CWE-22
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
Description
The product uses external input to construct a pathname that is intended to identify a file or directory that is located underneath a restricted parent directory, but the product does not properly neutralize special elements within the pathname that can cause the pathname to resolve to a location that is outside of the restricted directory.
Hierarchy (View 1000)
Related attack patterns (CAPEC)
CAPEC-126 · CAPEC-64 · CAPEC-76 · CAPEC-78 · CAPEC-79
CVEs mapped to this weakness (10,483)
page 278 of 525| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2019-3662 | Med | 0.42 | 6.5 | 0.01 | Nov 14, 2019 | Path Traversal: '/absolute/pathname/here' vulnerability in McAfee Advanced Threat Defense (ATD) prior to 4.8 allows remote authenticated attacker to gain unintended access to files on the system via carefully constructed HTTP requests. | ||
| CVE-2019-16876 | Hig | 0.42 | 7.5 | 0.01 | Nov 7, 2019 | Portainer before 1.22.1 allows Directory Traversal. | ||
| CVE-2019-17324 | Med | 0.42 | 6.5 | 0.01 | Oct 30, 2019 | ClipSoft REXPERT 1.0.0.527 and earlier version allows directory traversal by issuing a special HTTP POST request with ../ characters. This could lead to create malicious HTML file, because they can inject a content with crafted template. User interaction is required to exploit… | ||
| CVE-2019-17322 | Med | 0.42 | 6.5 | 0.01 | Oct 30, 2019 | ClipSoft REXPERT 1.0.0.527 and earlier version allows arbitrary file creation via a POST request with the parameter set to the file path to be written. This can be an executable file that is written to in the arbitrary directory. User interaction is required to exploit this… | ||
| CVE-2019-14424 | Med | 0.42 | 6.5 | 0.01 | Oct 17, 2019 | A Local File Inclusion (LFI) issue in the addon CUx-Daemon 1.11a of the eQ-3 Homematic CCU-Firmware 2.35.16 until 2.45.6 allows remote authenticated attackers to read sensitive files via a simple HTTP Request. | ||
| CVE-2019-12704 | Med | 0.42 | 6.5 | 0.02 | Oct 16, 2019 | A vulnerability in the web-based management interface of Cisco SPA100 Series Analog Telephone Adapters (ATAs) could allow an authenticated, remote attacker to view the contents of arbitrary files on an affected device. The vulnerability is due to improper input validation in the… | ||
| CVE-2019-16198 | Med | 0.42 | 6.5 | 0.02 | Oct 3, 2019 | KSLabs KSWEB 3.93 allows ../ directory traversal, as demonstrated by the hostFile parameter. | ||
| CVE-2019-17073 | Med | 0.42 | 6.5 | 0.02 | Oct 1, 2019 | emlog through 6.0.0beta allows remote authenticated users to delete arbitrary files via admin/template.php?action=del&tpl=../ directory traversal. | ||
| CVE-2019-7618 | Med | 0.42 | 6.5 | 0.01 | Oct 1, 2019 | A local file disclosure flaw was found in Elastic Code versions 7.3.0, 7.3.1, and 7.3.2. If a malicious code repository is imported into Code it is possible to read arbitrary files from the local filesystem of the Kibana instance running Code with the permission of the Kibana… | ||
| CVE-2019-16867 | Med | 0.42 | 6.5 | 0.01 | Sep 25, 2019 | HongCMS 3.0.0 allows arbitrary file deletion via a ../ in the file parameter to admin/index.php/database/ajax?action=delete, a similar issue to CVE-2018-16774. (If the attacker deletes config.php and visits install/index.php, they can reinstall the product.) | ||
| CVE-2018-1847 | Med | 0.42 | 6.5 | 0.02 | Sep 18, 2019 | IBM Financial Transaction Manager (FTM) for Multi-Platform (MP) v2.0.0.0 through 2.0.0.5, v2.1.0.0 through 2.1.0.4, v2.1.1.0 through 2.1.1.4, and v3.0.0.0 through 3.0.0.8 could allow a remote attacker to traverse directories on the system. An attacker could send a… | ||
