CWE-22
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
Description
The product uses external input to construct a pathname that is intended to identify a file or directory that is located underneath a restricted parent directory, but the product does not properly neutralize special elements within the pathname that can cause the pathname to resolve to a location that is outside of the restricted directory.
Hierarchy (View 1000)
Related attack patterns (CAPEC)
CAPEC-126 · CAPEC-64 · CAPEC-76 · CAPEC-78 · CAPEC-79
CVEs mapped to this weakness (10,395)
page 173 of 520| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2016-10966 | Hig | 0.49 | 7.5 | 0.03 | Sep 16, 2019 | The real3d-flipbook-lite plugin 1.0 for WordPress has bookName=../ directory traversal for file upload. | ||
| CVE-2016-10965 | Hig | 0.49 | 7.5 | 0.02 | Sep 16, 2019 | The real3d-flipbook-lite plugin 1.0 for WordPress has deleteBook=../ directory traversal for file deletion. | ||
| CVE-2019-13532 | Hig | 0.49 | 7.5 | 0.03 | Sep 13, 2019 | CODESYS V3 web server, all versions prior to 3.5.14.10, allows an attacker to send specially crafted http or https requests which may allow access to files outside the restricted working directory of the controller. | ||
| CVE-2019-12464 | Hig | 0.49 | 7.5 | 0.02 | Sep 9, 2019 | An issue was discovered in LibreNMS 1.50.1. An authenticated user can perform a directory traversal attack against the /pdf.php file with a partial filename in the report parameter, to cause local file inclusion resulting in code execution. | ||
| CVE-2019-15839 | Hig | 0.49 | 7.5 | 0.02 | Aug 30, 2019 | The sina-extension-for-elementor plugin before 2.2.1 for WordPress has local file inclusion. | ||
| CVE-2019-15630 | Hig | 0.49 | 7.5 | 0.03 | Aug 30, 2019 | Directory Traversal in APIkit, HTTP connector, and OAuth2 Provider components in MuleSoft Mule Runtime 3.2.0 and higher released before August 1 2019, MuleSoft Mule Runtime 4.1.0 and higher released before August 1 2019, and all versions of MuleSoft API Gateway released before… | ||
| CVE-2019-6113 | Hig | 0.49 | 7.5 | 0.03 | Aug 30, 2019 | Directory traversal vulnerability on ONKYO TX-NR686 1030-5000-1040-0010 A/V Receiver devices allows remote attackers to read arbitrary files via a .. (dot dot) and %2f to the default URI. | ||
| CVE-2019-13408 | Hig | 0.49 | 7.5 | 0.02 | Aug 29, 2019 | A relative path traversal vulnerability found in Advan VD-1 firmware versions up to 230. It allows attackers to download arbitrary files via url cgibin/ExportSettings.cgi?Download=filepath, without any authentication. | ||
| CVE-2019-11654 | Hig | 0.49 | 7.5 | 0.03 | Aug 23, 2019 | Path traversal vulnerability in Micro Focus Verastream Host Integrator (VHI), versions 7.7 SP2 and earlier, The vulnerability allows remote unauthenticated attackers to read arbitrary files. | ||
| CVE-2019-15326 | Hig | 0.49 | 7.5 | 0.02 | Aug 22, 2019 | The import-users-from-csv-with-meta plugin before 1.14.2.1 for WordPress has directory traversal. | ||
| CVE-2019-11029 | Hig | 0.49 | 7.5 | 0.02 | Aug 22, 2019 | Mirasys VMS before V7.6.1 and 8.x before V8.3.2 mishandles the Download() method of AutoUpdateService in SMServer.exe, leading to Directory Traversal. An attacker could use ..\ with this method to iterate over lists of interesting system files and download them without previous… | ||
| CVE-2019-15323 | Hig | 0.49 | 7.5 | 0.02 | Aug 22, 2019 | The ad-inserter plugin before 2.4.20 for WordPress has path traversal. | ||
| CVE-2019-11603 | Hig | 0.49 | 7.5 | 0.02 | Aug 21, 2019 | A HTTP Traversal Attack in earlier versions than ProSyst mBS SDK 8.2.6 and Bosch IoT Gateway Software 9.0.2 allows remote attackers to read files outside the http root. | ||
| CVE-2019-11601 | Hig | 0.49 | 7.5 | 0.03 | Aug 21, 2019 | A directory traversal vulnerability in remote access to backup & restore in earlier versions than ProSyst mBS SDK 8.2.6 and Bosch IoT Gateway Software 9.2.0 allows remote attackers to write or delete files at any location. | ||
| CVE-2019-4460 | Hig | 0.49 | 7.5 | 0.03 | Aug 20, 2019 | IBM API Connect 5.0.0.0 through 5.0.8.6 developer portal could allow a remote attacker to traverse directories on the system. An attacker could send a specially-crafted URL request containing "dot dot" sequences (/../) to view arbitrary files on the system. IBM X-Force ID:… | ||
| CVE-2019-14701 | Hig | 0.49 | 7.5 | 0.02 | Aug 6, 2019 | An issue was discovered on MicroDigital N-series cameras with firmware through 6400.0.8.5. An attacker can trigger read operations on an arbitrary file via Path Traversal in the TZ parameter, but cannot retrieve the data that is read. This causes a denial of service if the… | ||
| CVE-2019-14700 | Hig | 0.49 | 7.5 | 0.02 | Aug 6, 2019 | An issue was discovered on MicroDigital N-series cameras with firmware through 6400.0.8.5. There is disclosure of the existence of arbitrary files via Path Traversal in HTTPD. This occurs because the filename specified in the TZ parameter is accessed with a substantial delay if… | ||
| CVE-2019-14521 | Hig | 0.49 | 7.5 | 0.02 | Aug 5, 2019 | The api/admin/logoupload Logo File upload feature in EMCA Energy Logserver 6.1.2 allows attackers to send any kind of file to any location on the server via path traversal in the filename parameter. | ||
| CVE-2019-1020001 | Hig | 0.49 | 7.5 | 0.02 | Jul 29, 2019 | yard before 0.9.20 allows path traversal. | ||
| CVE-2019-10265 | Hig | 0.49 | 7.5 | 0.03 | Jul 26, 2019 | An issue was discovered in Ahsay Cloud Backup Suite before 8.1.1.50. On the /cbs/system/ShowAdvanced.do "File Explorer" screen, it is possible to change the directory in the JavaScript code. If changed to (for example) "C:" then one can browse the whole server. |
- risk 0.49cvss 7.5epss 0.03
The real3d-flipbook-lite plugin 1.0 for WordPress has bookName=../ directory traversal for file upload.
