CWE-22
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
Description
The product uses external input to construct a pathname that is intended to identify a file or directory that is located underneath a restricted parent directory, but the product does not properly neutralize special elements within the pathname that can cause the pathname to resolve to a location that is outside of the restricted directory.
Hierarchy (View 1000)
Related attack patterns (CAPEC)
CAPEC-126 · CAPEC-64 · CAPEC-76 · CAPEC-78 · CAPEC-79
CVEs mapped to this weakness (10,483)
page 279 of 525| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2019-13396 | Med | 0.42 | 5.3 | 0.63 | Jul 10, 2019 | FlightPath 4.x and 5.0-x allows directory traversal and Local File Inclusion through the form_include parameter in an index.php?q=system-handle-form-submit POST request because of an include_once in system_handle_form_submit in modules/system/system.module. | ||
| CVE-2018-18863 | Med | 0.42 | 6.5 | 0.01 | Jun 19, 2019 | NGA ResourceLink 20.0.2.1 allows local file inclusion. | ||
| CVE-2019-8952 | Med | 0.42 | 6.5 | 0.01 | May 13, 2019 | A Path Traversal vulnerability located in the webserver affects several Bosch hardware and software products. The vulnerability potentially allows a remote authorized user to access arbitrary files on the system via the network interface. Affected hardware products: Bosch DIVAR… | ||
| CVE-2019-9005 | Med | 0.42 | 6.5 | 0.02 | Apr 18, 2019 | The Cprime Power Scripts app before 4.0.14 for Atlassian Jira allows Directory Traversal. | ||
| CVE-2019-4178 | Med | 0.42 | 6.4 | 0.03 | Apr 15, 2019 | IBM Cognos Analytics 11 could allow a remote attacker to traverse directories on the system. An attacker could send a specially-crafted URL request to write or view arbitrary files on the system. IBM X-Force ID: 158919. | ||
| CVE-2019-10632 | Med | 0.42 | 6.5 | 0.01 | Apr 9, 2019 | A directory traversal vulnerability in the file browser component on the Zyxel NAS 326 version 5.21 and below allows a lower privileged user to change the location of any other user's files. | ||
| CVE-2018-20647 | Med | 0.42 | 6.5 | 0.02 | Mar 21, 2019 | PHP Scripts Mall Car Rental Script 2.0.8 has directory traversal via a direct request for a listing of an image directory such as an images/ directory. | ||
| CVE-2018-20646 | Med | 0.42 | 6.5 | 0.02 | Mar 21, 2019 | PHP Scripts Mall Basic B2B Script 2.0.9 has has directory traversal via a direct request for a listing of an image directory such as an uploads/ directory. | ||
| CVE-2018-20643 | Med | 0.42 | 6.5 | 0.02 | Mar 21, 2019 | PHP Scripts Mall Entrepreneur Job Portal Script 3.0.1 has directory traversal via a direct request for a listing of an image directory such as an assets/ directory. | ||
| CVE-2018-20638 | Med | 0.42 | 6.5 | 0.01 | Mar 21, 2019 | PHP Scripts Mall Chartered Accountant : Auditor Website 2.0.1 has directory traversal via a direct request for a listing of an image directory such as an assets/ directory. | ||
| CVE-2018-20626 | Med | 0.42 | 6.5 | 0.02 | Mar 21, 2019 | PHP Scripts Mall Consumer Reviews Script 4.0.3 has directory traversal via a direct request for a listing of an uploads directory such as the wp-content/uploads/2018/12 directory. | ||
| CVE-2019-9611 | Med | 0.42 | 6.5 | 0.01 | Mar 6, 2019 | An issue was discovered in OFCMS before 1.1.3. It allows admin/cms/template/getTemplates.html?res_path=res directory traversal, with ../ in the dir parameter, to write arbitrary content (in the file_content parameter) into an arbitrary file (specified by the file_name… | ||
| CVE-2019-8407 | Med | 0.42 | 6.5 | 0.01 | Feb 17, 2019 | HongCMS 3.0.0 allows arbitrary file read and write operations via a ../ in the filename parameter to the admin/index.php/language/edit URI. | ||
| CVE-2019-7387 | Med | 0.42 | 6.5 | 0.01 | Feb 4, 2019 | A local file inclusion vulnerability exists in the web interface of Systrome Cumilon ISG-600C, ISG-600H, and ISG-800W 1.1-R2.1_TRUNK-20180914.bin devices. When the export function is called from system/maintenance/export.php, it accepts the path provided by the user, leading to… | ||
| CVE-2019-1000009 | Med | 0.42 | 6.5 | 0.01 | Feb 4, 2019 | Helm ChartMuseum version >=0.1.0 and < 0.8.1 contains a CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in HTTP API to save charts that can result in a specially crafted chart could be uploaded and saved outside the intended… | ||
| CVE-2019-1000008 | Med | 0.42 | 6.5 | 0.01 | Feb 4, 2019 | All versions of Helm between Helm >=2.0.0 and < 2.12.2 contains a CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in The commands `helm fetch --untar` and `helm lint some.tgz` that can result when chart archive files are… | ||
| CVE-2018-16485 | Med | 0.42 | 6.5 | 0.01 | Feb 1, 2019 | Path Traversal vulnerability in module m-server <1.4.1 allows malicious user to access unauthorized content of any file in the directory tree e.g. /etc/passwd by appending slashes to the URL request. | ||
| CVE-2018-1000850 | Hig | 0.42 | 7.5 | 0.04 | Dec 20, 2018 | Square Retrofit version versions from (including) 2.0 and 2.5.0 (excluding) contains a Directory Traversal vulnerability in RequestBuilder class, method addPathParameter that can result in By manipulating the URL an attacker could add or delete resources otherwise unavailable to… | ||
| CVE-2018-20303 | Hig | 0.42 | 7.5 | 0.03 | Dec 20, 2018 | In pkg/tool/path.go in Gogs before 0.11.82.1218, a directory traversal in the file-upload functionality can allow an attacker to create a file under data/sessions on the server, a similar issue to CVE-2018-18925. | ||
| CVE-2018-20227 | Hig | 0.42 | 7.5 | 0.02 | Dec 19, 2018 | RDF4J 2.4.2 allows Directory Traversal via ../ in an entry in a ZIP archive. |
- risk 0.42cvss 5.3epss 0.63
FlightPath 4.x and 5.0-x allows directory traversal and Local File Inclusion through the form_include parameter in an index.php?q=system-handle-form-submit POST request because of an include_once in system_handle_form_submit in modules/system/system.module.
