CWE-22
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
Description
The product uses external input to construct a pathname that is intended to identify a file or directory that is located underneath a restricted parent directory, but the product does not properly neutralize special elements within the pathname that can cause the pathname to resolve to a location that is outside of the restricted directory.
Hierarchy (View 1000)
Related attack patterns (CAPEC)
CAPEC-126 · CAPEC-64 · CAPEC-76 · CAPEC-78 · CAPEC-79
CVEs mapped to this weakness (10,485)
page 338 of 525| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2020-12765 | Med | 0.35 | 5.3 | 0.01 | May 9, 2020 | Solis Miolo 2.0 allows index.php?module=install&action=view&item= Directory Traversal. | ||
| CVE-2020-12764 | Med | 0.35 | 5.3 | 0.01 | May 9, 2020 | Gnuteca 3.8 allows file.php?folder=/&file= Directory Traversal. | ||
| CVE-2020-12448 | Med | 0.35 | 5.3 | 0.01 | May 7, 2020 | GitLab EE 12.8 and later allows Exposure of Sensitive Information to an Unauthorized Actor via NuGet. | ||
| CVE-2020-4209 | Med | 0.35 | 5.4 | 0.01 | May 4, 2020 | IBM Spectrum Protect Plus 10.1.0 through 10.1.5 could allow a remote attacker to traverse directories on the system. An attacker could send a specially-crafted URL request containing "dot dot" sequences (/../) to create arbitrary files on the system. IBM X-Force ID: 175019. | ||
| CVE-2020-11491 | Med | 0.35 | 4.9 | 0.08 | Apr 2, 2020 | Monitoring::Logs in Zen Load Balancer 3.10.1 allows remote authenticated admins to conduct absolute path traversal attacks, as demonstrated by a filelog=/etc/shadow request to index.cgi. | ||
| CVE-2020-9323 | Med | 0.35 | 5.3 | 0.02 | Mar 18, 2020 | Aquaforest TIFF Server 4.0 allows Unauthenticated File and Directory Enumeration via tiffserver/tssp.aspx. | ||
| CVE-2018-18576 | Med | 0.35 | 5.3 | 0.01 | Mar 17, 2020 | The Hustle (aka wordpress-popup) plugin through 6.0.5 for WordPress allows Directory Traversal to obtain a directory listing via the views/admin/dashboard/ URI. | ||
| CVE-2020-10086 | Med | 0.35 | 5.3 | 0.01 | Mar 13, 2020 | GitLab 10.4 through 12.8.1 allows Directory Traversal. A particular endpoint was vulnerable to a directory traversal vulnerability, leading to arbitrary file read. | ||
| CVE-2020-10387 | Med | 0.35 | 4.9 | 0.08 | Mar 12, 2020 | Path Traversal in admin/download.php in Chadha PHPKB Standard Multi-Language 9 allows remote attackers to download files from the server using a dot-dot-slash sequence (../) via the GET parameter file. | ||
| CVE-2020-2139 | Med | 0.35 | 6.5 | 0.02 | Mar 9, 2020 | An arbitrary file write vulnerability in Jenkins Cobertura Plugin 1.15 and earlier allows attackers able to control the coverage report file contents to overwrite any file on the Jenkins master file system. | ||
| CVE-2020-9364 | Med | 0.35 | 5.3 | 0.03 | Mar 4, 2020 | An issue was discovered in helpers/mailer.php in the Creative Contact Form extension 4.6.2 before 2019-12-03 for Joomla!. A directory traversal vulnerability resides in the filename field for uploaded attachments via the creativecontactform_upload parameter. An attacker could… | ||
| CVE-2014-9609 | Med | 0.35 | 5.3 | 0.13 | Feb 19, 2020 | Directory traversal vulnerability in webadmin/reporter/view_server_log.php in Netsweeper before 3.1.10, 4.0.x before 4.0.9, and 4.1.x before 4.1.2 allows remote attackers to list directory contents via a .. (dot dot) in the log parameter in a stats action. | ||
| CVE-2020-3717 | Med | 0.35 | 5.3 | 0.03 | Jan 29, 2020 | Magento versions 2.3.3 and earlier, 2.2.10 and earlier, 1.14.4.3 and earlier, and 1.9.4.3 and earlier have a path traversal vulnerability. Successful exploitation could lead to sensitive information disclosure. | ||
| CVE-2020-1606 | Med | 0.35 | 5.4 | 0.01 | Jan 15, 2020 | A path traversal vulnerability in the Juniper Networks Junos OS device may allow an authenticated J-web user to read files with 'world' readable permission and delete files with 'world' writeable permission. This issue does not affect system files that can be accessed only by… | ||
| CVE-2019-19845 | Med | 0.35 | 5.3 | 0.01 | Dec 18, 2019 | In Joomla! before 3.9.14, a missing access check in framework files could lead to a path disclosure. | ||
| CVE-2019-13944 | Med | 0.35 | 5.3 | 0.02 | Dec 12, 2019 | A vulnerability has been identified in EN100 Ethernet module DNP3 variant (All versions), EN100 Ethernet module IEC 61850 variant (All versions < V4.37), EN100 Ethernet module IEC104 variant (All versions), EN100 Ethernet module Modbus TCP variant (All versions), EN100 Ethernet… | ||
| CVE-2015-2060 | Med | 0.35 | 5.3 | 0.02 | Nov 29, 2019 | cabextract before 1.6 does not properly check for leading slashes when extracting files, which allows remote attackers to conduct absolute directory traversal attacks via a malformed UTF-8 character that is changed to a UTF-8 encoded slash. | ||
| CVE-2019-17406 | Med | 0.35 | 5.3 | 0.01 | Nov 25, 2019 | Nokia IMPACT < 18A has path traversal that may lead to RCE if chained with CVE-2019-1743 | ||
| CVE-2019-16540 | Med | 0.35 | 6.5 | 0.02 | Nov 21, 2019 | A path traversal vulnerability in Jenkins Support Core Plugin 2.63 and earlier allows attackers with Overall/Read permission to delete arbitrary files on the Jenkins master. | ||
| CVE-2019-3423 | Med | 0.35 | 5.3 | 0.01 | Nov 18, 2019 | permission and access control vulnerability, which exists in V2.1.14 and below versions of C520V21 smart camera devices. An attacker can construct a URL for directory traversal and access to other unauthorized files or resources. |
- risk 0.35cvss 5.3epss 0.01
Solis Miolo 2.0 allows index.php?module=install&action=view&item= Directory Traversal.
