CWE-22
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
Description
The product uses external input to construct a pathname that is intended to identify a file or directory that is located underneath a restricted parent directory, but the product does not properly neutralize special elements within the pathname that can cause the pathname to resolve to a location that is outside of the restricted directory.
Hierarchy (View 1000)
Related attack patterns (CAPEC)
CAPEC-126 · CAPEC-64 · CAPEC-76 · CAPEC-78 · CAPEC-79
CVEs mapped to this weakness (10,483)
page 267 of 525| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2022-37906 | Med | 0.42 | 6.5 | 0.01 | Dec 12, 2022 | An authenticated path traversal vulnerability exists in the ArubaOS command line interface. Successful exploitation of the vulnerability results in the ability to delete arbitrary files on the underlying operating system. | ||
| CVE-2022-41712 | Med | 0.42 | 6.5 | 0.01 | Nov 25, 2022 | Frappe version 14.10.0 allows an external attacker to remotely obtain arbitrary local files. This is possible because the application does not correctly validate the information injected by the user in the import_file parameter. | ||
| CVE-2022-44280 | Med | 0.42 | 6.5 | 0.01 | Nov 23, 2022 | Automotive Shop Management System v1.0 is vulnerable to Delete any file via /asms/classes/Master.php?f=delete_img. | ||
| CVE-2022-44008 | Med | 0.42 | 6.5 | 0.01 | Nov 16, 2022 | An issue was discovered in BACKCLICK Professional 5.9.63. Due to improper validation, arbitrary local files can be retrieved by accessing the back-end Tomcat server directly. | ||
| CVE-2022-34662 | Med | 0.42 | 6.5 | 0.02 | Nov 1, 2022 | When users add resources to the resource center with a relation path will cause path traversal issues and only for logged-in users. You could upgrade to version 3.0.0 or higher | ||
| CVE-2022-40742 | Med | 0.42 | 6.5 | 0.01 | Oct 31, 2022 | Mail SQR Expert system has a Local File Inclusion vulnerability. An unauthenticated remote attacker can exploit this vulnerability to execute arbitrary PHP file with .asp file extension under specific system paths, to access and modify partial system information but does not… | ||
| CVE-2022-39023 | Med | 0.42 | 6.5 | 0.01 | Oct 31, 2022 | U-Office Force Download function has a path traversal vulnerability. A remote attacker with general user privilege can exploit this vulnerability to download arbitrary system file. | ||
| CVE-2022-39022 | Med | 0.42 | 6.5 | 0.01 | Oct 31, 2022 | U-Office Force Download function has a path traversal vulnerability. A remote attacker with general user privilege can exploit this vulnerability to download arbitrary system file. | ||
| CVE-2022-38196 | Med | 0.42 | 6.5 | 0.01 | Oct 25, 2022 | Esri ArcGIS Server versions 10.9.1 and prior have a path traversal vulnerability that may result in a denial of service by allowing a remote, authenticated attacker to overwrite internal ArcGIS Server directory. | ||
| CVE-2022-3389 | Hig | 0.42 | 7.5 | 0.01 | Oct 6, 2022 | Path Traversal in GitHub repository ikus060/rdiffweb prior to 2.4.10. | ||
| CVE-2022-40123 | Med | 0.42 | 6.5 | 0.01 | Oct 3, 2022 | mojoPortal v2.7 was discovered to contain a path traversal vulnerability via the "f" parameter at /DesignTools/CssEditor.aspx. This vulnerability allows authenticated attackers to read arbitrary files in the system. | ||
| CVE-2022-34429 | Med | 0.42 | 6.5 | 0.00 | Sep 30, 2022 | Dell Hybrid Client below 1.8 version contains a Zip Slip Vulnerability in UI. A guest privilege attacker could potentially exploit this vulnerability, leading to system files modification. | ||
| CVE-2022-40082 | Hig | 0.42 | 7.5 | 0.01 | Sep 28, 2022 | Hertz v0.3.0 ws discovered to contain a path traversal vulnerability via the normalizePath function. | ||
| CVE-2022-39261 | Hig | 0.42 | 7.5 | 0.03 | Sep 28, 2022 | Twig is a template language for PHP. Versions 1.x prior to 1.44.7, 2.x prior to 2.15.3, and 3.x prior to 3.4.3 encounter an issue when the filesystem loader loads templates for which the name is a user input. It is possible to use the `source` or `include` statement to read… | ||
| CVE-2022-39034 | Med | 0.42 | 6.5 | 0.01 | Sep 28, 2022 | Smart eVision has a path traversal vulnerability in the Report API function due to insufficient filtering for special characters in URLs. A remote attacker with general user privilege can exploit this vulnerability to bypass authentication, access restricted paths and download… | ||
| CVE-2022-40715 | Med | 0.42 | 6.5 | 0.01 | Sep 19, 2022 | An issue was discovered in NOKIA 1350OMS R14.2. An Absolute Path Traversal vulnerability exists for a specific endpoint via the logfile parameter, allowing a remote authenticated attacker to read files on the filesystem arbitrarily. | ||
| CVE-2022-40713 | Med | 0.42 | 6.5 | 0.01 | Sep 19, 2022 | An issue was discovered in NOKIA 1350OMS R14.2. Multiple Relative Path Traversal issues exist in different specific endpoints via the file parameter, allowing a remote authenticated attacker to read files on the filesystem arbitrarily. | ||
| CVE-2022-34002 | Med | 0.42 | 6.5 | 0.01 | Sep 16, 2022 | The ‘document’ parameter of PDS Vista 7’s /application/documents/display.aspx page is vulnerable to a Local File Inclusion vulnerability which allows an low-privileged authenticated attacker to leak the configuration files and source code of the web application. | ||
| CVE-2022-32190 | Hig | 0.42 | 7.5 | 0.02 | Sep 13, 2022 | JoinPath and URL.JoinPath do not remove ../ path elements appended to a relative path. For example, JoinPath("https://go.dev", "../go") returns the URL "https://go.dev/../go", despite the JoinPath documentation stating that ../ path elements are removed from the result. | ||
| CVE-2022-38613 | Med | 0.42 | 6.5 | 0.01 | Sep 9, 2022 | A Path Traversal vulnerability in SmartVista Cardgen v3.28.0 allows authenticated attackers to read arbitrary files in the system. |
- risk 0.42cvss 6.5epss 0.01
An authenticated path traversal vulnerability exists in the ArubaOS command line interface. Successful exploitation of the vulnerability results in the ability to delete arbitrary files on the underlying operating system.
