CWE-22
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
Description
The product uses external input to construct a pathname that is intended to identify a file or directory that is located underneath a restricted parent directory, but the product does not properly neutralize special elements within the pathname that can cause the pathname to resolve to a location that is outside of the restricted directory.
Hierarchy (View 1000)
Related attack patterns (CAPEC)
CAPEC-126 · CAPEC-64 · CAPEC-76 · CAPEC-78 · CAPEC-79
CVEs mapped to this weakness (10,395)
page 27 of 520| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2020-10564 | Cri | 0.64 | 9.8 | 0.09 | Mar 13, 2020 | An issue was discovered in the File Upload plugin before 4.13.0 for WordPress. A directory traversal can lead to remote code execution by uploading a crafted txt file into the lib directory, because of a wfu_include_lib call. | ||
| CVE-2019-12182 | Cri | 0.64 | 9.8 | 0.05 | Mar 13, 2020 | Directory Traversal in Safescan Timemoto and TA-8000 series version 1.0 allows unauthenticated remote attackers to execute code via the administrative API. | ||
| CVE-2020-8803 | Cri | 0.64 | 9.8 | 0.03 | Feb 13, 2020 | SuiteCRM through 7.11.11 allows Directory Traversal to include arbitrary .php files within the webroot via add_to_prospect_list. | ||
| CVE-2015-5952 | Cri | 0.64 | 9.8 | 0.03 | Jan 15, 2020 | Directory traversal vulnerability in Thomson Reuters for FATCA before 5.2 allows remote attackers to execute arbitrary files via the item parameter. | ||
| CVE-2019-19628 | Cri | 0.64 | 9.8 | 0.04 | Jan 5, 2020 | In GitLab EE 11.3 through 12.5.3, 12.4.5, and 12.3.8, insufficient parameter sanitization for the Maven package registry could lead to privilege escalation and remote code execution vulnerabilities under certain conditions. | ||
| CVE-2019-11994 | Cri | 0.64 | 9.8 | 0.07 | Jan 3, 2020 | A security vulnerability has been identified in HPE SimpliVity 380 Gen 9, HPE SimpliVity 380 Gen 10, HPE SimpliVity 380 Gen 10 G, HPE SimpliVity 2600 Gen 10, SimpliVity OmniCube, SimpliVity OmniStack for Cisco, SimpliVity OmniStack for Lenovo and SimpliVity OmniStack for Dell… | ||
| CVE-2019-19088 | Cri | 0.64 | 9.8 | 0.02 | Jan 3, 2020 | Gitlab Enterprise Edition (EE) 11.3 through 12.4.2 allows Directory Traversal. | ||
| CVE-2019-19790 | Cri | 0.64 | 9.8 | 0.03 | Dec 13, 2019 | Path traversal in RadChart in Telerik UI for ASP.NET AJAX allows a remote attacker to read and delete an image with extension .BMP, .EXIF, .GIF, .ICON, .JPEG, .PNG, .TIFF, or .WMF on the server through a specially crafted request. NOTE: RadChart was discontinued in 2014 in favor… | ||
| CVE-2019-16246 | Cri | 0.64 | 9.8 | 0.03 | Dec 12, 2019 | Intesync Solismed 3.3sp1 allows Local File Inclusion (LFI), a different vulnerability than CVE-2019-15931. This leads to unauthenticated code execution. | ||
| CVE-2019-15931 | Cri | 0.64 | 9.8 | 0.03 | Dec 12, 2019 | Intesync Solismed 3.3sp allows Directory Traversal, a different vulnerability than CVE-2019-16246. | ||
| CVE-2019-19459 | Cri | 0.64 | 9.8 | 0.04 | Dec 3, 2019 | An issue was discovered in SALTO ProAccess SPACE 5.4.3.0. An attacker can write arbitrary content to arbitrary files, as demonstrated by CVE-2019-19458 files under the web root, or .bat files that will be used with auto start. This allows an attacker to execute arbitrary… | ||
| CVE-2013-3073 | Cri | 0.64 | 9.8 | 0.04 | Nov 14, 2019 | A Symlink Traversal vulnerability exists in NETGEAR Centria WNDR4700 Firmware 1.0.0.34. | ||
| CVE-2013-4657 | Cri | 0.64 | 9.8 | 0.02 | Nov 13, 2019 | Symlink Traversal vulnerability in NETGEAR WNR3500U and WNR3500L due to misconfiguration in the SMB service. | ||
| CVE-2013-4654 | Cri | 0.64 | 9.8 | 0.03 | Nov 13, 2019 | Symlink Traversal vulnerability in TP-LINK TL-WDR4300 and TL-1043ND.. | ||
| CVE-2013-4656 | Cri | 0.64 | 9.8 | 0.02 | Nov 13, 2019 | Symlink Traversal vulnerability in ASUS RT-AC66U and RT-N56U due to misconfiguration in the SMB service. | ||
| CVE-2019-13551 | Cri | 0.64 | 9.8 | 0.05 | Oct 31, 2019 | Advantech WISE-PaaS/RMM, Versions 3.3.29 and prior. Path traversal vulnerabilities are caused by a lack of proper validation of a user-supplied path prior to use in file operations. An attacker can leverage these vulnerabilities to remotely execute code while posing as an… | ||
| CVE-2009-3887 | Cri | 0.64 | 9.8 | 0.03 | Oct 29, 2019 | ytnef has directory traversal | ||
| CVE-2019-18189 | Cri | 0.64 | 9.8 | 0.05 | Oct 28, 2019 | A directory traversal vulnerability in Trend Micro Apex One, OfficeScan (11.0, XG) and Worry-Free Business Security (9.5, 10.0) may allow an attacker to bypass authentication and log on to an affected product's management console as a root user. The vulnerability does not… | ||
| CVE-2013-4658 | Cri | 0.64 | 9.8 | 0.09 | Oct 25, 2019 | Linksys EA6500 has SMB Symlink Traversal allowing symbolic links to be created to locations outside of the Samba share. | ||
| CVE-2019-17399 | Cri | 0.64 | 9.8 | 0.02 | Oct 9, 2019 | The Shack Forms Pro extension before 4.0.32 for Joomla! allows path traversal via a file attachment. |
- risk 0.64cvss 9.8epss 0.09
An issue was discovered in the File Upload plugin before 4.13.0 for WordPress. A directory traversal can lead to remote code execution by uploading a crafted txt file into the lib directory, because of a wfu_include_lib call.
