CWE-22
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
Description
The product uses external input to construct a pathname that is intended to identify a file or directory that is located underneath a restricted parent directory, but the product does not properly neutralize special elements within the pathname that can cause the pathname to resolve to a location that is outside of the restricted directory.
Hierarchy (View 1000)
Related attack patterns (CAPEC)
CAPEC-126 · CAPEC-64 · CAPEC-76 · CAPEC-78 · CAPEC-79
CVEs mapped to this weakness (10,395)
page 172 of 520| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2013-3311 | Hig | 0.49 | 7.5 | 0.04 | Nov 21, 2019 | Directory traversal vulnerability in the Loftek Nexus 543 IP Camera allows remote attackers to read arbitrary files via a .. (dot dot) in the URL of an HTTP GET request. | ||
| CVE-2019-15004 | Hig | 0.49 | 7.5 | 0.04 | Nov 7, 2019 | The Customer Context Filter in Atlassian Jira Service Desk Server and Jira Service Desk Data Center before 3.9.17, from 3.10.0 before 3.16.10, from 4.0.0 before 4.2.6, from 4.3.0 before 4.3.5, from 4.4.0 before 4.4.3, and from 4.5.0 before 4.5.1 allows remote attackers with… | ||
| CVE-2005-2349 | Hig | 0.49 | 7.5 | 0.02 | Oct 28, 2019 | Zoo 2.10 has Directory traversal | ||
| CVE-2019-8238 | Hig | 0.49 | 7.5 | 0.05 | Oct 23, 2019 | Adobe Acrobat and Reader versions 2019.010.20100 and earlier; 2019.010.20099 and earlier versions; 2017.011.30140 and earlier version; 2017.011.30138 and earlier version; 2015.006.30495 and earlier versions; 2015.006.30493 and earlier versions have a Path Traversal… | ||
| CVE-2019-17537 | Hig | 0.49 | 7.5 | 0.02 | Oct 13, 2019 | Jiangnan Online Judge (aka jnoj) 0.8.0 has Directory Traversal for file deletion via the web/polygon/problem/deletefile?id=1&name=../ substring. | ||
| CVE-2010-5335 | Hig | 0.49 | 7.5 | 0.03 | Oct 11, 2019 | IceWarp Webclient before 10.2.1 has a directory traversal vulnerability. This can result in loss of confidential data of IceWarp Mailserver and the operating system. Input passed via a certain parameter (script to basic/minimizer/index.php) is not properly sanitised and can… | ||
| CVE-2010-5334 | Hig | 0.49 | 7.5 | 0.03 | Oct 11, 2019 | IceWarp Webclient before 10.2.1 has a directory traversal vulnerability. This can result in loss of confidential data of IceWarp Mailserver and the operating system. Input passed via a certain parameter (_c to basic/index.html) is not properly sanitised and can therefore be… | ||
| CVE-2015-9473 | Hig | 0.49 | 7.5 | 0.04 | Oct 10, 2019 | The estrutura-basica theme through 2015-09-13 for WordPress has directory traversal via the scripts/download.php arquivo parameter. | ||
| CVE-2015-9470 | Hig | 0.49 | 7.5 | 0.04 | Oct 10, 2019 | The history-collection plugin through 1.1.1 for WordPress has directory traversal via the download.php var parameter. | ||
| CVE-2015-9463 | Hig | 0.49 | 7.5 | 0.04 | Oct 10, 2019 | The s3bubble-amazon-s3-audio-streaming plugin 2.0 for WordPress has directory traversal via the adverts/assets/plugins/ultimate/content/downloader.php path parameter. | ||
| CVE-2015-9464 | Hig | 0.49 | 7.5 | 0.04 | Oct 10, 2019 | The s3bubble-amazon-s3-html-5-video-with-adverts plugin 0.7 for WordPress has directory traversal via the adverts/assets/plugins/ultimate/content/downloader.php path parameter. | ||
| CVE-2019-17175 | Hig | 0.49 | 7.5 | 0.02 | Oct 4, 2019 | joyplus-cms 1.6.0 allows manager/admin_pic.php?rootpath= absolute path traversal. | ||
| CVE-2019-13343 | Hig | 0.49 | 7.5 | 0.02 | Oct 2, 2019 | Butor Portal before 1.0.27 is affected by a Path Traversal vulnerability leading to a pre-authentication arbitrary file download. Effectively, a remote anonymous user can download any file on servers running Butor Portal. WhiteLabelingServlet is responsible for this… | ||
| CVE-2019-8291 | Hig | 0.49 | 7.5 | 0.01 | Oct 1, 2019 | Online Store System v1.0 delete_file.php doesn't check to see if a user has administrative rights nor does it check for path traversal. | ||
| CVE-2017-18636 | Hig | 0.49 | 7.5 | 0.02 | Sep 30, 2019 | CDG through 2017-01-01 allows downloadDocument.jsp?command=download&pathAndName= directory traversal. | ||
| CVE-2019-9281 | Hig | 0.49 | 7.5 | 0.01 | Sep 27, 2019 | In GoogleContactsSyncAdapter, there is a possible path traversal due to improper input sanitization. This could lead to a bypass of user interaction requirements with no additional execution privileges needed. User interaction is not needed for exploitation. Product:… | ||
| CVE-2014-10397 | Hig | 0.49 | 7.5 | 0.03 | Sep 20, 2019 | The Antioch theme through 2014-09-07 for WordPress allows arbitrary file downloads via the file parameter to lib/scripts/download.php. | ||
| CVE-2014-10396 | Hig | 0.49 | 7.5 | 0.03 | Sep 20, 2019 | The epic theme through 2014-09-07 for WordPress allows arbitrary file downloads via the file parameter to includes/download.php. | ||
| CVE-2019-14994 | Hig | 0.49 | 7.5 | 0.06 | Sep 19, 2019 | The Customer Context Filter in Atlassian Jira Service Desk Server and Jira Service Desk Data Center before version 3.9.16, from version 3.10.0 before version 3.16.8, from version 4.0.0 before version 4.1.3, from version 4.2.0 before version 4.2.5, from version 4.3.0 before… | ||
| CVE-2019-0207 | Hig | 0.49 | 7.5 | 0.03 | Sep 16, 2019 | Tapestry processes assets `/assets/ctx` using classes chain `StaticFilesFilter -> AssetDispatcher -> ContextResource`, which doesn't filter the character `\`, so attacker can perform a path traversal attack to read any files on Windows platform. |
- risk 0.49cvss 7.5epss 0.04
Directory traversal vulnerability in the Loftek Nexus 543 IP Camera allows remote attackers to read arbitrary files via a .. (dot dot) in the URL of an HTTP GET request.
