CWE-22
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
Description
The product uses external input to construct a pathname that is intended to identify a file or directory that is located underneath a restricted parent directory, but the product does not properly neutralize special elements within the pathname that can cause the pathname to resolve to a location that is outside of the restricted directory.
Hierarchy (View 1000)
Related attack patterns (CAPEC)
CAPEC-126 · CAPEC-64 · CAPEC-76 · CAPEC-78 · CAPEC-79
CVEs mapped to this weakness (10,485)
page 340 of 525| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2019-5447 | Med | 0.35 | 5.3 | 0.01 | Jul 15, 2019 | A path traversal vulnerability in <= v0.2.6 of http-file-server npm module allows attackers to list files in arbitrary folders. | ||
| CVE-2019-5444 | Med | 0.35 | 5.3 | 0.01 | Jul 10, 2019 | Path traversal vulnerability in version up to v1.1.3 in serve-here.js npm module allows attackers to list any file in arbitrary folder. | ||
| CVE-2018-18876 | Med | 0.35 | 5.3 | 0.02 | Jun 18, 2019 | In firmware version MS_2.6.9900 of Columbia Weather MicroServer, a readouts_rd.php directory traversal issue makes it possible to read any file present on the underlying operating system. | ||
| CVE-2019-12143 | Med | 0.35 | 5.3 | 0.02 | Jun 11, 2019 | A Directory Traversal issue was discovered in SSHServerAPI.dll in Progress ipswitch WS_FTP Server 2018 before 8.6.1. An attacker can supply a string using special patterns via the SCP protocol to disclose WS_FTP usernames as well as filenames. | ||
| CVE-2019-12459 | Med | 0.35 | 5.3 | 0.02 | May 30, 2019 | FileRun 2019.05.21 allows customizables/plugins/audio_player Directory Listing. This issue has been fixed in FileRun 2019.06.01. | ||
| CVE-2019-12458 | Med | 0.35 | 5.3 | 0.02 | May 30, 2019 | FileRun 2019.05.21 allows css/ext-ux Directory Listing. This issue has been fixed in FileRun 2019.06.01. | ||
| CVE-2019-12457 | Med | 0.35 | 5.3 | 0.02 | May 30, 2019 | FileRun 2019.05.21 allows images/extjs Directory Listing. This issue has been fixed in FileRun 2019.06.01. | ||
| CVE-2019-5936 | Med | 0.35 | 5.4 | 0.02 | May 17, 2019 | Directory traversal vulnerability in Cybozu Garoon 4.0.0 to 4.10.1 allows remote authenticated attackers to obtain files without access privileges via the application 'Work Flow'. | ||
| CVE-2018-17180 | Med | 0.35 | 5.3 | 0.02 | May 17, 2019 | An issue was discovered in OpenEMR before 5.0.1 Patch 7. Directory Traversal exists via docid=../ to /portal/lib/download_template.php. | ||
| CVE-2019-5438 | Med | 0.35 | 5.3 | 0.01 | May 10, 2019 | Path traversal using symlink in npm harp module versions <= 0.29.0. | ||
| CVE-2019-10242 | Med | 0.35 | 5.3 | 0.02 | Apr 9, 2019 | In Eclipse Kura versions up to 4.0.0, the SkinServlet did not checked the path passed during servlet call, potentially allowing path traversal in get requests for a limited number of file types. | ||
| CVE-2018-20631 | Med | 0.35 | 5.3 | 0.02 | Mar 21, 2019 | PHP Scripts Mall Website Seller Script 2.0.5 allows full Path Disclosure via a request for an arbitrary image URL such as a .png file. | ||
| CVE-2018-20630 | Med | 0.35 | 5.3 | 0.02 | Mar 21, 2019 | PHP Scripts Mall Advance Crowdfunding Script 2.0.3 has directory traversal via a direct request for a listing of an uploads directory such as the wp-content/uploads/2018/12 directory. | ||
| CVE-2018-20629 | Med | 0.35 | 5.3 | 0.02 | Mar 21, 2019 | PHP Scripts Mall Charity Donation Script readymadeb2bscript has directory traversal via a direct request for a listing of an uploads directory such as the wp-content/uploads/2018/12 directory. | ||
| CVE-2019-9607 | Med | 0.35 | 5.3 | 0.02 | Mar 6, 2019 | PHP Scripts Mall Medical Store Script 3.0.3 allows Path Traversal by navigating to the parent directory of a jpg or png file. | ||
| CVE-2019-9064 | Med | 0.35 | 5.3 | 0.02 | Feb 23, 2019 | PHP Scripts Mall Cab Booking Script 1.0.3 allows Directory Traversal into the parent directory of a jpg or png file. | ||
| CVE-2013-2565 | Med | 0.35 | 5.3 | 0.02 | Feb 15, 2019 | A vulnerability in Mambo CMS v4.6.5 where the scripts thumbs.php, editorFrame.php, editor.php, images.php, manager.php discloses the root path of the webserver. | ||
| CVE-2015-9275 | Med | 0.35 | 5.3 | 0.02 | Jan 7, 2019 | ARC 5.21q allows directory traversal via a full pathname in an archive file. | ||
| CVE-2018-20566 | Med | 0.35 | 5.3 | 0.01 | Dec 28, 2018 | An issue was discovered in DouCo DouPHP 1.5 20181221. It allows full path disclosure in "Smarty error: unable to read resource" error messages for a crafted installation page. | ||
| CVE-2018-19859 | Med | 0.35 | 6.5 | 0.02 | Dec 5, 2018 | OpenRefine before 3.2 beta allows directory traversal via a relative pathname in a ZIP archive. |
- risk 0.35cvss 5.3epss 0.01
A path traversal vulnerability in <= v0.2.6 of http-file-server npm module allows attackers to list files in arbitrary folders.
