CWE-22
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
Description
The product uses external input to construct a pathname that is intended to identify a file or directory that is located underneath a restricted parent directory, but the product does not properly neutralize special elements within the pathname that can cause the pathname to resolve to a location that is outside of the restricted directory.
Hierarchy (View 1000)
Related attack patterns (CAPEC)
CAPEC-126 · CAPEC-64 · CAPEC-76 · CAPEC-78 · CAPEC-79
CVEs mapped to this weakness (10,485)
page 339 of 525| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2019-18924 | Med | 0.35 | 5.3 | 0.01 | Nov 12, 2019 | Systematic IRIS WebForms 5.4 is vulnerable to directory traversal. By manipulating variables that reference files with ../ (and variations), it is possible to list all the directories and check if a particular file exists. | ||
| CVE-2019-15003 | Med | 0.35 | 5.3 | 0.02 | Nov 7, 2019 | The Customer Context Filter in Atlassian Jira Service Desk Server and Jira Service Desk Data Center before 3.9.17, from 3.10.0 before 3.16.10, from 4.0.0 before 4.2.6, from 4.3.0 before 4.3.5, from 4.4.0 before 4.4.3, and from 4.5.0 before 4.5.1 allows remote attackers with… | ||
| CVE-2019-17224 | Med | 0.35 | 5.3 | 0.01 | Oct 28, 2019 | The web interface of the Compal Broadband CH7465LG modem (version CH7465LG-NCIP-6.12.18.25-2p6-NOSH) is vulnerable to a /%2f/ path traversal attack, which can be exploited in order to test for the existence of a file pathname outside of the web root directory. If a file exists… | ||
| CVE-2019-18212 | Med | 0.35 | 6.5 | 0.03 | Oct 23, 2019 | XMLLanguageService.java in XML Language Server (aka lsp4xml) before 0.9.1, as used in Red Hat XML Language Support (aka vscode-xml) before 0.9.1 for Visual Studio and other products, allows a remote attacker to write to arbitrary files via Directory Traversal. | ||
| CVE-2019-16986 | Med | 0.35 | 6.5 | 0.01 | Oct 21, 2019 | In FusionPBX up to v4.5.7, the file resources\download.php uses an unsanitized "f" variable coming from the URL, which takes any pathname and allows a download of it. (resources\secure_download.php is also affected.) | ||
| CVE-2019-16985 | Med | 0.35 | 6.5 | 0.01 | Oct 21, 2019 | In FusionPBX up to v4.5.7, the file app\xml_cdr\xml_cdr_delete.php uses an unsanitized "rec" variable coming from the URL, which is base64 decoded and allows deletion of any file of the system. | ||
| CVE-2019-16990 | Med | 0.35 | 6.5 | 0.01 | Oct 21, 2019 | In FusionPBX up to v4.5.7, the file app/music_on_hold/music_on_hold.php uses an unsanitized "file" variable coming from the URL, which takes any pathname (base64 encoded) and allows a download of it. | ||
| CVE-2019-10436 | Med | 0.35 | 6.5 | 0.01 | Oct 16, 2019 | An arbitrary file read vulnerability in Jenkins Google OAuth Credentials Plugin 0.9 and earlier allowed attackers able to configure jobs and credentials in Jenkins to obtain the contents of any file on the Jenkins master. | ||
| CVE-2019-17109 | Med | 0.35 | 6.5 | 0.03 | Oct 9, 2019 | Koji through 1.18.0 allows remote Directory Traversal, with resultant Privilege Escalation. | ||
| CVE-2019-4423 | Med | 0.35 | 5.3 | 0.03 | Sep 30, 2019 | IBM Sterling File Gateway 2.2.0.0 through 6.0.1.0 could allow a remote attacker to traverse directories on the system. An attacker could send a specially-crafted URL request containing "dot dot" sequences (/../) to view arbitrary files on the system. IBM X-Force ID: 162769. | ||
| CVE-2019-16903 | Med | 0.35 | 5.3 | 0.02 | Sep 26, 2019 | Platinum UPnP SDK 1.2.0 allows Directory Traversal in Core/PltHttpServer.cpp because it checks for /.. where it should be checking for ../ instead. | ||
| CVE-2019-16679 | Med | 0.35 | 4.9 | 0.07 | Sep 21, 2019 | Gila CMS before 1.11.1 allows admin/fm/?f=../ directory traversal, leading to Local File Inclusion. | ||
| CVE-2019-4268 | Med | 0.35 | 5.3 | 0.03 | Sep 17, 2019 | IBM WebSphere Application Server 7.0, 8.0, 8.5, and 9.0 could allow a remote attacker to traverse directories on the system. An attacker could send a specially-crafted URL containing "dot dot" sequences (/../) to view arbitrary files on the system. IBM X-Force ID: 160201. | ||
| CVE-2019-5480 | Med | 0.35 | 5.3 | 0.02 | Sep 3, 2019 | A path traversal vulnerability in <= v0.9.7 of statichttpserver npm module allows attackers to list files in arbitrary folders. | ||
| CVE-2019-15714 | Med | 0.35 | 5.3 | 0.02 | Aug 28, 2019 | cli/lib/main.js in Entropic before 2019-06-13 does not reject / and \ in command names, which might allow a directory traversal attack in unusual situations. | ||
| CVE-2019-15520 | Med | 0.35 | 5.3 | 0.02 | Aug 23, 2019 | comelz Quark before 2019-03-26 allows directory traversal to locations outside of the project directory. | ||
| CVE-2019-15518 | Med | 0.35 | 5.3 | 0.02 | Aug 23, 2019 | Swoole before 4.2.13 allows directory traversal in swPort_http_static_handler. | ||
| CVE-2017-18448 | Med | 0.35 | 5.3 | 0.01 | Aug 2, 2019 | cPanel before 64.0.21 allows certain file-read operations via a Serverinfo_manpage API call (SEC-252). | ||
| CVE-2019-14362 | Med | 0.35 | 5.4 | 0.02 | Jul 28, 2019 | Openbravo ERP before 3.0PR19Q1.3 is affected by Directory Traversal. This vulnerability could allow remote authenticated attackers to replace a file on the server via the getAttachmentDirectoryForNewAttachment inpKey value. | ||
| CVE-2019-13584 | Med | 0.35 | 5.3 | 0.03 | Jul 17, 2019 | The remote admin webserver on FANUC Robotics Virtual Robot Controller 8.23 allows Directory Traversal via a forged HTTP request. |
- risk 0.35cvss 5.3epss 0.01
Systematic IRIS WebForms 5.4 is vulnerable to directory traversal. By manipulating variables that reference files with ../ (and variations), it is possible to list all the directories and check if a particular file exists.
