CWE-22
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
Description
The product uses external input to construct a pathname that is intended to identify a file or directory that is located underneath a restricted parent directory, but the product does not properly neutralize special elements within the pathname that can cause the pathname to resolve to a location that is outside of the restricted directory.
Hierarchy (View 1000)
Related attack patterns (CAPEC)
CAPEC-126 · CAPEC-64 · CAPEC-76 · CAPEC-78 · CAPEC-79
CVEs mapped to this weakness (10,395)
page 22 of 520| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2023-34880 | Cri | 0.64 | 9.8 | 0.01 | Jun 15, 2023 | cmseasy v7.7.7.7 20230520 was discovered to contain a path traversal vulnerability via the add_action method at lib/admin/language_admin.php. This vulnerability allows attackers to execute arbitrary code and perform a local file inclusion. | ||
| CVE-2023-34865 | Cri | 0.64 | 9.8 | 0.01 | Jun 14, 2023 | Directory traversal vulnerability in ujcms 6.0.2 allows attackers to move files via the rename feature. | ||
| CVE-2023-34409 | Cri | 0.64 | 9.8 | 0.01 | Jun 6, 2023 | In Percona Monitoring and Management (PMM) server 2.x before 2.37.1, the authenticate function in auth_server.go does not properly formalize and sanitize URL paths to reject path traversal attempts. This allows an unauthenticated remote user, when a crafted POST request is made… | ||
| CVE-2023-29736 | Cri | 0.64 | 9.8 | 0.01 | Jun 1, 2023 | Keyboard Themes 1.275.1.164 for Android contains a dictionary traversal vulnerability that allows unauthorized apps to overwrite arbitrary files in its internal storage and achieve arbitrary code execution. | ||
| CVE-2022-47526 | Cri | 0.64 | 9.8 | 0.01 | May 31, 2023 | Fox-IT DataDiode (aka Fox DataDiode) 3.4.3 suffers from a path traversal vulnerability with resultant arbitrary writing of files. A remote attacker could leverage this vulnerability to achieve arbitrary code execution in the context of the downstream node user. Exploitation of… | ||
| CVE-2023-28413 | Cri | 0.64 | 9.8 | 0.02 | May 23, 2023 | Directory traversal vulnerability in Snow Monkey Forms versions v5.0.6 and earlier allows a remote unauthenticated attacker to obtain sensitive information, alter the website, or cause a denial-of-service (DoS) condition. | ||
| CVE-2023-28408 | Cri | 0.64 | 9.8 | 0.02 | May 23, 2023 | Directory traversal vulnerability in MW WP Form versions v4.4.2 and earlier allows a remote unauthenticated attacker to alter the website or cause a denial-of-service (DoS) condition, and obtain sensitive information depending on settings. | ||
| CVE-2023-27507 | Cri | 0.64 | 9.8 | 0.01 | May 23, 2023 | MicroEngine Mailform version 1.1.0 to 1.1.8 contains a path traversal vulnerability. If the product's file upload function and server save option are enabled, a remote attacker may save an arbitrary file on the server and execute it. | ||
| CVE-2020-20012 | Cri | 0.64 | 9.8 | 0.01 | May 23, 2023 | WebPlus Pro v1.4.7.8.4-01 is vulnerable to Incorrect Access Control. | ||
| CVE-2023-30268 | Cri | 0.64 | 9.8 | 0.01 | May 4, 2023 | CLTPHP <=6.0 is vulnerable to Improper Input Validation. | ||
| CVE-2022-47757 | Cri | 0.64 | 9.8 | 0.01 | May 4, 2023 | In imo.im 2022.11.1051, a path traversal vulnerability delivered via an unsanitized deeplink can force the application to write a file into the application's data directory. This may allow an attacker to save a shared library under a special directory which the app uses to… | ||
