CWE-22
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
Description
The product uses external input to construct a pathname that is intended to identify a file or directory that is located underneath a restricted parent directory, but the product does not properly neutralize special elements within the pathname that can cause the pathname to resolve to a location that is outside of the restricted directory.
Hierarchy (View 1000)
Related attack patterns (CAPEC)
CAPEC-126 · CAPEC-64 · CAPEC-76 · CAPEC-78 · CAPEC-79
CVEs mapped to this weakness (10,485)
page 335 of 525| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2022-26315 | Med | 0.35 | 5.3 | 0.01 | Feb 28, 2022 | qrcp through 0.8.4, in receive mode, allows ../ Directory Traversal via the file name specified by the uploader. | ||
| CVE-2022-0665 | Med | 0.35 | 6.5 | 0.02 | Feb 22, 2022 | Path Traversal in GitHub repository pimcore/pimcore prior to 10.3.2. | ||
| CVE-2021-45286 | Med | 0.35 | 5.3 | 0.02 | Feb 9, 2022 | Directory Traversal vulnerability exists in ZZCMS 2021 via the skin parameter in 1) index.php, 2) bottom.php, and 3) top_index.php. | ||
| CVE-2021-29398 | Med | 0.35 | 5.3 | 0.02 | Feb 4, 2022 | Directory traversal in /northstar/Common/NorthFileManager/fileManagerObjects.jsp Northstar Technologies Inc NorthStar Club Management 6.3 allows remote unauthenticated users to browse and list the directories across the entire filesystem of the host of the web application. | ||
| CVE-2021-28377 | Med | 0.35 | 5.3 | 0.08 | Jan 12, 2022 | ChronoForums 2.0.11 allows av Directory Traversal to read arbitrary files. | ||
| CVE-2021-40003 | Med | 0.35 | 5.3 | 0.01 | Jan 10, 2022 | HwPCAssistant has a path traversal vulnerability. Successful exploitation of this vulnerability may affect data confidentiality. | ||
| CVE-2021-40001 | Med | 0.35 | 5.3 | 0.01 | Jan 10, 2022 | The CaasKit module has a path traversal vulnerability. Successful exploitation of this vulnerability may cause the MeeTime application to be unavailable. | ||
| CVE-2021-22404 | Med | 0.35 | 5.3 | 0.01 | Oct 28, 2021 | There is a Directory traversal vulnerability in Huawei Smartphone.Successful exploitation of this vulnerability may affect service confidentiality. | ||
| CVE-2021-37922 | Med | 0.35 | 5.3 | 0.02 | Oct 7, 2021 | Zoho ManageEngine ADManager Plus version 7110 and prior is vulnerable to path traversal which allows copying of files from one directory to another. | ||
| CVE-2021-21683 | Med | 0.35 | 6.5 | 0.02 | Oct 6, 2021 | The file browser in Jenkins 2.314 and earlier, LTS 2.303.1 and earlier may interpret some paths to files as absolute on Windows, resulting in a path traversal vulnerability allowing attackers with Overall/Read permission (Windows controller) or Job/Workspace permission (Windows… | ||
| CVE-2020-15941 | Med | 0.35 | 5.4 | 0.01 | Oct 6, 2021 | A path traversal vulnerability [CWE-22] in FortiClientEMS versions 6.4.1 and below; 6.2.8 and below may allow an authenticated attacker to inject directory traversal character sequences to add/delete the files of the server via the name parameter of Deployment Packages. | ||
| CVE-2021-41596 | Med | 0.35 | 5.3 | 0.02 | Oct 4, 2021 | SuiteCRM before 7.10.33 and 7.11.22 allows information disclosure via Directory Traversal. An attacker can partially include arbitrary files via the importFile parameter of the RefreshMapping import functionality. | ||
| CVE-2021-41595 | Med | 0.35 | 5.3 | 0.02 | Oct 4, 2021 | SuiteCRM before 7.10.33 and 7.11.22 allows information disclosure via Directory Traversal. An attacker can partially include arbitrary files via the file_name parameter of the Step3 import functionality. | ||
| CVE-2021-21706 | Med | 0.35 | 5.3 | 0.01 | Oct 4, 2021 | In PHP versions 7.3.x below 7.3.31, 7.4.x below 7.4.24 and 8.0.x below 8.0.11, in Microsoft Windows environment, ZipArchive::extractTo may be tricked into writing a file outside target directory when extracting a ZIP file, thus potentially causing files to be created or… | ||
| CVE-2021-40349 | Med | 0.35 | 5.3 | 0.01 | Sep 27, 2021 | e7d Speed Test (aka speedtest) 0.5.3 allows a path-traversal attack that results in information disclosure via the "GET /.." substring. | ||
| CVE-2021-3806 | Med | 0.35 | 5.3 | 0.01 | Sep 18, 2021 | A path traversal vulnerability on Pardus Software Center's "extractArchive" function could allow anyone on the same network to do a man-in-the-middle and write files on the system. | ||
| CVE-2021-36717 | Med | 0.35 | 5.4 | 0.01 | Sep 7, 2021 | Synerion TimeNet version 9.21 contains a directory traversal vulnerability where, on the "Name" parameter, the attacker can return to the root directory and open the host file. This might give the attacker the ability to view restricted files, which could provide the attacker… | ||
| CVE-2020-18878 | Med | 0.35 | 5.3 | 0.02 | Aug 20, 2021 | Directory Traversal in Skycaiji v1.3 allows remote attackers to obtain sensitive information via the component 'index.php?m=admin&c=Tool&a=log&file=D%3A%5CphpStudy%5CWWW%5Cindex.php'. | ||
| CVE-2021-36156 | Med | 0.35 | 5.3 | 0.01 | Aug 3, 2021 | An issue was discovered in Grafana Loki through 2.2.1. The header value X-Scope-OrgID is used to construct file paths for rules files, and if crafted to conduct directory traversal such as ae ../../sensitive/path/in/deployment pathname, then Loki will attempt to parse a rules… | ||
| CVE-2021-30483 | Med | 0.35 | 5.3 | 0.02 | Jul 30, 2021 | isomorphic-git before 1.8.2 allows Directory Traversal via a crafted repository. |
- risk 0.35cvss 5.3epss 0.01
qrcp through 0.8.4, in receive mode, allows ../ Directory Traversal via the file name specified by the uploader.