- risk 0.49cvss 7.5epss 0.02
The real3d-flipbook-lite plugin 1.0 for WordPress has deleteBook=../ directory traversal for file deletion.
- risk 0.49cvss 7.5epss 0.03
CODESYS V3 web server, all versions prior to 3.5.14.10, allows an attacker to send specially crafted http or https requests which may allow access to files outside the restricted working directory of the controller.
- risk 0.49cvss 7.5epss 0.02
An issue was discovered in LibreNMS 1.50.1. An authenticated user can perform a directory traversal attack against the /pdf.php file with a partial filename in the report parameter, to cause local file inclusion resulting in code execution.
- risk 0.49cvss 7.5epss 0.02
The sina-extension-for-elementor plugin before 2.2.1 for WordPress has local file inclusion.
- risk 0.49cvss 7.5epss 0.03
Directory Traversal in APIkit, HTTP connector, and OAuth2 Provider components in MuleSoft Mule Runtime 3.2.0 and higher released before August 1 2019, MuleSoft Mule Runtime 4.1.0 and higher released before August 1 2019, and all versions of MuleSoft API Gateway released before…
- risk 0.49cvss 7.5epss 0.03
Directory traversal vulnerability on ONKYO TX-NR686 1030-5000-1040-0010 A/V Receiver devices allows remote attackers to read arbitrary files via a .. (dot dot) and %2f to the default URI.
- risk 0.49cvss 7.5epss 0.02
A relative path traversal vulnerability found in Advan VD-1 firmware versions up to 230. It allows attackers to download arbitrary files via url cgibin/ExportSettings.cgi?Download=filepath, without any authentication.
- risk 0.49cvss 7.5epss 0.03
Path traversal vulnerability in Micro Focus Verastream Host Integrator (VHI), versions 7.7 SP2 and earlier, The vulnerability allows remote unauthenticated attackers to read arbitrary files.
- risk 0.49cvss 7.5epss 0.02
The import-users-from-csv-with-meta plugin before 1.14.2.1 for WordPress has directory traversal.
- risk 0.49cvss 7.5epss 0.02
Mirasys VMS before V7.6.1 and 8.x before V8.3.2 mishandles the Download() method of AutoUpdateService in SMServer.exe, leading to Directory Traversal. An attacker could use ..\ with this method to iterate over lists of interesting system files and download them without previous…
- risk 0.49cvss 7.5epss 0.02
The ad-inserter plugin before 2.4.20 for WordPress has path traversal.
- risk 0.49cvss 7.5epss 0.02
A HTTP Traversal Attack in earlier versions than ProSyst mBS SDK 8.2.6 and Bosch IoT Gateway Software 9.0.2 allows remote attackers to read files outside the http root.
- risk 0.49cvss 7.5epss 0.03
A directory traversal vulnerability in remote access to backup & restore in earlier versions than ProSyst mBS SDK 8.2.6 and Bosch IoT Gateway Software 9.2.0 allows remote attackers to write or delete files at any location.
- risk 0.49cvss 7.5epss 0.03
IBM API Connect 5.0.0.0 through 5.0.8.6 developer portal could allow a remote attacker to traverse directories on the system. An attacker could send a specially-crafted URL request containing "dot dot" sequences (/../) to view arbitrary files on the system. IBM X-Force ID:…
- risk 0.49cvss 7.5epss 0.02
An issue was discovered on MicroDigital N-series cameras with firmware through 6400.0.8.5. An attacker can trigger read operations on an arbitrary file via Path Traversal in the TZ parameter, but cannot retrieve the data that is read. This causes a denial of service if the…
- risk 0.49cvss 7.5epss 0.02
An issue was discovered on MicroDigital N-series cameras with firmware through 6400.0.8.5. There is disclosure of the existence of arbitrary files via Path Traversal in HTTPD. This occurs because the filename specified in the TZ parameter is accessed with a substantial delay if…
- risk 0.49cvss 7.5epss 0.02
The api/admin/logoupload Logo File upload feature in EMCA Energy Logserver 6.1.2 allows attackers to send any kind of file to any location on the server via path traversal in the filename parameter.
- risk 0.49cvss 7.5epss 0.02
yard before 0.9.20 allows path traversal.
- risk 0.49cvss 7.5epss 0.03
An issue was discovered in Ahsay Cloud Backup Suite before 8.1.1.50. On the /cbs/system/ShowAdvanced.do "File Explorer" screen, it is possible to change the directory in the JavaScript code. If changed to (for example) "C:" then one can browse the whole server.