- risk 0.35cvss 5.3epss 0.01
Gnuteca 3.8 allows file.php?folder=/&file= Directory Traversal.
- risk 0.35cvss 5.3epss 0.01
GitLab EE 12.8 and later allows Exposure of Sensitive Information to an Unauthorized Actor via NuGet.
- risk 0.35cvss 5.4epss 0.01
IBM Spectrum Protect Plus 10.1.0 through 10.1.5 could allow a remote attacker to traverse directories on the system. An attacker could send a specially-crafted URL request containing "dot dot" sequences (/../) to create arbitrary files on the system. IBM X-Force ID: 175019.
- risk 0.35cvss 4.9epss 0.08
Monitoring::Logs in Zen Load Balancer 3.10.1 allows remote authenticated admins to conduct absolute path traversal attacks, as demonstrated by a filelog=/etc/shadow request to index.cgi.
- risk 0.35cvss 5.3epss 0.02
Aquaforest TIFF Server 4.0 allows Unauthenticated File and Directory Enumeration via tiffserver/tssp.aspx.
- risk 0.35cvss 5.3epss 0.01
The Hustle (aka wordpress-popup) plugin through 6.0.5 for WordPress allows Directory Traversal to obtain a directory listing via the views/admin/dashboard/ URI.
- risk 0.35cvss 5.3epss 0.01
GitLab 10.4 through 12.8.1 allows Directory Traversal. A particular endpoint was vulnerable to a directory traversal vulnerability, leading to arbitrary file read.
- risk 0.35cvss 4.9epss 0.08
Path Traversal in admin/download.php in Chadha PHPKB Standard Multi-Language 9 allows remote attackers to download files from the server using a dot-dot-slash sequence (../) via the GET parameter file.
- risk 0.35cvss 6.5epss 0.02
An arbitrary file write vulnerability in Jenkins Cobertura Plugin 1.15 and earlier allows attackers able to control the coverage report file contents to overwrite any file on the Jenkins master file system.
- risk 0.35cvss 5.3epss 0.03
An issue was discovered in helpers/mailer.php in the Creative Contact Form extension 4.6.2 before 2019-12-03 for Joomla!. A directory traversal vulnerability resides in the filename field for uploaded attachments via the creativecontactform_upload parameter. An attacker could…
- risk 0.35cvss 5.3epss 0.13
Directory traversal vulnerability in webadmin/reporter/view_server_log.php in Netsweeper before 3.1.10, 4.0.x before 4.0.9, and 4.1.x before 4.1.2 allows remote attackers to list directory contents via a .. (dot dot) in the log parameter in a stats action.
- risk 0.35cvss 5.3epss 0.03
Magento versions 2.3.3 and earlier, 2.2.10 and earlier, 1.14.4.3 and earlier, and 1.9.4.3 and earlier have a path traversal vulnerability. Successful exploitation could lead to sensitive information disclosure.
- risk 0.35cvss 5.4epss 0.01
A path traversal vulnerability in the Juniper Networks Junos OS device may allow an authenticated J-web user to read files with 'world' readable permission and delete files with 'world' writeable permission. This issue does not affect system files that can be accessed only by…
- risk 0.35cvss 5.3epss 0.01
In Joomla! before 3.9.14, a missing access check in framework files could lead to a path disclosure.
- risk 0.35cvss 5.3epss 0.02
A vulnerability has been identified in EN100 Ethernet module DNP3 variant (All versions), EN100 Ethernet module IEC 61850 variant (All versions < V4.37), EN100 Ethernet module IEC104 variant (All versions), EN100 Ethernet module Modbus TCP variant (All versions), EN100 Ethernet…
- risk 0.35cvss 5.3epss 0.02
cabextract before 1.6 does not properly check for leading slashes when extracting files, which allows remote attackers to conduct absolute directory traversal attacks via a malformed UTF-8 character that is changed to a UTF-8 encoded slash.
- risk 0.35cvss 5.3epss 0.01
Nokia IMPACT < 18A has path traversal that may lead to RCE if chained with CVE-2019-1743
- risk 0.35cvss 6.5epss 0.02
A path traversal vulnerability in Jenkins Support Core Plugin 2.63 and earlier allows attackers with Overall/Read permission to delete arbitrary files on the Jenkins master.
- risk 0.35cvss 5.3epss 0.01
permission and access control vulnerability, which exists in V2.1.14 and below versions of C520V21 smart camera devices. An attacker can construct a URL for directory traversal and access to other unauthorized files or resources.