| CVE-2016-10977 | Med | 0.42 | 6.5 | 0.02 | Sep 17, 2019 | The nelio-ab-testing plugin before 4.5.0 for WordPress has filename=..%2f directory traversal. | ||
| CVE-2019-5484 | Hig | 0.42 | 7.5 | 0.03 | Sep 13, 2019 | Bower before 1.8.8 has a path traversal vulnerability permitting file write in arbitrary locations via install command, which allows attackers to write arbitrary files when a malicious package is extracted. | ||
| CVE-2019-5956 | Med | 0.42 | 6.5 | 0.02 | Sep 12, 2019 | Directory traversal vulnerability in WonderCMS 2.6.0 and earlier allows remote attackers to delete arbitrary files via unspecified vectors. | ||
| CVE-2019-15648 | Med | 0.42 | 6.5 | 0.01 | Aug 27, 2019 | The insert-or-embed-articulate-content-into-wordpress plugin before 4.29991 for WordPress has insufficient restrictions on deleting or renaming by a Subscriber. | ||
| CVE-2019-15055 | Med | 0.42 | 6.5 | 0.02 | Aug 26, 2019 | MikroTik RouterOS through 6.44.5 and 6.45.x through 6.45.3 improperly handles the disk name, which allows authenticated users to delete arbitrary files. Attackers can exploit this vulnerability to reset credential storage, which allows them access to the management interface as… | ||
| CVE-2019-14751 | Hig | 0.42 | 7.5 | 0.06 | Aug 22, 2019 | NLTK Downloader before 3.4.5 is vulnerable to a directory traversal, allowing attackers to write arbitrary files via a ../ (dot dot slash) in an NLTK package (ZIP archive) that is mishandled during extraction. | ||
| CVE-2019-10375 | Med | 0.42 | 6.5 | 0.01 | Aug 7, 2019 | An arbitrary file read vulnerability in Jenkins File System SCM Plugin 2.1 and earlier allows attackers able to configure jobs in Jenkins to obtain the contents of any file on the Jenkins master. | ||
| CVE-2019-7859 | Hig | 0.42 | 7.5 | 0.01 | Aug 2, 2019 | A path traversal vulnerability in the WYSIWYG editor for Magento 2.1 prior to 2.1.18, Magento 2.2 prior to 2.2.9, Magento 2.3 prior to 2.3.2 could result in unauthorized access to uploaded images due to insufficient access control. | ||
| CVE-2019-5221 | Med | 0.42 | 6.5 | 0.00 | Jul 10, 2019 | There is a path traversal vulnerability on Huawei Share. The software does not properly validate the path, an attacker could crafted a file path when transporting file through Huawei Share, successful exploit could allow the attacker to transport a file to arbitrary path on the… |
- risk 0.42cvss 6.5epss 0.01
Path Traversal: '/absolute/pathname/here' vulnerability in McAfee Advanced Threat Defense (ATD) prior to 4.8 allows remote authenticated attacker to gain unintended access to files on the system via carefully constructed HTTP requests.
- risk 0.42cvss 7.5epss 0.01
Portainer before 1.22.1 allows Directory Traversal.
- risk 0.42cvss 6.5epss 0.01
ClipSoft REXPERT 1.0.0.527 and earlier version allows directory traversal by issuing a special HTTP POST request with ../ characters. This could lead to create malicious HTML file, because they can inject a content with crafted template. User interaction is required to exploit…
- risk 0.42cvss 6.5epss 0.01
ClipSoft REXPERT 1.0.0.527 and earlier version allows arbitrary file creation via a POST request with the parameter set to the file path to be written. This can be an executable file that is written to in the arbitrary directory. User interaction is required to exploit this…
- risk 0.42cvss 6.5epss 0.01
A Local File Inclusion (LFI) issue in the addon CUx-Daemon 1.11a of the eQ-3 Homematic CCU-Firmware 2.35.16 until 2.45.6 allows remote authenticated attackers to read sensitive files via a simple HTTP Request.