- risk 0.35cvss 5.3epss 0.02
The Customer Context Filter in Atlassian Jira Service Desk Server and Jira Service Desk Data Center before 3.9.17, from 3.10.0 before 3.16.10, from 4.0.0 before 4.2.6, from 4.3.0 before 4.3.5, from 4.4.0 before 4.4.3, and from 4.5.0 before 4.5.1 allows remote attackers with…
- risk 0.35cvss 5.3epss 0.01
The web interface of the Compal Broadband CH7465LG modem (version CH7465LG-NCIP-6.12.18.25-2p6-NOSH) is vulnerable to a /%2f/ path traversal attack, which can be exploited in order to test for the existence of a file pathname outside of the web root directory. If a file exists…
- risk 0.35cvss 6.5epss 0.03
XMLLanguageService.java in XML Language Server (aka lsp4xml) before 0.9.1, as used in Red Hat XML Language Support (aka vscode-xml) before 0.9.1 for Visual Studio and other products, allows a remote attacker to write to arbitrary files via Directory Traversal.
- risk 0.35cvss 6.5epss 0.01
In FusionPBX up to v4.5.7, the file resources\download.php uses an unsanitized "f" variable coming from the URL, which takes any pathname and allows a download of it. (resources\secure_download.php is also affected.)
- risk 0.35cvss 6.5epss 0.01
In FusionPBX up to v4.5.7, the file app\xml_cdr\xml_cdr_delete.php uses an unsanitized "rec" variable coming from the URL, which is base64 decoded and allows deletion of any file of the system.
- risk 0.35cvss 6.5epss 0.01
In FusionPBX up to v4.5.7, the file app/music_on_hold/music_on_hold.php uses an unsanitized "file" variable coming from the URL, which takes any pathname (base64 encoded) and allows a download of it.
- risk 0.35cvss 6.5epss 0.01
An arbitrary file read vulnerability in Jenkins Google OAuth Credentials Plugin 0.9 and earlier allowed attackers able to configure jobs and credentials in Jenkins to obtain the contents of any file on the Jenkins master.
- risk 0.35cvss 6.5epss 0.03
Koji through 1.18.0 allows remote Directory Traversal, with resultant Privilege Escalation.
- risk 0.35cvss 5.3epss 0.03
IBM Sterling File Gateway 2.2.0.0 through 6.0.1.0 could allow a remote attacker to traverse directories on the system. An attacker could send a specially-crafted URL request containing "dot dot" sequences (/../) to view arbitrary files on the system. IBM X-Force ID: 162769.
- risk 0.35cvss 5.3epss 0.02
Platinum UPnP SDK 1.2.0 allows Directory Traversal in Core/PltHttpServer.cpp because it checks for /.. where it should be checking for ../ instead.
- risk 0.35cvss 4.9epss 0.07
Gila CMS before 1.11.1 allows admin/fm/?f=../ directory traversal, leading to Local File Inclusion.
- risk 0.35cvss 5.3epss 0.03
IBM WebSphere Application Server 7.0, 8.0, 8.5, and 9.0 could allow a remote attacker to traverse directories on the system. An attacker could send a specially-crafted URL containing "dot dot" sequences (/../) to view arbitrary files on the system. IBM X-Force ID: 160201.
- risk 0.35cvss 5.3epss 0.02
A path traversal vulnerability in <= v0.9.7 of statichttpserver npm module allows attackers to list files in arbitrary folders.
- risk 0.35cvss 5.3epss 0.02
cli/lib/main.js in Entropic before 2019-06-13 does not reject / and \ in command names, which might allow a directory traversal attack in unusual situations.
- risk 0.35cvss 5.3epss 0.02
comelz Quark before 2019-03-26 allows directory traversal to locations outside of the project directory.
- risk 0.35cvss 5.3epss 0.02
Swoole before 4.2.13 allows directory traversal in swPort_http_static_handler.
- risk 0.35cvss 5.3epss 0.01
cPanel before 64.0.21 allows certain file-read operations via a Serverinfo_manpage API call (SEC-252).
- risk 0.35cvss 5.4epss 0.02
Openbravo ERP before 3.0PR19Q1.3 is affected by Directory Traversal. This vulnerability could allow remote authenticated attackers to replace a file on the server via the getAttachmentDirectoryForNewAttachment inpKey value.
- risk 0.35cvss 5.3epss 0.03
The remote admin webserver on FANUC Robotics Virtual Robot Controller 8.23 allows Directory Traversal via a forged HTTP request.