CWE-22
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
Description
The product uses external input to construct a pathname that is intended to identify a file or directory that is located underneath a restricted parent directory, but the product does not properly neutralize special elements within the pathname that can cause the pathname to resolve to a location that is outside of the restricted directory.
Hierarchy (View 1000)
Related attack patterns (CAPEC)
CAPEC-126 · CAPEC-64 · CAPEC-76 · CAPEC-78 · CAPEC-79
CVEs mapped to this weakness (10,395)
page 485 of 520| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2020-7665 | Hig | 0.00 | 7.5 | 0.02 | Sep 1, 2020 | This affects all versions of package github.com/u-root/u-root/pkg/uzip. It is vulnerable to both leading and non-leading relative path traversal attacks in zip file extraction. | ||
| CVE-2020-15908 | Hig | 0.00 | 7.5 | 0.02 | Jul 23, 2020 | tar/TarFileReader.cpp in Cauldron cbang (aka C-Bang or C!) before 1.6.0 allows Directory Traversal during extraction from a TAR archive. | ||
| CVE-2020-15124 | Cri | 0.00 | 9.6 | 0.02 | Jul 22, 2020 | In Goobi Viewer Core before version 4.8.3, a path traversal vulnerability allows for remote attackers to access files on the server via the application. This is limited to files accessible to the application server user, eg. tomcat, but can potentially lead to the disclosure of… | ||
| CVE-2020-13795 | Med | 0.00 | 5.3 | 0.02 | Jun 3, 2020 | An issue was discovered in Navigate CMS through 2.8.7. It allows Directory Traversal because lib/packages/templates/template.class.php mishandles ../ and ..\ substrings. | ||
| CVE-2020-11073 | Hig | 0.00 | 7.9 | 0.01 | May 13, 2020 | In Autoswitch Python Virtualenv before version 0.16.0, a user who enters a directory with a malicious `.venv` file could run arbitrary code without any user interaction. This is fixed in version: 1.16.0 | ||
| CVE-2020-12649 | Hig | 0.00 | 7.5 | 0.02 | May 5, 2020 | Gurbalib through 2020-04-30 allows lib/cmds/player/help.c directory traversal for reading administrative paths. | ||
| CVE-2020-12479 | Hig | 0.00 | 8.8 | 0.03 | Apr 29, 2020 | TeamPass 2.1.27.36 allows any authenticated TeamPass user to trigger a PHP file include vulnerability via a crafted HTTP request with sources/users.queries.php newValue directory traversal. | ||
| CVE-2020-12443 | Cri | 0.00 | 9.8 | 0.04 | Apr 29, 2020 | BigBlueButton before 2.2.6 allows remote attackers to read arbitrary files because the presfilename (lowercase) value can be a .pdf filename while the presFilename (mixed case) value has a ../ sequence. This can be leveraged for privilege escalation via a directory traversal to… | ||
| CVE-2020-12103 | Hig | 0.00 | 7.7 | 0.01 | Apr 28, 2020 | In Tiny File Manager 2.4.1 there is a vulnerability in the ajax file backup copy functionality which allows authenticated users to create backup copies of files (with .bak extension) outside the scope in the same directory in which they are stored. | ||
| CVE-2020-12102 | Hig | 0.00 | 7.7 | 0.02 | Apr 28, 2020 | In Tiny File Manager 2.4.1, there is a Path Traversal vulnerability in the ajax recursive directory listing functionality. This allows authenticated users to enumerate directories and files on the filesystem (outside of the application scope). | ||
| CVE-2020-11736 | Low | 0.00 | 3.9 | 0.01 | Apr 13, 2020 | fr-archive-libarchive.c in GNOME file-roller through 3.36.1 allows Directory Traversal during extraction because it lacks a check of whether a file's parent is a symlink to a directory outside of the intended extraction location. | ||
| CVE-2020-11498 | Hig | 0.00 | 8.8 | 0.03 | Apr 2, 2020 | Slack Nebula through 1.1.0 contains a relative path vulnerability that allows a low-privileged attacker to execute code in the context of the root user via tun_darwin.go or tun_windows.go. A user can also use Nebula to execute arbitrary code in the user's own context, e.g., for… | ||
| CVE-2020-10696 | Hig | 0.00 | 8.8 | 0.03 | Mar 31, 2020 | A path traversal flaw was found in Buildah in versions before 1.14.5. This flaw allows an attacker to trick a user into building a malicious container image hosted on an HTTP(s) server and then write files to the user's system anywhere that the user has permissions. | ||
| CVE-2020-8131 | Hig | 0.00 | 7.5 | 0.05 | Feb 24, 2020 | Arbitrary filesystem write vulnerability in Yarn before 1.22.0 allows attackers to write to any path on the filesystem and potentially lead to arbitrary code execution by forcing the user to install a malicious package. | ||
| CVE-2020-8545 | Hig | 0.00 | 7.5 | 0.01 | Feb 3, 2020 | Global.py in AIL framework 2.8 allows path traversal. | ||
| CVE-2020-5221 | Med | 0.00 | 6.5 | 0.01 | Jan 22, 2020 | In uftpd before 2.11, it is possible for an unauthenticated user to perform a directory traversal attack using multiple different FTP commands and read and write to arbitrary locations on the filesystem due to the lack of a well-written chroot jail in compose_abspath(). This has… | ||
| CVE-2019-11246 | Med | 0.00 | 6.5 | 0.04 | Aug 29, 2019 | The kubectl cp command allows copying files between containers and the user machine. To copy files from a container, Kubernetes runs tar inside the container to create a tar archive, copies it over the network, and kubectl unpacks it on the user’s machine. If the tar binary in… | ||
| CVE-2019-15520 | Med | 0.00 | 5.3 | 0.02 | Aug 23, 2019 | comelz Quark before 2019-03-26 allows directory traversal to locations outside of the project directory. | ||
| CVE-2019-15519 | Cri | 0.00 | 9.8 | 0.03 | Aug 23, 2019 | Power-Response before 2019-02-02 allows directory traversal (up to the application's main directory) via a plugin. | ||
| CVE-2019-15518 | Med | 0.00 | 5.3 | 0.02 | Aug 23, 2019 | Swoole before 4.2.13 allows directory traversal in swPort_http_static_handler. |
- risk 0.00cvss 7.5epss 0.02
This affects all versions of package github.com/u-root/u-root/pkg/uzip. It is vulnerable to both leading and non-leading relative path traversal attacks in zip file extraction.