- risk 0.42cvss 6.5epss 0.02
A vulnerability in the web-based management interface of Cisco SPA100 Series Analog Telephone Adapters (ATAs) could allow an authenticated, remote attacker to view the contents of arbitrary files on an affected device. The vulnerability is due to improper input validation in the…
- risk 0.42cvss 6.5epss 0.02
KSLabs KSWEB 3.93 allows ../ directory traversal, as demonstrated by the hostFile parameter.
- risk 0.42cvss 6.5epss 0.02
emlog through 6.0.0beta allows remote authenticated users to delete arbitrary files via admin/template.php?action=del&tpl=../ directory traversal.
- risk 0.42cvss 6.5epss 0.01
A local file disclosure flaw was found in Elastic Code versions 7.3.0, 7.3.1, and 7.3.2. If a malicious code repository is imported into Code it is possible to read arbitrary files from the local filesystem of the Kibana instance running Code with the permission of the Kibana…
- risk 0.42cvss 6.5epss 0.01
HongCMS 3.0.0 allows arbitrary file deletion via a ../ in the file parameter to admin/index.php/database/ajax?action=delete, a similar issue to CVE-2018-16774. (If the attacker deletes config.php and visits install/index.php, they can reinstall the product.)
- risk 0.42cvss 6.5epss 0.02
IBM Financial Transaction Manager (FTM) for Multi-Platform (MP) v2.0.0.0 through 2.0.0.5, v2.1.0.0 through 2.1.0.4, v2.1.1.0 through 2.1.1.4, and v3.0.0.0 through 3.0.0.8 could allow a remote attacker to traverse directories on the system. An attacker could send a…
- risk 0.42cvss 6.5epss 0.02
The nelio-ab-testing plugin before 4.5.0 for WordPress has filename=..%2f directory traversal.
- risk 0.42cvss 7.5epss 0.03
Bower before 1.8.8 has a path traversal vulnerability permitting file write in arbitrary locations via install command, which allows attackers to write arbitrary files when a malicious package is extracted.
- risk 0.42cvss 6.5epss 0.02
Directory traversal vulnerability in WonderCMS 2.6.0 and earlier allows remote attackers to delete arbitrary files via unspecified vectors.
- risk 0.42cvss 6.5epss 0.01
The insert-or-embed-articulate-content-into-wordpress plugin before 4.29991 for WordPress has insufficient restrictions on deleting or renaming by a Subscriber.
- risk 0.42cvss 6.5epss 0.02
MikroTik RouterOS through 6.44.5 and 6.45.x through 6.45.3 improperly handles the disk name, which allows authenticated users to delete arbitrary files. Attackers can exploit this vulnerability to reset credential storage, which allows them access to the management interface as…
- risk 0.42cvss 7.5epss 0.06
NLTK Downloader before 3.4.5 is vulnerable to a directory traversal, allowing attackers to write arbitrary files via a ../ (dot dot slash) in an NLTK package (ZIP archive) that is mishandled during extraction.
- risk 0.42cvss 6.5epss 0.01
An arbitrary file read vulnerability in Jenkins File System SCM Plugin 2.1 and earlier allows attackers able to configure jobs in Jenkins to obtain the contents of any file on the Jenkins master.
- risk 0.42cvss 7.5epss 0.01
A path traversal vulnerability in the WYSIWYG editor for Magento 2.1 prior to 2.1.18, Magento 2.2 prior to 2.2.9, Magento 2.3 prior to 2.3.2 could result in unauthorized access to uploaded images due to insufficient access control.
- risk 0.42cvss 6.5epss 0.00
There is a path traversal vulnerability on Huawei Share. The software does not properly validate the path, an attacker could crafted a file path when transporting file through Huawei Share, successful exploit could allow the attacker to transport a file to arbitrary path on the…