CWE-22
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
Description
The product uses external input to construct a pathname that is intended to identify a file or directory that is located underneath a restricted parent directory, but the product does not properly neutralize special elements within the pathname that can cause the pathname to resolve to a location that is outside of the restricted directory.
Hierarchy (View 1000)
Related attack patterns (CAPEC)
CAPEC-126 · CAPEC-64 · CAPEC-76 · CAPEC-78 · CAPEC-79
CVEs mapped to this weakness (10,483)
page 273 of 525| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2021-37728 | Med | 0.42 | 6.5 | 0.01 | Sep 7, 2021 | A remote path traversal vulnerability was discovered in Aruba Operating System Software version(s): Prior to 8.8.0.1, 8.7.1.4, 8.6.0.11, 8.5.0.13. Aruba has released patches for ArubaOS that address this security vulnerability. | ||
| CVE-2020-18127 | Med | 0.42 | 6.5 | 0.01 | Aug 30, 2021 | An issue in the /config/config.php component of Indexhibit 2.1.5 allows attackers to arbitrarily view files. | ||
| CVE-2020-19547 | Med | 0.42 | 6.5 | 0.01 | Aug 25, 2021 | Directory Traversal vulnerability exists in PopojiCMS 2.0.1 via the id parameter in admin.php. | ||
| CVE-2020-23069 | Med | 0.42 | 6.5 | 0.02 | Aug 18, 2021 | Path Traversal vulneraility exists in webTareas 2.0 via the extpath parameter in general_serv.php, which could let a malicious user read arbitrary files. | ||
| CVE-2021-22933 | Med | 0.42 | 6.5 | 0.01 | Aug 16, 2021 | A vulnerability in Pulse Connect Secure before 9.1R12 could allow an authenticated administrator to perform an arbitrary file delete via a maliciously crafted web request. | ||
| CVE-2021-27402 | Med | 0.42 | 6.5 | 0.01 | Aug 13, 2021 | The SAS Admin portal of Mitel MiCollab before 9.2 FP2 could allow an unauthenticated attacker to access (view and modify) user data by injecting arbitrary directory paths due to improper URL validation, aka Directory Traversal. | ||
| CVE-2021-31731 | Med | 0.42 | 6.5 | 0.01 | Aug 12, 2021 | A directory traversal issue in KiteCMS 1.1.1 allows remote administrators to overwrite arbitrary files via ../ in the path parameter to index.php/admin/Template/fileedit, with PHP code in the html parameter. | ||
| CVE-2021-22674 | Med | 0.42 | 6.5 | 0.01 | Aug 10, 2021 | The affected product is vulnerable to a relative path traversal condition, which may allow an attacker access to unauthorized files and directories on the WebAccess/SCADA (WebAccess/SCADA versions prior to 8.4.5, WebAccess/SCADA versions prior to 9.0.1). | ||
| CVE-2021-21501 | Hig | 0.42 | 7.5 | 0.04 | Aug 10, 2021 | Improper configuration will cause ServiceComb ServiceCenter Directory Traversal problem in ServcieCenter 1.x.x versions and fixed in 2.0.0. | ||
| CVE-2021-38136 | Med | 0.42 | 6.5 | 0.01 | Aug 6, 2021 | Corero SecureWatch Managed Services 9.7.2.0020 is affected by a Path Traversal vulnerability via the snap_file parameter in the /it-IT/splunkd/__raw/services/get_snapshot HTTP API endpoint. A ‘low privileged’ attacker can read any file on the target host. | ||
| CVE-2021-34638 | Med | 0.42 | 6.5 | 0.01 | Aug 5, 2021 | Authenticated Directory Traversal in WordPress Download Manager <= 3.1.24 allows authenticated (Contributor+) users to obtain sensitive configuration file information, as well as allowing Author+ users to perform XSS attacks, by setting Download template to a file containing… | ||
| CVE-2021-36168 | Med | 0.42 | 6.5 | 0.01 | Aug 4, 2021 | A Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') in Fortinet FortiPortal 6.x before 6.0.5, FortiPortal 5.3.x before 5.3.6 and any FortiPortal before 6.2.5 allows authenticated attacker to disclosure information via crafted GET request with… | ||
| CVE-2021-23415 | Hig | 0.42 | 7.5 | 0.02 | Jul 28, 2021 | This affects the package elFinder.AspNet before 1.1.1. The user-controlled file name is not properly sanitized before it is used to create a file system path. | ||
| CVE-2021-37445 | Med | 0.42 | 6.5 | 0.01 | Jul 25, 2021 | In NCH Quorum v2.03 and earlier, an authenticated user can use directory traversal via logprop?file=/.. for file reading. | ||
| CVE-2021-37442 | Med | 0.42 | 6.5 | 0.01 | Jul 25, 2021 | NCH IVM Attendant v5.12 and earlier allows path traversal via viewfile?file=/.. to read files. | ||
| CVE-2021-37440 | Med | 0.42 | 6.5 | 0.01 | Jul 25, 2021 | NCH Axon PBX v2.22 and earlier allows path traversal for file disclosure via the logprop?file=/.. substring. | ||
| CVE-2021-37439 | Med | 0.42 | 6.5 | 0.01 | Jul 25, 2021 | NCH FlexiServer v6.00 suffers from a syslog?file=/.. path traversal vulnerability. | ||
| CVE-2021-37469 | Med | 0.42 | 6.5 | 0.01 | Jul 25, 2021 | In NCH WebDictate v2.13 and earlier, authenticated users can abuse logprop?file=/.. path traversal to read files on the filesystem. | ||
| CVE-2021-1617 | Med | 0.42 | 6.5 | 0.02 | Jul 22, 2021 | Multiple vulnerabilities in the web-based management interface of Cisco Intersight Virtual Appliance could allow an authenticated, remote attacker to conduct a path traversal or command injection attack on an affected system. These vulnerabilities are due to insufficient input… | ||
| CVE-2021-32769 | Hig | 0.42 | 7.5 | 0.02 | Jul 16, 2021 | Micronaut is a JVM-based, full stack Java framework designed for building JVM applications. A path traversal vulnerability exists in versions prior to 2.5.9. With a basic configuration, it is possible to access any file from a filesystem, using "/../../" in the URL. This occurs… |
- risk 0.42cvss 6.5epss 0.01
A remote path traversal vulnerability was discovered in Aruba Operating System Software version(s): Prior to 8.8.0.1, 8.7.1.4, 8.6.0.11, 8.5.0.13. Aruba has released patches for ArubaOS that address this security vulnerability.