- risk 0.42cvss 6.5epss 0.01
NGA ResourceLink 20.0.2.1 allows local file inclusion.
- risk 0.42cvss 6.5epss 0.01
A Path Traversal vulnerability located in the webserver affects several Bosch hardware and software products. The vulnerability potentially allows a remote authorized user to access arbitrary files on the system via the network interface. Affected hardware products: Bosch DIVAR…
- risk 0.42cvss 6.5epss 0.02
The Cprime Power Scripts app before 4.0.14 for Atlassian Jira allows Directory Traversal.
- risk 0.42cvss 6.4epss 0.03
IBM Cognos Analytics 11 could allow a remote attacker to traverse directories on the system. An attacker could send a specially-crafted URL request to write or view arbitrary files on the system. IBM X-Force ID: 158919.
- risk 0.42cvss 6.5epss 0.01
A directory traversal vulnerability in the file browser component on the Zyxel NAS 326 version 5.21 and below allows a lower privileged user to change the location of any other user's files.
- risk 0.42cvss 6.5epss 0.02
PHP Scripts Mall Car Rental Script 2.0.8 has directory traversal via a direct request for a listing of an image directory such as an images/ directory.
- risk 0.42cvss 6.5epss 0.02
PHP Scripts Mall Basic B2B Script 2.0.9 has has directory traversal via a direct request for a listing of an image directory such as an uploads/ directory.
- risk 0.42cvss 6.5epss 0.02
PHP Scripts Mall Entrepreneur Job Portal Script 3.0.1 has directory traversal via a direct request for a listing of an image directory such as an assets/ directory.
- risk 0.42cvss 6.5epss 0.01
PHP Scripts Mall Chartered Accountant : Auditor Website 2.0.1 has directory traversal via a direct request for a listing of an image directory such as an assets/ directory.
- risk 0.42cvss 6.5epss 0.02
PHP Scripts Mall Consumer Reviews Script 4.0.3 has directory traversal via a direct request for a listing of an uploads directory such as the wp-content/uploads/2018/12 directory.
- risk 0.42cvss 6.5epss 0.01
An issue was discovered in OFCMS before 1.1.3. It allows admin/cms/template/getTemplates.html?res_path=res directory traversal, with ../ in the dir parameter, to write arbitrary content (in the file_content parameter) into an arbitrary file (specified by the file_name…
- risk 0.42cvss 6.5epss 0.01
HongCMS 3.0.0 allows arbitrary file read and write operations via a ../ in the filename parameter to the admin/index.php/language/edit URI.
- risk 0.42cvss 6.5epss 0.01
A local file inclusion vulnerability exists in the web interface of Systrome Cumilon ISG-600C, ISG-600H, and ISG-800W 1.1-R2.1_TRUNK-20180914.bin devices. When the export function is called from system/maintenance/export.php, it accepts the path provided by the user, leading to…
- risk 0.42cvss 6.5epss 0.01
Helm ChartMuseum version >=0.1.0 and < 0.8.1 contains a CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in HTTP API to save charts that can result in a specially crafted chart could be uploaded and saved outside the intended…
- risk 0.42cvss 6.5epss 0.01
All versions of Helm between Helm >=2.0.0 and < 2.12.2 contains a CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in The commands `helm fetch --untar` and `helm lint some.tgz` that can result when chart archive files are…
- risk 0.42cvss 6.5epss 0.01
Path Traversal vulnerability in module m-server <1.4.1 allows malicious user to access unauthorized content of any file in the directory tree e.g. /etc/passwd by appending slashes to the URL request.
- risk 0.42cvss 7.5epss 0.04
Square Retrofit version versions from (including) 2.0 and 2.5.0 (excluding) contains a Directory Traversal vulnerability in RequestBuilder class, method addPathParameter that can result in By manipulating the URL an attacker could add or delete resources otherwise unavailable to…
- risk 0.42cvss 7.5epss 0.03
In pkg/tool/path.go in Gogs before 0.11.82.1218, a directory traversal in the file-upload functionality can allow an attacker to create a file under data/sessions on the server, a similar issue to CVE-2018-18925.
- risk 0.42cvss 7.5epss 0.02
RDF4J 2.4.2 allows Directory Traversal via ../ in an entry in a ZIP archive.