- risk 0.35cvss 5.3epss 0.01
Path traversal vulnerability in version up to v1.1.3 in serve-here.js npm module allows attackers to list any file in arbitrary folder.
- risk 0.35cvss 5.3epss 0.02
In firmware version MS_2.6.9900 of Columbia Weather MicroServer, a readouts_rd.php directory traversal issue makes it possible to read any file present on the underlying operating system.
- risk 0.35cvss 5.3epss 0.02
A Directory Traversal issue was discovered in SSHServerAPI.dll in Progress ipswitch WS_FTP Server 2018 before 8.6.1. An attacker can supply a string using special patterns via the SCP protocol to disclose WS_FTP usernames as well as filenames.
- risk 0.35cvss 5.3epss 0.02
FileRun 2019.05.21 allows customizables/plugins/audio_player Directory Listing. This issue has been fixed in FileRun 2019.06.01.
- risk 0.35cvss 5.3epss 0.02
FileRun 2019.05.21 allows css/ext-ux Directory Listing. This issue has been fixed in FileRun 2019.06.01.
- risk 0.35cvss 5.3epss 0.02
FileRun 2019.05.21 allows images/extjs Directory Listing. This issue has been fixed in FileRun 2019.06.01.
- risk 0.35cvss 5.4epss 0.02
Directory traversal vulnerability in Cybozu Garoon 4.0.0 to 4.10.1 allows remote authenticated attackers to obtain files without access privileges via the application 'Work Flow'.
- risk 0.35cvss 5.3epss 0.02
An issue was discovered in OpenEMR before 5.0.1 Patch 7. Directory Traversal exists via docid=../ to /portal/lib/download_template.php.
- risk 0.35cvss 5.3epss 0.01
Path traversal using symlink in npm harp module versions <= 0.29.0.
- risk 0.35cvss 5.3epss 0.02
In Eclipse Kura versions up to 4.0.0, the SkinServlet did not checked the path passed during servlet call, potentially allowing path traversal in get requests for a limited number of file types.
- risk 0.35cvss 5.3epss 0.02
PHP Scripts Mall Website Seller Script 2.0.5 allows full Path Disclosure via a request for an arbitrary image URL such as a .png file.
- risk 0.35cvss 5.3epss 0.02
PHP Scripts Mall Advance Crowdfunding Script 2.0.3 has directory traversal via a direct request for a listing of an uploads directory such as the wp-content/uploads/2018/12 directory.
- risk 0.35cvss 5.3epss 0.02
PHP Scripts Mall Charity Donation Script readymadeb2bscript has directory traversal via a direct request for a listing of an uploads directory such as the wp-content/uploads/2018/12 directory.
- risk 0.35cvss 5.3epss 0.02
PHP Scripts Mall Medical Store Script 3.0.3 allows Path Traversal by navigating to the parent directory of a jpg or png file.
- risk 0.35cvss 5.3epss 0.02
PHP Scripts Mall Cab Booking Script 1.0.3 allows Directory Traversal into the parent directory of a jpg or png file.
- risk 0.35cvss 5.3epss 0.02
A vulnerability in Mambo CMS v4.6.5 where the scripts thumbs.php, editorFrame.php, editor.php, images.php, manager.php discloses the root path of the webserver.
- risk 0.35cvss 5.3epss 0.02
ARC 5.21q allows directory traversal via a full pathname in an archive file.
- risk 0.35cvss 5.3epss 0.01
An issue was discovered in DouCo DouPHP 1.5 20181221. It allows full path disclosure in "Smarty error: unable to read resource" error messages for a crafted installation page.
- risk 0.35cvss 6.5epss 0.02
OpenRefine before 3.2 beta allows directory traversal via a relative pathname in a ZIP archive.