CWE-22
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
Description
The product uses external input to construct a pathname that is intended to identify a file or directory that is located underneath a restricted parent directory, but the product does not properly neutralize special elements within the pathname that can cause the pathname to resolve to a location that is outside of the restricted directory.
Hierarchy (View 1000)
Related attack patterns (CAPEC)
CAPEC-126 · CAPEC-64 · CAPEC-76 · CAPEC-78 · CAPEC-79
CVEs mapped to this weakness (10,395)
page 483 of 520| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2021-41242 | Hig | 0.00 | 8.1 | 0.01 | Dec 10, 2021 | OpenOlat is a web-basedlearning management system. A path traversal vulnerability exists in OpenOlat prior to versions 15.5.12 and 16.0.5. By providing a filename that contains a relative path as a parameter in some REST methods, it is possible to create directory structures and… | ||
| CVE-2021-43800 | Hig | 0.00 | 7.5 | 0.02 | Dec 6, 2021 | Wiki.js is a wiki app built on Node.js. Prior to version 2.5.254, directory traversal outside of Wiki.js context is possible when a storage module with local asset cache fetching is enabled on a Windows host. A malicious user can potentially read any file on the file system by… | ||
| CVE-2021-44278 | Cri | 0.00 | 9.8 | 0.01 | Dec 3, 2021 | Librenms 21.11.0 is affected by a path manipulation vulnerability in includes/html/pages/device/showconfig.inc.php. | ||
| CVE-2021-3916 | Med | 0.00 | 6.5 | 0.01 | Nov 5, 2021 | bookstack is vulnerable to Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') | ||
| CVE-2019-3556 | Hig | 0.00 | 8.1 | 0.02 | Oct 26, 2021 | HHVM supports the use of an "admin" server which accepts administrative requests over HTTP. One of those request handlers, dump-pcre-cache, can be used to output cached regular expressions from the current execution context into a file. The handler takes a parameter which… | ||
| CVE-2021-41185 | Hig | 0.00 | 8.8 | 0.01 | Oct 26, 2021 | Mycodo is an environmental monitoring and regulation system. An exploit in versions prior to 8.12.7 allows anyone with access to endpoints to download files outside the intended directory. A patch has been applied and a release made. Users should upgrade to version 8.12.7. As a… | ||
| CVE-2021-41178 | Hig | 0.00 | 8.8 | 0.02 | Oct 25, 2021 | Nextcloud is an open-source, self-hosted productivity platform. Prior to versions 20.0.13, 21.0.5, and 22.2.0, a file traversal vulnerability makes an attacker able to download arbitrary SVG images from the host system, including user provided files. This could also be leveraged… | ||
| CVE-2021-41152 | Hig | 0.00 | 7.7 | 0.01 | Oct 18, 2021 | OpenOlat is a web-based e-learning platform for teaching, learning, assessment and communication, an LMS, a learning management system. In affected versions by manipulating the HTTP request an attacker can modify the path of a requested file download in the folder component to… | ||
| CVE-2021-3874 | Med | 0.00 | 6.5 | 0.01 | Oct 15, 2021 | bookstack is vulnerable to Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') | ||
| CVE-2021-27341 | Cri | 0.00 | 9.8 | 0.02 | Sep 16, 2021 | OpenSIS Community Edition version <= 7.6 is affected by a local file inclusion vulnerability in DownloadWindow.php via the "filename" parameter. | ||
| CVE-2021-41072 | Hig | 0.00 | 8.1 | 0.02 | Sep 14, 2021 | squashfs_opendir in unsquash-2.c in Squashfs-Tools 4.5 allows Directory Traversal, a different vulnerability than CVE-2021-40153. A squashfs filesystem that has been crafted to include a symbolic link and then contents under the same filename in a filesystem can cause unsquashfs… | ||
| CVE-2021-39180 | Hig | 0.00 | 8.1 | 0.02 | Aug 31, 2021 | OpenOLAT is a web-based learning management system (LMS). A path traversal vulnerability exists in versions prior to 15.3.18, 15.5.3, and 16.0.0. Using a specially prepared ZIP file, it is possible to overwrite any file that is writable by the application server user (e.g. the… | ||
| CVE-2021-40153 | Hig | 0.00 | 8.1 | 0.03 | Aug 27, 2021 | squashfs_opendir in unsquash-1.c in Squashfs-Tools 4.5 stores the filename in the directory entry; this is then used by unsquashfs to create the new file during the unsquash. The filename is not validated for traversal outside of the destination directory, and thus allows… | ||
| CVE-2021-38511 | Hig | 0.00 | 7.5 | 0.01 | Aug 10, 2021 | An issue was discovered in the tar crate before 0.4.36 for Rust. When symlinks are present in a TAR archive, extraction can create arbitrary directories via .. traversal. | ||
| CVE-2021-32814 | Hig | 0.00 | 8.8 | 0.02 | Aug 3, 2021 | Skytable is a NoSQL database with automated snapshots and TLS. Versions prior to 0.5.1 are vulnerable to a a directory traversal attack enabling remotely connected clients to destroy and/or manipulate critical files on the host's file system. This security bug has been patched… | ||
| CVE-2021-36156 | Med | 0.00 | 5.3 | 0.01 | Aug 3, 2021 | An issue was discovered in Grafana Loki through 2.2.1. The header value X-Scope-OrgID is used to construct file paths for rules files, and if crafted to conduct directory traversal such as ae ../../sensitive/path/in/deployment pathname, then Loki will attempt to parse a rules… | ||
| CVE-2021-30483 | Med | 0.00 | 5.3 | 0.02 | Jul 30, 2021 | isomorphic-git before 1.8.2 allows Directory Traversal via a crafted repository. | ||
| CVE-2021-31272 | Cri | 0.00 | 9.8 | 0.03 | Jun 18, 2021 | SerenityOS before commit 3844e8569689dd476064a0759d704bc64fb3ca2c contains a directory traversal vulnerability in tar/unzip that may lead to command execution or privilege escalation. | ||
| CVE-2021-33497 | Cri | 0.00 | 9.1 | 0.02 | May 24, 2021 | Dutchcoders transfer.sh before 1.2.4 allows Directory Traversal for deleting files. | ||
| CVE-2020-21057 | Hig | 0.00 | 8.1 | 0.02 | May 20, 2021 | Directory Traversal vulnerability in FusionPBX 4.5.7, which allows a remote malicious user to delete folders on the system via the folder variable to app/edit/folderdelete.php. |
- risk 0.00cvss 8.1epss 0.01
OpenOlat is a web-basedlearning management system. A path traversal vulnerability exists in OpenOlat prior to versions 15.5.12 and 16.0.5. By providing a filename that contains a relative path as a parameter in some REST methods, it is possible to create directory structures and…
- risk 0.00cvss 7.5epss 0.02
Wiki.js is a wiki app built on Node.js. Prior to version 2.5.254, directory traversal outside of Wiki.js context is possible when a storage module with local asset cache fetching is enabled on a Windows host. A malicious user can potentially read any file on the file system by…
- risk 0.00cvss 9.8epss 0.01
Librenms 21.11.0 is affected by a path manipulation vulnerability in includes/html/pages/device/showconfig.inc.php.