- risk 0.64cvss 9.8epss 0.05
Directory Traversal in Safescan Timemoto and TA-8000 series version 1.0 allows unauthenticated remote attackers to execute code via the administrative API.
- risk 0.64cvss 9.8epss 0.03
SuiteCRM through 7.11.11 allows Directory Traversal to include arbitrary .php files within the webroot via add_to_prospect_list.
- risk 0.64cvss 9.8epss 0.03
Directory traversal vulnerability in Thomson Reuters for FATCA before 5.2 allows remote attackers to execute arbitrary files via the item parameter.
- risk 0.64cvss 9.8epss 0.04
In GitLab EE 11.3 through 12.5.3, 12.4.5, and 12.3.8, insufficient parameter sanitization for the Maven package registry could lead to privilege escalation and remote code execution vulnerabilities under certain conditions.
- risk 0.64cvss 9.8epss 0.07
A security vulnerability has been identified in HPE SimpliVity 380 Gen 9, HPE SimpliVity 380 Gen 10, HPE SimpliVity 380 Gen 10 G, HPE SimpliVity 2600 Gen 10, SimpliVity OmniCube, SimpliVity OmniStack for Cisco, SimpliVity OmniStack for Lenovo and SimpliVity OmniStack for Dell…
- risk 0.64cvss 9.8epss 0.02
Gitlab Enterprise Edition (EE) 11.3 through 12.4.2 allows Directory Traversal.
- risk 0.64cvss 9.8epss 0.03
Path traversal in RadChart in Telerik UI for ASP.NET AJAX allows a remote attacker to read and delete an image with extension .BMP, .EXIF, .GIF, .ICON, .JPEG, .PNG, .TIFF, or .WMF on the server through a specially crafted request. NOTE: RadChart was discontinued in 2014 in favor…
- risk 0.64cvss 9.8epss 0.03
Intesync Solismed 3.3sp1 allows Local File Inclusion (LFI), a different vulnerability than CVE-2019-15931. This leads to unauthenticated code execution.
- risk 0.64cvss 9.8epss 0.03
Intesync Solismed 3.3sp allows Directory Traversal, a different vulnerability than CVE-2019-16246.
- risk 0.64cvss 9.8epss 0.04
An issue was discovered in SALTO ProAccess SPACE 5.4.3.0. An attacker can write arbitrary content to arbitrary files, as demonstrated by CVE-2019-19458 files under the web root, or .bat files that will be used with auto start. This allows an attacker to execute arbitrary…
- risk 0.64cvss 9.8epss 0.04
A Symlink Traversal vulnerability exists in NETGEAR Centria WNDR4700 Firmware 1.0.0.34.
- risk 0.64cvss 9.8epss 0.02
Symlink Traversal vulnerability in NETGEAR WNR3500U and WNR3500L due to misconfiguration in the SMB service.
- risk 0.64cvss 9.8epss 0.03
Symlink Traversal vulnerability in TP-LINK TL-WDR4300 and TL-1043ND..
- risk 0.64cvss 9.8epss 0.02
Symlink Traversal vulnerability in ASUS RT-AC66U and RT-N56U due to misconfiguration in the SMB service.
- risk 0.64cvss 9.8epss 0.05
Advantech WISE-PaaS/RMM, Versions 3.3.29 and prior. Path traversal vulnerabilities are caused by a lack of proper validation of a user-supplied path prior to use in file operations. An attacker can leverage these vulnerabilities to remotely execute code while posing as an…
- risk 0.64cvss 9.8epss 0.03
ytnef has directory traversal
- risk 0.64cvss 9.8epss 0.05
A directory traversal vulnerability in Trend Micro Apex One, OfficeScan (11.0, XG) and Worry-Free Business Security (9.5, 10.0) may allow an attacker to bypass authentication and log on to an affected product's management console as a root user. The vulnerability does not…
- risk 0.64cvss 9.8epss 0.09
Linksys EA6500 has SMB Symlink Traversal allowing symbolic links to be created to locations outside of the Samba share.
- risk 0.64cvss 9.8epss 0.02
The Shack Forms Pro extension before 4.0.32 for Joomla! allows path traversal via a file attachment.