VYPR

CWE-22

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')

BaseStableLikelihood: High

Description

The product uses external input to construct a pathname that is intended to identify a file or directory that is located underneath a restricted parent directory, but the product does not properly neutralize special elements within the pathname that can cause the pathname to resolve to a location that is outside of the restricted directory.

Hierarchy (View 1000)

Parents

Children

Related attack patterns (CAPEC)

CAPEC-126 · CAPEC-64 · CAPEC-76 · CAPEC-78 · CAPEC-79

CVEs mapped to this weakness (10,485)

page 318 of 525
  • CVE-2018-1002209MedJul 25, 2018
    risk 0.36cvss 5.5epss 0.05

    QuaZIP before 0.7.6 is vulnerable to directory traversal, allowing attackers to write to arbitrary files via a ../ (dot dot slash) in a Zip archive entry that is mishandled during extraction. This vulnerability is also known as 'Zip-Slip'.

  • CVE-2018-14573MedJul 23, 2018
    risk 0.36cvss 5.5epss 0.06

    A Local File Inclusion (LFI) vulnerability exists in the Web Interface API of TightRope Media Carousel Digital Signage before 7.3.5. The RenderingFetch API allows for the downloading of arbitrary files through the use of directory traversal sequences, aka CSL-1683.

  • CVE-2018-1999020MedJul 23, 2018
    risk 0.36cvss 5.5epss 0.01

    Open Networking Foundation (ONF) ONOS version 1.13.2 and earlier version contains a Directory Traversal vulnerability in core/common/src/main/java/org/onosproject/common/app/ApplicationArchive.java line 35 that can result in arbitrary file deletion (overwrite). This attack…

  • CVE-2018-3770MedJul 20, 2018
    risk 0.36cvss 5.5epss 0.01

    A path traversal exists in markdown-pdf version <9.0.0 that allows a user to insert a malicious html code that can result in reading the local files.

  • CVE-2017-16814MedFeb 26, 2018
    risk 0.36cvss 5.5epss 0.01

    A Directory Traversal issue was discovered in the Foxit MobilePDF app before 6.1 for iOS. This occurs by abusing the URL + escape character during a Wi-Fi transfer, which could be exploited by attackers to bypass intended restrictions on local application files.

  • CVE-2018-6356MedFeb 20, 2018
    risk 0.36cvss 6.5epss 0.04

    Jenkins before 2.107 and Jenkins LTS before 2.89.4 did not properly prevent specifying relative paths that escape a base directory for URLs accessing plugin resource files. This allowed users with Overall/Read permission to download files from the Jenkins master they should not…

  • CVE-2018-0123MedFeb 8, 2018
    risk 0.36cvss 5.5epss 0.00

    A Path Traversal vulnerability in the diagnostic shell for Cisco IOS and IOS XE Software could allow an authenticated, local attacker to use certain diagnostic shell commands that can overwrite system files. These system files may be sensitive and should not be able to be…

  • CVE-2018-1047MedJan 24, 2018
    risk 0.36cvss 5.5epss 0.01

    A flaw was found in Wildfly 9.x. A path traversal vulnerability through the org.wildfly.extension.undertow.deployment.ServletResourceManager.getResource method could lead to information disclosure of arbitrary local files.

  • CVE-2014-9485MedJan 16, 2018
    risk 0.36cvss 5.5epss 0.04

    Directory traversal vulnerability in the do_extract_currentfile function in miniunz.c in miniunzip in minizip before 1.1-5 might allow remote attackers to write to arbitrary files via a crafted entry in a ZIP archive.

  • CVE-2017-2695MedNov 22, 2017
    risk 0.36cvss 5.5epss 0.01

    TIT-AL00C583B211 has a directory traversal vulnerability which allows an attacker to obtain the files in email application.

  • CVE-2014-9983MedJun 4, 2017
    risk 0.36cvss 5.5epss 0.02

    Directory Traversal exists in RAR 4.x and 5.x because an unpack operation follows any symlinks, including symlinks contained in the archive. This allows remote attackers to write to arbitrary files via a crafted archive.

  • CVE-2017-8314MedMay 23, 2017
    risk 0.36cvss 5.5epss 0.02

    Directory Traversal in Zip Extraction built-in function in Kodi 17.1 and earlier allows arbitrary file write on disk via a Zip file as subtitles.

  • CVE-2016-7843MedApr 28, 2017
    risk 0.36cvss 5.5epss 0.03

    Directory traversal vulnerability in AttacheCase for Java 0.60 and earlier, AttacheCase Lite 1.4.6 and earlier, and AttacheCase Pro 1.5.7 and earlier allows remote attackers to read arbitrary files via specially crafted ATC file.

  • CVE-2016-7842MedApr 28, 2017
    risk 0.36cvss 5.5epss 0.03

    Directory traversal vulnerability in AttacheCase 2.8.2.8 and earlier and 3.2.0.4 and earlier allows remote attackers to read arbitrary files via specially crafted ATC file.

  • CVE-2017-7461MedApr 11, 2017
    risk 0.36cvss 4.9epss 0.11

    Directory traversal vulnerability in the web-based management site on the Intellinet NFC-30ir IP Camera with firmware LM.1.6.16.05 allows remote attackers to read arbitrary files via a request to a vendor-supplied CGI script that is used to read HTML text file, but that does not…

  • CVE-2016-4314MedFeb 17, 2017
    risk 0.36cvss 4.9epss 0.12

    Directory traversal vulnerability in the LogViewer Admin Service in WSO2 Carbon 4.4.5 allows remote authenticated administrators to read arbitrary files via a .. (dot dot) in the logFile parameter to downloadgz-ajaxprocessor.jsp.

  • CVE-2016-7569MedJan 27, 2017
    risk 0.36cvss 5.5epss 0.03

    Directory traversal vulnerability in docker2aci before 0.13.0 allows remote attackers to write to arbitrary files via a .. (dot dot) in the embedded layer data in an image.

  • CVE-2016-4004MedApr 12, 2016
    risk 0.36cvss 4.9epss 0.09

    Directory traversal vulnerability in Dell OpenManage Server Administrator (OMSA) 8.2 allows remote authenticated administrators to read arbitrary files via a ..\ (dot dot backslash) in the file parameter to ViewFile.

  • CVE-2010-0481MedApr 14, 2010
    risk 0.36cvss 5.5epss 0.02

    The kernel in Microsoft Windows Vista Gold, SP1, and SP2, Windows Server 2008 Gold, SP2, and R2, and Windows 7 does not properly translate a registry key's virtual path to its real path, which allows local users to cause a denial of service (reboot) via a crafted application,…

  • CVE-2026-106491MedOct 6, 2026
    risk 0.35cvss 6.4epss 0.00

    Backstage is an open framework for building developer portals. Prior to 0.6.17, the @backstage/plugin-proxy-backend package is affected by improper input validation in proxy-backend. An authenticated Backstage user could craft a request URL that causes the proxy-backend to…