- risk 0.42cvss 6.5epss 0.01
Frappe version 14.10.0 allows an external attacker to remotely obtain arbitrary local files. This is possible because the application does not correctly validate the information injected by the user in the import_file parameter.
- risk 0.42cvss 6.5epss 0.01
Automotive Shop Management System v1.0 is vulnerable to Delete any file via /asms/classes/Master.php?f=delete_img.
- risk 0.42cvss 6.5epss 0.01
An issue was discovered in BACKCLICK Professional 5.9.63. Due to improper validation, arbitrary local files can be retrieved by accessing the back-end Tomcat server directly.
- risk 0.42cvss 6.5epss 0.02
When users add resources to the resource center with a relation path will cause path traversal issues and only for logged-in users. You could upgrade to version 3.0.0 or higher
- risk 0.42cvss 6.5epss 0.01
Mail SQR Expert system has a Local File Inclusion vulnerability. An unauthenticated remote attacker can exploit this vulnerability to execute arbitrary PHP file with .asp file extension under specific system paths, to access and modify partial system information but does not…
- risk 0.42cvss 6.5epss 0.01
U-Office Force Download function has a path traversal vulnerability. A remote attacker with general user privilege can exploit this vulnerability to download arbitrary system file.
- risk 0.42cvss 6.5epss 0.01
U-Office Force Download function has a path traversal vulnerability. A remote attacker with general user privilege can exploit this vulnerability to download arbitrary system file.
- risk 0.42cvss 6.5epss 0.01
Esri ArcGIS Server versions 10.9.1 and prior have a path traversal vulnerability that may result in a denial of service by allowing a remote, authenticated attacker to overwrite internal ArcGIS Server directory.
- risk 0.42cvss 7.5epss 0.01
Path Traversal in GitHub repository ikus060/rdiffweb prior to 2.4.10.
- risk 0.42cvss 6.5epss 0.01
mojoPortal v2.7 was discovered to contain a path traversal vulnerability via the "f" parameter at /DesignTools/CssEditor.aspx. This vulnerability allows authenticated attackers to read arbitrary files in the system.
- risk 0.42cvss 6.5epss 0.00
Dell Hybrid Client below 1.8 version contains a Zip Slip Vulnerability in UI. A guest privilege attacker could potentially exploit this vulnerability, leading to system files modification.
- risk 0.42cvss 7.5epss 0.01
Hertz v0.3.0 ws discovered to contain a path traversal vulnerability via the normalizePath function.
- risk 0.42cvss 7.5epss 0.03
Twig is a template language for PHP. Versions 1.x prior to 1.44.7, 2.x prior to 2.15.3, and 3.x prior to 3.4.3 encounter an issue when the filesystem loader loads templates for which the name is a user input. It is possible to use the `source` or `include` statement to read…
- risk 0.42cvss 6.5epss 0.01
Smart eVision has a path traversal vulnerability in the Report API function due to insufficient filtering for special characters in URLs. A remote attacker with general user privilege can exploit this vulnerability to bypass authentication, access restricted paths and download…
- risk 0.42cvss 6.5epss 0.01
An issue was discovered in NOKIA 1350OMS R14.2. An Absolute Path Traversal vulnerability exists for a specific endpoint via the logfile parameter, allowing a remote authenticated attacker to read files on the filesystem arbitrarily.
- risk 0.42cvss 6.5epss 0.01
An issue was discovered in NOKIA 1350OMS R14.2. Multiple Relative Path Traversal issues exist in different specific endpoints via the file parameter, allowing a remote authenticated attacker to read files on the filesystem arbitrarily.
- risk 0.42cvss 6.5epss 0.01
The ‘document’ parameter of PDS Vista 7’s /application/documents/display.aspx page is vulnerable to a Local File Inclusion vulnerability which allows an low-privileged authenticated attacker to leak the configuration files and source code of the web application.
- risk 0.42cvss 7.5epss 0.02
JoinPath and URL.JoinPath do not remove ../ path elements appended to a relative path. For example, JoinPath("https://go.dev", "../go") returns the URL "https://go.dev/../go", despite the JoinPath documentation stating that ../ path elements are removed from the result.
- risk 0.42cvss 6.5epss 0.01
A Path Traversal vulnerability in SmartVista Cardgen v3.28.0 allows authenticated attackers to read arbitrary files in the system.