| CVE-2023-27105 | Cri | 0.64 | 9.8 | 0.01 | Apr 25, 2023 | A vulnerability in the Wi-Fi file transfer module of Shanling M5S Portable Music Player with Shanling MTouch OS v4.3 and Shanling M2X Portable Music Player with Shanling MTouch OS v3.3 allows attackers to arbitrarily read, delete, or modify any critical system files via… | ||
| CVE-2023-27648 | Cri | 0.64 | 9.8 | 0.03 | Apr 14, 2023 | Directory Traversal vulnerability found in T-ME Studios Change Color of Keypad v.1.275.1.277 allows a remote attacker to execute arbitrary code via the dex file in the internal storage. | ||
| CVE-2022-47027 | Cri | 0.64 | 9.8 | 0.01 | Apr 14, 2023 | Timmystudios Fast Typing Keyboard v1.275.1.162 allows unauthorized apps to overwrite arbitrary files in its internal storage via a dictionary traversal vulnerability and achieve arbitrary code execution. | ||
| CVE-2023-1478 | Cri | 0.64 | 9.8 | 0.01 | Apr 10, 2023 | The Hummingbird WordPress plugin before 3.4.2 does not validate the generated file path for page cache files before writing them, leading to a path traversal vulnerability in the page cache module. | ||
| CVE-2023-27603 | Cri | 0.64 | 9.8 | 0.02 | Apr 10, 2023 | In Apache Linkis <=1.3.1, due to the Manager module engineConn material upload does not check the zip path, This is a Zip Slip issue, which will lead to a potential RCE vulnerability. We recommend users upgrade the version of Linkis to version 1.3.2. | ||
| CVE-2023-29478 | Cri | 0.64 | 9.8 | 0.02 | Apr 7, 2023 | BiblioCraft before 2.4.6 does not sanitize path-traversal characters in filenames, allowing restricted write access to almost anywhere on the filesystem. This includes the Minecraft mods folder, which results in code execution. | ||
| CVE-2020-19279 | Cri | 0.64 | 9.8 | 0.01 | Apr 4, 2023 | Directory Traversal vulnerability found in B3log Wide allows a an attacker to escalate privileges via symbolic links. | ||
| CVE-2021-33353 | Cri | 0.64 | 9.8 | 0.02 | Mar 8, 2023 | Directory Traversal vulnerability in Wyomind Help Desk Magento 2 extension v.1.3.6 and before fixed in v.1.3.7 allows attacker to execute arbitrary code via the file attachment directory setting. | ||
| CVE-2023-22336 | Cri | 0.64 | 9.8 | 0.01 | Mar 6, 2023 | Path traversal vulnerability in SS1 Ver.13.0.0.40 and earlier and Rakuraku PC Cloud Agent Ver.2.1.8 and earlier allows a remote attacker to upload a specially crafted file to an arbitrary directory. As a result of exploiting this vulnerability with CVE-2023-22335 and… |
- risk 0.64cvss 9.8epss 0.01
cmseasy v7.7.7.7 20230520 was discovered to contain a path traversal vulnerability via the add_action method at lib/admin/language_admin.php. This vulnerability allows attackers to execute arbitrary code and perform a local file inclusion.
- risk 0.64cvss 9.8epss 0.01
Directory traversal vulnerability in ujcms 6.0.2 allows attackers to move files via the rename feature.
- risk 0.64cvss 9.8epss 0.01
In Percona Monitoring and Management (PMM) server 2.x before 2.37.1, the authenticate function in auth_server.go does not properly formalize and sanitize URL paths to reject path traversal attempts. This allows an unauthenticated remote user, when a crafted POST request is made…
- risk 0.64cvss 9.8epss 0.01
Keyboard Themes 1.275.1.164 for Android contains a dictionary traversal vulnerability that allows unauthorized apps to overwrite arbitrary files in its internal storage and achieve arbitrary code execution.
