CWE-22
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
Description
The product uses external input to construct a pathname that is intended to identify a file or directory that is located underneath a restricted parent directory, but the product does not properly neutralize special elements within the pathname that can cause the pathname to resolve to a location that is outside of the restricted directory.
Hierarchy (View 1000)
Related attack patterns (CAPEC)
CAPEC-126 · CAPEC-64 · CAPEC-76 · CAPEC-78 · CAPEC-79
CVEs mapped to this weakness (10,485)
page 337 of 525| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2020-28348 | Med | 0.35 | 6.5 | 0.02 | Nov 24, 2020 | HashiCorp Nomad and Nomad Enterprise 0.9.0 up to 0.12.7 client Docker file sandbox feature may be subverted when not explicitly disabled or when using a volume mount type. Fixed in 0.12.8, 0.11.7, and 0.10.8. | ||
| CVE-2020-15928 | Med | 0.35 | 5.3 | 0.02 | Nov 24, 2020 | In Ortus TestBox 2.4.0 through 4.1.0, unvalidated query string parameters to test-browser/index.cfm allow directory traversal. | ||
| CVE-2020-7762 | Med | 0.35 | 6.5 | 0.02 | Nov 5, 2020 | This affects the package jsreport-chrome-pdf before 1.10.0. | ||
| CVE-2020-27993 | Med | 0.35 | 5.3 | 0.03 | Oct 29, 2020 | Hrsale 2.0.0 allows download?type=files&filename=../ directory traversal to read arbitrary files. | ||
| CVE-2020-26650 | Med | 0.35 | 5.3 | 0.01 | Oct 22, 2020 | AtomXCMS 2.0 is affected by Arbitrary File Read via admin/dump.php | ||
| CVE-2020-3597 | Med | 0.35 | 5.4 | 0.01 | Oct 8, 2020 | A vulnerability in the configuration restore feature of Cisco Nexus Data Broker software could allow an unauthenticated, remote attacker to perform a directory traversal attack on an affected device. The vulnerability is due to insufficient validation of configuration backup… | ||
| CVE-2020-25734 | Med | 0.35 | 5.3 | 0.02 | Sep 18, 2020 | webTareas through 2.1 allows files/Default/ Directory Listing. | ||
| CVE-2020-2254 | Med | 0.35 | 6.5 | 0.02 | Sep 16, 2020 | Jenkins Blue Ocean Plugin 1.23.2 and earlier provides an undocumented feature flag that, when enabled, allows an attacker with Job/Configure or Job/Create permission to read arbitrary files on the Jenkins controller file system. | ||
| CVE-2012-3337 | Med | 0.35 | 5.3 | 0.02 | Sep 1, 2020 | IBM InfoSphere Guardium 8.0, 8.01, and 8.2 could allow a remote attacker to traverse directories on the system. An attacker could send a specially-crafted URL request containing "dot dot" sequences (/../) to download arbitrary files on the system. IBM X-Force ID: 78284. | ||
| CVE-2020-19877 | Med | 0.35 | 5.3 | 0.02 | Aug 24, 2020 | DBHcms v1.2.0 has a directory traversal vulnerability as there is no directory control function in directory /dbhcms/. A remote unauthenticated attacker can exploit this vulnerability to obtain server-sensitive information. | ||
| CVE-2020-5614 | Med | 0.35 | 5.3 | 0.02 | Jul 29, 2020 | Directory traversal vulnerability in KonaWiki 3.1.0 and earlier allows remote attackers to read arbitrary files via unspecified vectors. | ||
| CVE-2020-9663 | Med | 0.35 | 5.3 | 0.03 | Jul 22, 2020 | Adobe Reader Mobile versions 20.0.1 and earlier have a directory traversal vulnerability. Successful exploitation could lead to information disclosure. | ||
| CVE-2017-18874 | Med | 0.35 | 6.5 | 0.01 | Jun 19, 2020 | An issue was discovered in Mattermost Server before 4.3.0, 4.2.1, and 4.1.2 when local storage for files is used. A System Admin can achieve directory traversal. | ||
| CVE-2020-14452 | Med | 0.35 | 5.3 | 0.01 | Jun 19, 2020 | An issue was discovered in Mattermost Server before 5.21.0. mmctl allows directory traversal via HTTP, aka MMSA-2020-0014. | ||
| CVE-2020-13795 | Med | 0.35 | 5.3 | 0.02 | Jun 3, 2020 | An issue was discovered in Navigate CMS through 2.8.7. It allows Directory Traversal because lib/packages/templates/template.class.php mishandles ../ and ..\ substrings. | ||
| CVE-2020-13227 | Med | 0.35 | 5.3 | 0.02 | Jun 2, 2020 | An issue was discovered in Sysax Multi Server 6.90. An attacker can determine the username (under which the web server is running) by triggering an invalid path permission error. This bypasses the fakepath protection mechanism. | ||
| CVE-2014-8939 | Med | 0.35 | 5.3 | 0.01 | Jun 1, 2020 | Lexiglot through 2014-11-20 allows remote attackers to obtain sensitive information (full path) via an include/smarty/plugins/modifier.date_format.php request if PHP has a non-recommended configuration that produces warning messages. | ||
| CVE-2014-7174 | Med | 0.35 | 5.3 | 0.01 | Jun 1, 2020 | FarLinX X25 Gateway through 2014-09-25 allows directory traversal via the log-handling feature. | ||
| CVE-2020-13093 | Med | 0.35 | 5.3 | 0.01 | May 15, 2020 | iSpyConnect.com Agent DVR before 2.7.1.0 allows directory traversal. | ||
| CVE-2020-5834 | Med | 0.35 | 5.3 | 0.02 | May 11, 2020 | Symantec Endpoint Protection Manager, prior to 14.3, may be susceptible to a directory traversal attack that could allow a remote actor to determine the size of files in the directory. |
- risk 0.35cvss 6.5epss 0.02
HashiCorp Nomad and Nomad Enterprise 0.9.0 up to 0.12.7 client Docker file sandbox feature may be subverted when not explicitly disabled or when using a volume mount type. Fixed in 0.12.8, 0.11.7, and 0.10.8.
