before 7.6.0-rev10 allow remote attackers to read application files via a full pathname in a crafted (1) OLE Object or (2) image in an OpenDocument… | ||
| CVE-2012-6609 | Hig | 0.49 | 7.5 | 0.02 | Jan 28, 2020 | Directory traversal vulnerability in a_getlog.cgi in Polycom HDX Video End Points before 3.0.4 and UC APL before 2.7.1.J allows remote attackers to read arbitrary files via a .. (dot dot) in the name parameter. | ||
| CVE-2014-8742 | Hig | 0.49 | 7.5 | 0.04 | Jan 27, 2020 | Directory traversal vulnerability in the ReportDownloadServlet servlet in Lexmark MarkVision Enterprise before 2.1 allows remote attackers to read arbitrary files via unspecified vectors. | ||
| CVE-2013-6056 | Hig | 0.49 | 7.5 | 0.02 | Jan 27, 2020 | OSSIM before 4.3.3.1 has tele_compress.php path traversal vulnerability | ||
| CVE-2020-8009 | Hig | 0.49 | 7.5 | 0.02 | Jan 27, 2020 | AVB MOTU devices through 2020-01-22 allow /.. Directory Traversal, as demonstrated by reading the /etc/passwd file. | ||
| CVE-2014-1923 | Hig | 0.49 | 7.5 | 0.03 | Jan 24, 2020 | Multiple directory traversal vulnerabilities in the (1) staff interface help editor (edithelp.pl) or (2) member-picupload.pl in Koha before 3.8.23, 3.10.x before 3.10.13, 3.12.x before 3.12.10, and 3.14.x before 3.14.3 allow remote attackers to write to arbitrary files via… | ||
| CVE-2014-1922 | Hig | 0.49 | 7.5 | 0.02 | Jan 24, 2020 | Absolute path traversal vulnerability in tools/pdfViewer.pl in Koha before 3.8.23, 3.10.x before 3.10.13, 3.12.x before 3.12.10, and 3.14.x before 3.14.3 allows remote attackers to read arbitrary files via unspecified vectors. | ||
| CVE-2019-19893 | Hig | 0.49 | 7.5 | 0.03 | Jan 23, 2020 | In IXP EasyInstall 6.2.13723, there is Directory Traversal on TCP port 8000 via the Engine Service by an unauthenticated attacker, who can access the server's filesystem with the access rights of NT AUTHORITY\SYSTEM. | ||
| CVE-2020-7211 | Hig | 0.49 | 7.5 | 0.04 | Jan 21, 2020 | tftp.c in libslirp 4.1.0, as used in QEMU 4.2.0, does not prevent ..\ directory traversal on Windows. | ||
| CVE-2019-14767 | Hig | 0.49 | 7.5 | 0.01 | Jan 21, 2020 | In DIMO YellowBox CRM before 6.3.4, Path Traversal in images/Apparence (dossier=../) and servletrecuperefichier (document=../) allows an unauthenticated user to download arbitrary files from the server. | ||
| CVE-2019-15600 | Hig | 0.49 | 7.5 | 0.03 | Dec 18, 2019 | A Path traversal exists in http_server which allows an attacker to read arbitrary system files. | ||
| CVE-2019-15596 | Hig | 0.49 | 7.5 | 0.02 | Dec 18, 2019 | A path traversal in statics-server exists in all version that allows an attacker to perform a path traversal when a symlink is used within the working directory. | ||
| CVE-2019-19264 | Hig | 0.49 | 7.5 | 0.02 | Dec 17, 2019 | In Simplifile RecordFusion through 2019-11-25, the logs and hist parameters allow remote attackers to access local files via a logger/logs?/../ or logger/hist?/../ URI. | ||
| CVE-2019-14251 | Hig | 0.49 | 7.5 | 0.08 | Dec 9, 2019 | An issue was discovered in T24 in TEMENOS Channels R15.01. The login page presents JavaScript functions to access a document on the server once successfully authenticated. However, an attacker can leverage downloadDocServer() to traverse the file system and access files or… | ||
| CVE-2014-9356 | Hig | 0.49 | 8.6 | 0.05 | Dec 2, 2019 | Path traversal vulnerability in Docker before 1.3.3 allows remote attackers to write to arbitrary files and bypass a container protection mechanism via a full pathname in a symlink in an (1) image or (2) build in a Dockerfile. | ||
| CVE-2019-19372 | Hig | 0.49 | 7.5 | 0.01 | Nov 28, 2019 | A downloadFile.php download_file path traversal vulnerability in rConfig through 3.9.3 allows attackers to list files in arbitrary folders and potentially download files. NOTE: the discoverer later reported that there was not a "fully working exploit. | ||
| CVE-2015-1396 | Hig | 0.49 | 7.5 | 0.03 | Nov 25, 2019 | A Directory Traversal vulnerability exists in the GNU patch before 2.7.4. A remote attacker can write to arbitrary files via a symlink attack in a patch file. NOTE: this issue exists because of an incomplete fix for CVE-2015-1196. | ||
| CVE-2019-13157 | Hig | 0.49 | 7.5 | 0.02 | Nov 22, 2019 | nsGreen.dll in Naver Vaccine 2.1.4 allows remote attackers to overwrite arbitary files via directory traversal sequences in a filename within nsz archive. |
- risk 0.49cvss 7.5epss 0.02
An issue was discovered in SmartClient 12.0. The Remote Procedure Call (RPC) loadFile provided by the console functionality on the /tools/developerConsoleOperations.jsp (or /isomorphic/IDACall) URL is affected by unauthenticated Local File Inclusion via directory-traversal…
- risk 0.49cvss 7.5epss 0.02
GitLab EE 11.11 and later through 12.7.2 allows Directory Traversal.