- risk 0.64cvss 9.8epss 0.01
Fox-IT DataDiode (aka Fox DataDiode) 3.4.3 suffers from a path traversal vulnerability with resultant arbitrary writing of files. A remote attacker could leverage this vulnerability to achieve arbitrary code execution in the context of the downstream node user. Exploitation of…
- risk 0.64cvss 9.8epss 0.02
Directory traversal vulnerability in Snow Monkey Forms versions v5.0.6 and earlier allows a remote unauthenticated attacker to obtain sensitive information, alter the website, or cause a denial-of-service (DoS) condition.
- risk 0.64cvss 9.8epss 0.02
Directory traversal vulnerability in MW WP Form versions v4.4.2 and earlier allows a remote unauthenticated attacker to alter the website or cause a denial-of-service (DoS) condition, and obtain sensitive information depending on settings.
- risk 0.64cvss 9.8epss 0.01
MicroEngine Mailform version 1.1.0 to 1.1.8 contains a path traversal vulnerability. If the product's file upload function and server save option are enabled, a remote attacker may save an arbitrary file on the server and execute it.
- risk 0.64cvss 9.8epss 0.01
WebPlus Pro v1.4.7.8.4-01 is vulnerable to Incorrect Access Control.
- risk 0.64cvss 9.8epss 0.01
CLTPHP <=6.0 is vulnerable to Improper Input Validation.
- risk 0.64cvss 9.8epss 0.01
In imo.im 2022.11.1051, a path traversal vulnerability delivered via an unsanitized deeplink can force the application to write a file into the application's data directory. This may allow an attacker to save a shared library under a special directory which the app uses to…
- risk 0.64cvss 9.8epss 0.01
A vulnerability in the Wi-Fi file transfer module of Shanling M5S Portable Music Player with Shanling MTouch OS v4.3 and Shanling M2X Portable Music Player with Shanling MTouch OS v3.3 allows attackers to arbitrarily read, delete, or modify any critical system files via…
- risk 0.64cvss 9.8epss 0.03
Directory Traversal vulnerability found in T-ME Studios Change Color of Keypad v.1.275.1.277 allows a remote attacker to execute arbitrary code via the dex file in the internal storage.
- risk 0.64cvss 9.8epss 0.01
Timmystudios Fast Typing Keyboard v1.275.1.162 allows unauthorized apps to overwrite arbitrary files in its internal storage via a dictionary traversal vulnerability and achieve arbitrary code execution.
- risk 0.64cvss 9.8epss 0.01
The Hummingbird WordPress plugin before 3.4.2 does not validate the generated file path for page cache files before writing them, leading to a path traversal vulnerability in the page cache module.
- risk 0.64cvss 9.8epss 0.02
In Apache Linkis <=1.3.1, due to the Manager module engineConn material upload does not check the zip path, This is a Zip Slip issue, which will lead to a potential RCE vulnerability. We recommend users upgrade the version of Linkis to version 1.3.2.
- risk 0.64cvss 9.8epss 0.02
BiblioCraft before 2.4.6 does not sanitize path-traversal characters in filenames, allowing restricted write access to almost anywhere on the filesystem. This includes the Minecraft mods folder, which results in code execution.
- risk 0.64cvss 9.8epss 0.01
Directory Traversal vulnerability found in B3log Wide allows a an attacker to escalate privileges via symbolic links.
- risk 0.64cvss 9.8epss 0.02
Directory Traversal vulnerability in Wyomind Help Desk Magento 2 extension v.1.3.6 and before fixed in v.1.3.7 allows attacker to execute arbitrary code via the file attachment directory setting.
- risk 0.64cvss 9.8epss 0.01
Path traversal vulnerability in SS1 Ver.13.0.0.40 and earlier and Rakuraku PC Cloud Agent Ver.2.1.8 and earlier allows a remote attacker to upload a specially crafted file to an arbitrary directory. As a result of exploiting this vulnerability with CVE-2023-22335 and…