- risk 0.35cvss 5.3epss 0.02
In Ortus TestBox 2.4.0 through 4.1.0, unvalidated query string parameters to test-browser/index.cfm allow directory traversal.
- risk 0.35cvss 6.5epss 0.02
This affects the package jsreport-chrome-pdf before 1.10.0.
- risk 0.35cvss 5.3epss 0.03
Hrsale 2.0.0 allows download?type=files&filename=../ directory traversal to read arbitrary files.
- risk 0.35cvss 5.3epss 0.01
AtomXCMS 2.0 is affected by Arbitrary File Read via admin/dump.php
- risk 0.35cvss 5.4epss 0.01
A vulnerability in the configuration restore feature of Cisco Nexus Data Broker software could allow an unauthenticated, remote attacker to perform a directory traversal attack on an affected device. The vulnerability is due to insufficient validation of configuration backup…
- risk 0.35cvss 5.3epss 0.02
webTareas through 2.1 allows files/Default/ Directory Listing.
- risk 0.35cvss 6.5epss 0.02
Jenkins Blue Ocean Plugin 1.23.2 and earlier provides an undocumented feature flag that, when enabled, allows an attacker with Job/Configure or Job/Create permission to read arbitrary files on the Jenkins controller file system.
- risk 0.35cvss 5.3epss 0.02
IBM InfoSphere Guardium 8.0, 8.01, and 8.2 could allow a remote attacker to traverse directories on the system. An attacker could send a specially-crafted URL request containing "dot dot" sequences (/../) to download arbitrary files on the system. IBM X-Force ID: 78284.
- risk 0.35cvss 5.3epss 0.02
DBHcms v1.2.0 has a directory traversal vulnerability as there is no directory control function in directory /dbhcms/. A remote unauthenticated attacker can exploit this vulnerability to obtain server-sensitive information.
- risk 0.35cvss 5.3epss 0.02
Directory traversal vulnerability in KonaWiki 3.1.0 and earlier allows remote attackers to read arbitrary files via unspecified vectors.
- risk 0.35cvss 5.3epss 0.03
Adobe Reader Mobile versions 20.0.1 and earlier have a directory traversal vulnerability. Successful exploitation could lead to information disclosure.
- risk 0.35cvss 6.5epss 0.01
An issue was discovered in Mattermost Server before 4.3.0, 4.2.1, and 4.1.2 when local storage for files is used. A System Admin can achieve directory traversal.
- risk 0.35cvss 5.3epss 0.01
An issue was discovered in Mattermost Server before 5.21.0. mmctl allows directory traversal via HTTP, aka MMSA-2020-0014.
- risk 0.35cvss 5.3epss 0.02
An issue was discovered in Navigate CMS through 2.8.7. It allows Directory Traversal because lib/packages/templates/template.class.php mishandles ../ and ..\ substrings.
- risk 0.35cvss 5.3epss 0.02
An issue was discovered in Sysax Multi Server 6.90. An attacker can determine the username (under which the web server is running) by triggering an invalid path permission error. This bypasses the fakepath protection mechanism.
- risk 0.35cvss 5.3epss 0.01
Lexiglot through 2014-11-20 allows remote attackers to obtain sensitive information (full path) via an include/smarty/plugins/modifier.date_format.php request if PHP has a non-recommended configuration that produces warning messages.
- risk 0.35cvss 5.3epss 0.01
FarLinX X25 Gateway through 2014-09-25 allows directory traversal via the log-handling feature.
- risk 0.35cvss 5.3epss 0.01
iSpyConnect.com Agent DVR before 2.7.1.0 allows directory traversal.
- risk 0.35cvss 5.3epss 0.02
Symantec Endpoint Protection Manager, prior to 14.3, may be susceptible to a directory traversal attack that could allow a remote actor to determine the size of files in the directory.