- risk 0.49cvss 7.5epss 0.04
Multiple absolute path traversal vulnerabilities in documentconverter in Open-Xchange (OX) AppSuite before 7.4.2-rev10 and 7.6.x before 7.6.0-rev10 allow remote attackers to read application files via a full pathname in a crafted (1) OLE Object or (2) image in an OpenDocument…
- risk 0.49cvss 7.5epss 0.02
Directory traversal vulnerability in a_getlog.cgi in Polycom HDX Video End Points before 3.0.4 and UC APL before 2.7.1.J allows remote attackers to read arbitrary files via a .. (dot dot) in the name parameter.
- risk 0.49cvss 7.5epss 0.04
Directory traversal vulnerability in the ReportDownloadServlet servlet in Lexmark MarkVision Enterprise before 2.1 allows remote attackers to read arbitrary files via unspecified vectors.
- risk 0.49cvss 7.5epss 0.02
OSSIM before 4.3.3.1 has tele_compress.php path traversal vulnerability
- risk 0.49cvss 7.5epss 0.02
AVB MOTU devices through 2020-01-22 allow /.. Directory Traversal, as demonstrated by reading the /etc/passwd file.
- risk 0.49cvss 7.5epss 0.03
Multiple directory traversal vulnerabilities in the (1) staff interface help editor (edithelp.pl) or (2) member-picupload.pl in Koha before 3.8.23, 3.10.x before 3.10.13, 3.12.x before 3.12.10, and 3.14.x before 3.14.3 allow remote attackers to write to arbitrary files via…
- risk 0.49cvss 7.5epss 0.02
Absolute path traversal vulnerability in tools/pdfViewer.pl in Koha before 3.8.23, 3.10.x before 3.10.13, 3.12.x before 3.12.10, and 3.14.x before 3.14.3 allows remote attackers to read arbitrary files via unspecified vectors.
- risk 0.49cvss 7.5epss 0.03
In IXP EasyInstall 6.2.13723, there is Directory Traversal on TCP port 8000 via the Engine Service by an unauthenticated attacker, who can access the server's filesystem with the access rights of NT AUTHORITY\SYSTEM.
- risk 0.49cvss 7.5epss 0.04
tftp.c in libslirp 4.1.0, as used in QEMU 4.2.0, does not prevent ..\ directory traversal on Windows.
- risk 0.49cvss 7.5epss 0.01
In DIMO YellowBox CRM before 6.3.4, Path Traversal in images/Apparence (dossier=../) and servletrecuperefichier (document=../) allows an unauthenticated user to download arbitrary files from the server.
- risk 0.49cvss 7.5epss 0.03
A Path traversal exists in http_server which allows an attacker to read arbitrary system files.
- risk 0.49cvss 7.5epss 0.02
A path traversal in statics-server exists in all version that allows an attacker to perform a path traversal when a symlink is used within the working directory.
- risk 0.49cvss 7.5epss 0.02
In Simplifile RecordFusion through 2019-11-25, the logs and hist parameters allow remote attackers to access local files via a logger/logs?/../ or logger/hist?/../ URI.
- risk 0.49cvss 7.5epss 0.08
An issue was discovered in T24 in TEMENOS Channels R15.01. The login page presents JavaScript functions to access a document on the server once successfully authenticated. However, an attacker can leverage downloadDocServer() to traverse the file system and access files or…
- risk 0.49cvss 8.6epss 0.05
Path traversal vulnerability in Docker before 1.3.3 allows remote attackers to write to arbitrary files and bypass a container protection mechanism via a full pathname in a symlink in an (1) image or (2) build in a Dockerfile.
- risk 0.49cvss 7.5epss 0.01
A downloadFile.php download_file path traversal vulnerability in rConfig through 3.9.3 allows attackers to list files in arbitrary folders and potentially download files. NOTE: the discoverer later reported that there was not a "fully working exploit.
- risk 0.49cvss 7.5epss 0.03
A Directory Traversal vulnerability exists in the GNU patch before 2.7.4. A remote attacker can write to arbitrary files via a symlink attack in a patch file. NOTE: this issue exists because of an incomplete fix for CVE-2015-1196.
- risk 0.49cvss 7.5epss 0.02
nsGreen.dll in Naver Vaccine 2.1.4 allows remote attackers to overwrite arbitary files via directory traversal sequences in a filename within nsz archive.