- risk 0.42cvss 6.5epss 0.01
An issue in the /config/config.php component of Indexhibit 2.1.5 allows attackers to arbitrarily view files.
- risk 0.42cvss 6.5epss 0.01
Directory Traversal vulnerability exists in PopojiCMS 2.0.1 via the id parameter in admin.php.
- risk 0.42cvss 6.5epss 0.02
Path Traversal vulneraility exists in webTareas 2.0 via the extpath parameter in general_serv.php, which could let a malicious user read arbitrary files.
- risk 0.42cvss 6.5epss 0.01
A vulnerability in Pulse Connect Secure before 9.1R12 could allow an authenticated administrator to perform an arbitrary file delete via a maliciously crafted web request.
- risk 0.42cvss 6.5epss 0.01
The SAS Admin portal of Mitel MiCollab before 9.2 FP2 could allow an unauthenticated attacker to access (view and modify) user data by injecting arbitrary directory paths due to improper URL validation, aka Directory Traversal.
- risk 0.42cvss 6.5epss 0.01
A directory traversal issue in KiteCMS 1.1.1 allows remote administrators to overwrite arbitrary files via ../ in the path parameter to index.php/admin/Template/fileedit, with PHP code in the html parameter.
- risk 0.42cvss 6.5epss 0.01
The affected product is vulnerable to a relative path traversal condition, which may allow an attacker access to unauthorized files and directories on the WebAccess/SCADA (WebAccess/SCADA versions prior to 8.4.5, WebAccess/SCADA versions prior to 9.0.1).
- risk 0.42cvss 7.5epss 0.04
Improper configuration will cause ServiceComb ServiceCenter Directory Traversal problem in ServcieCenter 1.x.x versions and fixed in 2.0.0.
- risk 0.42cvss 6.5epss 0.01
Corero SecureWatch Managed Services 9.7.2.0020 is affected by a Path Traversal vulnerability via the snap_file parameter in the /it-IT/splunkd/__raw/services/get_snapshot HTTP API endpoint. A ‘low privileged’ attacker can read any file on the target host.
- risk 0.42cvss 6.5epss 0.01
Authenticated Directory Traversal in WordPress Download Manager <= 3.1.24 allows authenticated (Contributor+) users to obtain sensitive configuration file information, as well as allowing Author+ users to perform XSS attacks, by setting Download template to a file containing…
- risk 0.42cvss 6.5epss 0.01
A Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') in Fortinet FortiPortal 6.x before 6.0.5, FortiPortal 5.3.x before 5.3.6 and any FortiPortal before 6.2.5 allows authenticated attacker to disclosure information via crafted GET request with…
- risk 0.42cvss 7.5epss 0.02
This affects the package elFinder.AspNet before 1.1.1. The user-controlled file name is not properly sanitized before it is used to create a file system path.
- risk 0.42cvss 6.5epss 0.01
In NCH Quorum v2.03 and earlier, an authenticated user can use directory traversal via logprop?file=/.. for file reading.
- risk 0.42cvss 6.5epss 0.01
NCH IVM Attendant v5.12 and earlier allows path traversal via viewfile?file=/.. to read files.
- risk 0.42cvss 6.5epss 0.01
NCH Axon PBX v2.22 and earlier allows path traversal for file disclosure via the logprop?file=/.. substring.
- risk 0.42cvss 6.5epss 0.01
NCH FlexiServer v6.00 suffers from a syslog?file=/.. path traversal vulnerability.
- risk 0.42cvss 6.5epss 0.01
In NCH WebDictate v2.13 and earlier, authenticated users can abuse logprop?file=/.. path traversal to read files on the filesystem.
- risk 0.42cvss 6.5epss 0.02
Multiple vulnerabilities in the web-based management interface of Cisco Intersight Virtual Appliance could allow an authenticated, remote attacker to conduct a path traversal or command injection attack on an affected system. These vulnerabilities are due to insufficient input…
- risk 0.42cvss 7.5epss 0.02
Micronaut is a JVM-based, full stack Java framework designed for building JVM applications. A path traversal vulnerability exists in versions prior to 2.5.9. With a basic configuration, it is possible to access any file from a filesystem, using "/../../" in the URL. This occurs…