CWE-22
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
Description
The product uses external input to construct a pathname that is intended to identify a file or directory that is located underneath a restricted parent directory, but the product does not properly neutralize special elements within the pathname that can cause the pathname to resolve to a location that is outside of the restricted directory.
Hierarchy (View 1000)
Related attack patterns (CAPEC)
CAPEC-126 · CAPEC-64 · CAPEC-76 · CAPEC-78 · CAPEC-79
CVEs mapped to this weakness (10,483)
page 269 of 525| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2022-34177 | Hig | 0.42 | 7.5 | 0.02 | Jun 23, 2022 | Jenkins Pipeline: Input Step Plugin 448.v37cea_9a_10a_70 and earlier archives files uploaded for `file` parameters for Pipeline `input` steps on the controller as part of build metadata, using the parameter name without sanitization as a relative path inside a build-related… | ||
| CVE-2022-25856 | Hig | 0.42 | 7.5 | 0.02 | Jun 17, 2022 | The package github.com/argoproj/argo-events/sensors/artifacts before 1.7.1 are vulnerable to Directory Traversal in the (g *GitArtifactReader).Read() API in git.go. This could allow arbitrary file reads if the GitArtifactReader is provided a pathname containing a symbolic link… | ||
| CVE-2022-26041 | Med | 0.42 | 6.5 | 0.02 | Jun 13, 2022 | Directory traversal vulnerability in RCCMD 4.26 and earlier allows a remote authenticated attacker with an administrative privilege to read or alter an arbitrary file on the server via unspecified vectors. | ||
| CVE-2022-24278 | Hig | 0.42 | 7.5 | 0.02 | Jun 10, 2022 | The package convert-svg-core before 0.6.4 are vulnerable to Directory Traversal due to improper sanitization of SVG tags. Exploiting this vulnerability is possible by using a specially crafted SVG file. | ||
| CVE-2022-0779 | Med | 0.42 | 6.5 | 0.02 | Jun 8, 2022 | The User Meta WordPress plugin before 2.4.4 does not validate the filepath parameter of its um_show_uploaded_file AJAX action, which could allow low privileged users such as subscriber to enumerate the local files on the web server via path traversal payloads | ||
| CVE-2022-28478 | Med | 0.42 | 6.5 | 0.02 | Jun 6, 2022 | SeedDMS 6.0.17 and 5.1.24 are vulnerable to Directory Traversal. The "Remove file" functionality inside the "Log files management" menu does not sanitize user input allowing attackers with admin privileges to delete arbitrary files on the remote system. | ||
| CVE-2022-29597 | Med | 0.42 | 6.5 | 0.02 | Jun 2, 2022 | Solutions Atlantic Regulatory Reporting System (RRS) v500 is vulnerable to Local File Inclusion (LFI). Any authenticated user has the ability to reference internal system files within requests made to the RRSWeb/maint/ShowDocument/ShowDocument.aspx page. The server will… | ||
| CVE-2022-30804 | Med | 0.42 | 6.5 | 0.01 | Jun 2, 2022 | elitecms v1.01 is vulnerable to Delete any file via /admin/delete_image.php?file=. | ||
| CVE-2022-23082 | Hig | 0.42 | 7.5 | 0.01 | May 31, 2022 | In CureKit versions v1.0.1 through v1.1.3 are vulnerable to path traversal as the function isFileOutsideDir fails to sanitize the user input which may lead to path traversal. | ||
| CVE-2022-30508 | Med | 0.42 | 6.5 | 0.01 | May 26, 2022 | DedeCMS v5.7.93 was discovered to contain arbitrary file deletion vulnerability in upload.php via the delete parameter. | ||
| CVE-2022-30428 | Hig | 0.42 | 7.5 | 0.01 | May 25, 2022 | In ginadmin through 05-10-2022, the incoming path value is not filtered, resulting in arbitrary file reading. | ||
| CVE-2022-30427 | Hig | 0.42 | 7.5 | 0.02 | May 25, 2022 | In ginadmin through 05-10-2022 the incoming path value is not filtered, resulting in directory traversal. | ||
| CVE-2021-32964 | Med | 0.42 | 6.5 | 0.01 | May 24, 2022 | The AGG Software Web Server version 4.0.40.1014 and prior is vulnerable to a path traversal attack, which may allow an attacker to read arbitrary files from the file system. | ||
| CVE-2022-30948 | Hig | 0.42 | 7.5 | 0.02 | May 17, 2022 | Jenkins Mercurial Plugin 2.16 and earlier allows attackers able to configure pipelines to check out some SCM repositories stored on the Jenkins controller's file system using local paths as SCM URLs, obtaining limited information about other projects' SCM contents. | ||
| CVE-2022-30947 | Hig | 0.42 | 7.5 | 0.01 | May 17, 2022 | Jenkins Git Plugin 4.11.1 and earlier allows attackers able to configure pipelines to check out some SCM repositories stored on the Jenkins controller's file system using local paths as SCM URLs, obtaining limited information about other projects' SCM contents. | ||
| CVE-2022-29332 | Med | 0.42 | 6.5 | 0.01 | May 17, 2022 | D-LINK DIR-825 AC1200 R2 is vulnerable to Directory Traversal. An attacker could use the "../../../../" setting of the FTP server folder to set the router's root folder for FTP access. This allows you to access the entire router file system via the FTP server. | ||
| CVE-2022-1560 | Med | 0.42 | 6.5 | 0.02 | May 16, 2022 | The Amministrazione Aperta WordPress plugin before 3.8 does not validate the open parameter before using it in an include statement, leading to a Local File Inclusion issue. The original advisory mentions that unauthenticated users can exploit this, however the affected file… | ||