- risk 0.00cvss 6.5epss 0.01
bookstack is vulnerable to Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
- risk 0.00cvss 8.1epss 0.02
HHVM supports the use of an "admin" server which accepts administrative requests over HTTP. One of those request handlers, dump-pcre-cache, can be used to output cached regular expressions from the current execution context into a file. The handler takes a parameter which…
- risk 0.00cvss 8.8epss 0.01
Mycodo is an environmental monitoring and regulation system. An exploit in versions prior to 8.12.7 allows anyone with access to endpoints to download files outside the intended directory. A patch has been applied and a release made. Users should upgrade to version 8.12.7. As a…
- risk 0.00cvss 8.8epss 0.02
Nextcloud is an open-source, self-hosted productivity platform. Prior to versions 20.0.13, 21.0.5, and 22.2.0, a file traversal vulnerability makes an attacker able to download arbitrary SVG images from the host system, including user provided files. This could also be leveraged…
- risk 0.00cvss 7.7epss 0.01
OpenOlat is a web-based e-learning platform for teaching, learning, assessment and communication, an LMS, a learning management system. In affected versions by manipulating the HTTP request an attacker can modify the path of a requested file download in the folder component to…
- risk 0.00cvss 6.5epss 0.01
bookstack is vulnerable to Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
- risk 0.00cvss 9.8epss 0.02
OpenSIS Community Edition version <= 7.6 is affected by a local file inclusion vulnerability in DownloadWindow.php via the "filename" parameter.
- risk 0.00cvss 8.1epss 0.02
squashfs_opendir in unsquash-2.c in Squashfs-Tools 4.5 allows Directory Traversal, a different vulnerability than CVE-2021-40153. A squashfs filesystem that has been crafted to include a symbolic link and then contents under the same filename in a filesystem can cause unsquashfs…
- risk 0.00cvss 8.1epss 0.02
OpenOLAT is a web-based learning management system (LMS). A path traversal vulnerability exists in versions prior to 15.3.18, 15.5.3, and 16.0.0. Using a specially prepared ZIP file, it is possible to overwrite any file that is writable by the application server user (e.g. the…
- risk 0.00cvss 8.1epss 0.03
squashfs_opendir in unsquash-1.c in Squashfs-Tools 4.5 stores the filename in the directory entry; this is then used by unsquashfs to create the new file during the unsquash. The filename is not validated for traversal outside of the destination directory, and thus allows…
- risk 0.00cvss 7.5epss 0.01
An issue was discovered in the tar crate before 0.4.36 for Rust. When symlinks are present in a TAR archive, extraction can create arbitrary directories via .. traversal.
- risk 0.00cvss 8.8epss 0.02
Skytable is a NoSQL database with automated snapshots and TLS. Versions prior to 0.5.1 are vulnerable to a a directory traversal attack enabling remotely connected clients to destroy and/or manipulate critical files on the host's file system. This security bug has been patched…
- risk 0.00cvss 5.3epss 0.01
An issue was discovered in Grafana Loki through 2.2.1. The header value X-Scope-OrgID is used to construct file paths for rules files, and if crafted to conduct directory traversal such as ae ../../sensitive/path/in/deployment pathname, then Loki will attempt to parse a rules…
- risk 0.00cvss 5.3epss 0.02
isomorphic-git before 1.8.2 allows Directory Traversal via a crafted repository.
- risk 0.00cvss 9.8epss 0.03
SerenityOS before commit 3844e8569689dd476064a0759d704bc64fb3ca2c contains a directory traversal vulnerability in tar/unzip that may lead to command execution or privilege escalation.
- risk 0.00cvss 9.1epss 0.02
Dutchcoders transfer.sh before 1.2.4 allows Directory Traversal for deleting files.
- risk 0.00cvss 8.1epss 0.02
Directory Traversal vulnerability in FusionPBX 4.5.7, which allows a remote malicious user to delete folders on the system via the folder variable to app/edit/folderdelete.php.