- risk 0.49cvss 7.5epss 0.04
The Customer Context Filter in Atlassian Jira Service Desk Server and Jira Service Desk Data Center before 3.9.17, from 3.10.0 before 3.16.10, from 4.0.0 before 4.2.6, from 4.3.0 before 4.3.5, from 4.4.0 before 4.4.3, and from 4.5.0 before 4.5.1 allows remote attackers with…
- risk 0.49cvss 7.5epss 0.02
Zoo 2.10 has Directory traversal
- risk 0.49cvss 7.5epss 0.05
Adobe Acrobat and Reader versions 2019.010.20100 and earlier; 2019.010.20099 and earlier versions; 2017.011.30140 and earlier version; 2017.011.30138 and earlier version; 2015.006.30495 and earlier versions; 2015.006.30493 and earlier versions have a Path Traversal…
- risk 0.49cvss 7.5epss 0.02
Jiangnan Online Judge (aka jnoj) 0.8.0 has Directory Traversal for file deletion via the web/polygon/problem/deletefile?id=1&name=../ substring.
- risk 0.49cvss 7.5epss 0.03
IceWarp Webclient before 10.2.1 has a directory traversal vulnerability. This can result in loss of confidential data of IceWarp Mailserver and the operating system. Input passed via a certain parameter (script to basic/minimizer/index.php) is not properly sanitised and can…
- risk 0.49cvss 7.5epss 0.03
IceWarp Webclient before 10.2.1 has a directory traversal vulnerability. This can result in loss of confidential data of IceWarp Mailserver and the operating system. Input passed via a certain parameter (_c to basic/index.html) is not properly sanitised and can therefore be…
- risk 0.49cvss 7.5epss 0.04
The estrutura-basica theme through 2015-09-13 for WordPress has directory traversal via the scripts/download.php arquivo parameter.
- risk 0.49cvss 7.5epss 0.04
The history-collection plugin through 1.1.1 for WordPress has directory traversal via the download.php var parameter.
- risk 0.49cvss 7.5epss 0.04
The s3bubble-amazon-s3-audio-streaming plugin 2.0 for WordPress has directory traversal via the adverts/assets/plugins/ultimate/content/downloader.php path parameter.
- risk 0.49cvss 7.5epss 0.04
The s3bubble-amazon-s3-html-5-video-with-adverts plugin 0.7 for WordPress has directory traversal via the adverts/assets/plugins/ultimate/content/downloader.php path parameter.
- risk 0.49cvss 7.5epss 0.02
joyplus-cms 1.6.0 allows manager/admin_pic.php?rootpath= absolute path traversal.
- risk 0.49cvss 7.5epss 0.02
Butor Portal before 1.0.27 is affected by a Path Traversal vulnerability leading to a pre-authentication arbitrary file download. Effectively, a remote anonymous user can download any file on servers running Butor Portal. WhiteLabelingServlet is responsible for this…
- risk 0.49cvss 7.5epss 0.01
Online Store System v1.0 delete_file.php doesn't check to see if a user has administrative rights nor does it check for path traversal.
- risk 0.49cvss 7.5epss 0.02
CDG through 2017-01-01 allows downloadDocument.jsp?command=download&pathAndName= directory traversal.
- risk 0.49cvss 7.5epss 0.01
In GoogleContactsSyncAdapter, there is a possible path traversal due to improper input sanitization. This could lead to a bypass of user interaction requirements with no additional execution privileges needed. User interaction is not needed for exploitation. Product:…
- risk 0.49cvss 7.5epss 0.03
The Antioch theme through 2014-09-07 for WordPress allows arbitrary file downloads via the file parameter to lib/scripts/download.php.
- risk 0.49cvss 7.5epss 0.03
The epic theme through 2014-09-07 for WordPress allows arbitrary file downloads via the file parameter to includes/download.php.
- risk 0.49cvss 7.5epss 0.06
The Customer Context Filter in Atlassian Jira Service Desk Server and Jira Service Desk Data Center before version 3.9.16, from version 3.10.0 before version 3.16.8, from version 4.0.0 before version 4.1.3, from version 4.2.0 before version 4.2.5, from version 4.3.0 before…
- risk 0.49cvss 7.5epss 0.03
Tapestry processes assets `/assets/ctx` using classes chain `StaticFilesFilter -> AssetDispatcher -> ContextResource`, which doesn't filter the character `\`, so attacker can perform a path traversal attack to read any files on Windows platform.