| CVE-2022-30062 | Med | 0.42 | 6.5 | 0.01 | May 11, 2022 | ftcms <=2.1 was discovered to be vulnerable to Arbitrary File Read via tp.php | ||
| CVE-2022-30061 | Med | 0.42 | 6.5 | 0.01 | May 11, 2022 | ftcms <=2.1 was discovered to be vulnerable to directory traversal attacks via the parameter tp. | ||
| CVE-2022-30059 | Med | 0.42 | 6.5 | 0.01 | May 11, 2022 | Shopwind <=v3.4.2 was discovered to contain a Arbitrary File Delete vulnerability via the neirong parameter at \backend\controllers\DbController.php. |
- risk 0.42cvss 7.5epss 0.02
Jenkins Pipeline: Input Step Plugin 448.v37cea_9a_10a_70 and earlier archives files uploaded for `file` parameters for Pipeline `input` steps on the controller as part of build metadata, using the parameter name without sanitization as a relative path inside a build-related…
- risk 0.42cvss 7.5epss 0.02
The package github.com/argoproj/argo-events/sensors/artifacts before 1.7.1 are vulnerable to Directory Traversal in the (g *GitArtifactReader).Read() API in git.go. This could allow arbitrary file reads if the GitArtifactReader is provided a pathname containing a symbolic link…
- risk 0.42cvss 6.5epss 0.02
Directory traversal vulnerability in RCCMD 4.26 and earlier allows a remote authenticated attacker with an administrative privilege to read or alter an arbitrary file on the server via unspecified vectors.
- risk 0.42cvss 7.5epss 0.02
The package convert-svg-core before 0.6.4 are vulnerable to Directory Traversal due to improper sanitization of SVG tags. Exploiting this vulnerability is possible by using a specially crafted SVG file.
- risk 0.42cvss 6.5epss 0.02
The User Meta WordPress plugin before 2.4.4 does not validate the filepath parameter of its um_show_uploaded_file AJAX action, which could allow low privileged users such as subscriber to enumerate the local files on the web server via path traversal payloads
- risk 0.42cvss 6.5epss 0.02
SeedDMS 6.0.17 and 5.1.24 are vulnerable to Directory Traversal. The "Remove file" functionality inside the "Log files management" menu does not sanitize user input allowing attackers with admin privileges to delete arbitrary files on the remote system.
- risk 0.42cvss 6.5epss 0.02
Solutions Atlantic Regulatory Reporting System (RRS) v500 is vulnerable to Local File Inclusion (LFI). Any authenticated user has the ability to reference internal system files within requests made to the RRSWeb/maint/ShowDocument/ShowDocument.aspx page. The server will…
- risk 0.42cvss 6.5epss 0.01
elitecms v1.01 is vulnerable to Delete any file via /admin/delete_image.php?file=.
- risk 0.42cvss 7.5epss 0.01
In CureKit versions v1.0.1 through v1.1.3 are vulnerable to path traversal as the function isFileOutsideDir fails to sanitize the user input which may lead to path traversal.
- risk 0.42cvss 6.5epss 0.01
DedeCMS v5.7.93 was discovered to contain arbitrary file deletion vulnerability in upload.php via the delete parameter.
- risk 0.42cvss 7.5epss 0.01
In ginadmin through 05-10-2022, the incoming path value is not filtered, resulting in arbitrary file reading.
- risk 0.42cvss 7.5epss 0.02
In ginadmin through 05-10-2022 the incoming path value is not filtered, resulting in directory traversal.
- risk 0.42cvss 6.5epss 0.01
The AGG Software Web Server version 4.0.40.1014 and prior is vulnerable to a path traversal attack, which may allow an attacker to read arbitrary files from the file system.
- risk 0.42cvss 7.5epss 0.02
Jenkins Mercurial Plugin 2.16 and earlier allows attackers able to configure pipelines to check out some SCM repositories stored on the Jenkins controller's file system using local paths as SCM URLs, obtaining limited information about other projects' SCM contents.
- risk 0.42cvss 7.5epss 0.01
Jenkins Git Plugin 4.11.1 and earlier allows attackers able to configure pipelines to check out some SCM repositories stored on the Jenkins controller's file system using local paths as SCM URLs, obtaining limited information about other projects' SCM contents.
- risk 0.42cvss 6.5epss 0.01
D-LINK DIR-825 AC1200 R2 is vulnerable to Directory Traversal. An attacker could use the "../../../../" setting of the FTP server folder to set the router's root folder for FTP access. This allows you to access the entire router file system via the FTP server.
- risk 0.42cvss 6.5epss 0.02
The Amministrazione Aperta WordPress plugin before 3.8 does not validate the open parameter before using it in an include statement, leading to a Local File Inclusion issue. The original advisory mentions that unauthenticated users can exploit this, however the affected file…
- risk 0.42cvss 6.5epss 0.01
ftcms <=2.1 was discovered to be vulnerable to Arbitrary File Read via tp.php
- risk 0.42cvss 6.5epss 0.01
ftcms <=2.1 was discovered to be vulnerable to directory traversal attacks via the parameter tp.
- risk 0.42cvss 6.5epss 0.01
Shopwind <=v3.4.2 was discovered to contain a Arbitrary File Delete vulnerability via the neirong parameter at \backend\controllers\DbController.php.