- risk 0.35cvss 6.5epss 0.02
Path Traversal in GitHub repository pimcore/pimcore prior to 10.3.2.
- risk 0.35cvss 5.3epss 0.02
Directory Traversal vulnerability exists in ZZCMS 2021 via the skin parameter in 1) index.php, 2) bottom.php, and 3) top_index.php.
- risk 0.35cvss 5.3epss 0.02
Directory traversal in /northstar/Common/NorthFileManager/fileManagerObjects.jsp Northstar Technologies Inc NorthStar Club Management 6.3 allows remote unauthenticated users to browse and list the directories across the entire filesystem of the host of the web application.
- risk 0.35cvss 5.3epss 0.08
ChronoForums 2.0.11 allows av Directory Traversal to read arbitrary files.
- risk 0.35cvss 5.3epss 0.01
HwPCAssistant has a path traversal vulnerability. Successful exploitation of this vulnerability may affect data confidentiality.
- risk 0.35cvss 5.3epss 0.01
The CaasKit module has a path traversal vulnerability. Successful exploitation of this vulnerability may cause the MeeTime application to be unavailable.
- risk 0.35cvss 5.3epss 0.01
There is a Directory traversal vulnerability in Huawei Smartphone.Successful exploitation of this vulnerability may affect service confidentiality.
- risk 0.35cvss 5.3epss 0.02
Zoho ManageEngine ADManager Plus version 7110 and prior is vulnerable to path traversal which allows copying of files from one directory to another.
- risk 0.35cvss 6.5epss 0.02
The file browser in Jenkins 2.314 and earlier, LTS 2.303.1 and earlier may interpret some paths to files as absolute on Windows, resulting in a path traversal vulnerability allowing attackers with Overall/Read permission (Windows controller) or Job/Workspace permission (Windows…
- risk 0.35cvss 5.4epss 0.01
A path traversal vulnerability [CWE-22] in FortiClientEMS versions 6.4.1 and below; 6.2.8 and below may allow an authenticated attacker to inject directory traversal character sequences to add/delete the files of the server via the name parameter of Deployment Packages.
- risk 0.35cvss 5.3epss 0.02
SuiteCRM before 7.10.33 and 7.11.22 allows information disclosure via Directory Traversal. An attacker can partially include arbitrary files via the importFile parameter of the RefreshMapping import functionality.
- risk 0.35cvss 5.3epss 0.02
SuiteCRM before 7.10.33 and 7.11.22 allows information disclosure via Directory Traversal. An attacker can partially include arbitrary files via the file_name parameter of the Step3 import functionality.
- risk 0.35cvss 5.3epss 0.01
In PHP versions 7.3.x below 7.3.31, 7.4.x below 7.4.24 and 8.0.x below 8.0.11, in Microsoft Windows environment, ZipArchive::extractTo may be tricked into writing a file outside target directory when extracting a ZIP file, thus potentially causing files to be created or…
- risk 0.35cvss 5.3epss 0.01
e7d Speed Test (aka speedtest) 0.5.3 allows a path-traversal attack that results in information disclosure via the "GET /.." substring.
- risk 0.35cvss 5.3epss 0.01
A path traversal vulnerability on Pardus Software Center's "extractArchive" function could allow anyone on the same network to do a man-in-the-middle and write files on the system.
- risk 0.35cvss 5.4epss 0.01
Synerion TimeNet version 9.21 contains a directory traversal vulnerability where, on the "Name" parameter, the attacker can return to the root directory and open the host file. This might give the attacker the ability to view restricted files, which could provide the attacker…
- risk 0.35cvss 5.3epss 0.02
Directory Traversal in Skycaiji v1.3 allows remote attackers to obtain sensitive information via the component 'index.php?m=admin&c=Tool&a=log&file=D%3A%5CphpStudy%5CWWW%5Cindex.php'.
- risk 0.35cvss 5.3epss 0.01
An issue was discovered in Grafana Loki through 2.2.1. The header value X-Scope-OrgID is used to construct file paths for rules files, and if crafted to conduct directory traversal such as ae ../../sensitive/path/in/deployment pathname, then Loki will attempt to parse a rules…
- risk 0.35cvss 5.3epss 0.02
isomorphic-git before 1.8.2 allows Directory Traversal via a crafted repository.