- risk 0.00cvss 7.5epss 0.02
tar/TarFileReader.cpp in Cauldron cbang (aka C-Bang or C!) before 1.6.0 allows Directory Traversal during extraction from a TAR archive.
- risk 0.00cvss 9.6epss 0.02
In Goobi Viewer Core before version 4.8.3, a path traversal vulnerability allows for remote attackers to access files on the server via the application. This is limited to files accessible to the application server user, eg. tomcat, but can potentially lead to the disclosure of…
- risk 0.00cvss 5.3epss 0.02
An issue was discovered in Navigate CMS through 2.8.7. It allows Directory Traversal because lib/packages/templates/template.class.php mishandles ../ and ..\ substrings.
- risk 0.00cvss 7.9epss 0.01
In Autoswitch Python Virtualenv before version 0.16.0, a user who enters a directory with a malicious `.venv` file could run arbitrary code without any user interaction. This is fixed in version: 1.16.0
- risk 0.00cvss 7.5epss 0.02
Gurbalib through 2020-04-30 allows lib/cmds/player/help.c directory traversal for reading administrative paths.
- risk 0.00cvss 8.8epss 0.03
TeamPass 2.1.27.36 allows any authenticated TeamPass user to trigger a PHP file include vulnerability via a crafted HTTP request with sources/users.queries.php newValue directory traversal.
- risk 0.00cvss 9.8epss 0.04
BigBlueButton before 2.2.6 allows remote attackers to read arbitrary files because the presfilename (lowercase) value can be a .pdf filename while the presFilename (mixed case) value has a ../ sequence. This can be leveraged for privilege escalation via a directory traversal to…
- risk 0.00cvss 7.7epss 0.01
In Tiny File Manager 2.4.1 there is a vulnerability in the ajax file backup copy functionality which allows authenticated users to create backup copies of files (with .bak extension) outside the scope in the same directory in which they are stored.
- risk 0.00cvss 7.7epss 0.02
In Tiny File Manager 2.4.1, there is a Path Traversal vulnerability in the ajax recursive directory listing functionality. This allows authenticated users to enumerate directories and files on the filesystem (outside of the application scope).
- risk 0.00cvss 3.9epss 0.01
fr-archive-libarchive.c in GNOME file-roller through 3.36.1 allows Directory Traversal during extraction because it lacks a check of whether a file's parent is a symlink to a directory outside of the intended extraction location.
- risk 0.00cvss 8.8epss 0.03
Slack Nebula through 1.1.0 contains a relative path vulnerability that allows a low-privileged attacker to execute code in the context of the root user via tun_darwin.go or tun_windows.go. A user can also use Nebula to execute arbitrary code in the user's own context, e.g., for…
- risk 0.00cvss 8.8epss 0.03
A path traversal flaw was found in Buildah in versions before 1.14.5. This flaw allows an attacker to trick a user into building a malicious container image hosted on an HTTP(s) server and then write files to the user's system anywhere that the user has permissions.
- risk 0.00cvss 7.5epss 0.05
Arbitrary filesystem write vulnerability in Yarn before 1.22.0 allows attackers to write to any path on the filesystem and potentially lead to arbitrary code execution by forcing the user to install a malicious package.
- risk 0.00cvss 7.5epss 0.01
Global.py in AIL framework 2.8 allows path traversal.
- risk 0.00cvss 6.5epss 0.01
In uftpd before 2.11, it is possible for an unauthenticated user to perform a directory traversal attack using multiple different FTP commands and read and write to arbitrary locations on the filesystem due to the lack of a well-written chroot jail in compose_abspath(). This has…
- risk 0.00cvss 6.5epss 0.04
The kubectl cp command allows copying files between containers and the user machine. To copy files from a container, Kubernetes runs tar inside the container to create a tar archive, copies it over the network, and kubectl unpacks it on the user’s machine. If the tar binary in…
- risk 0.00cvss 5.3epss 0.02
comelz Quark before 2019-03-26 allows directory traversal to locations outside of the project directory.
- risk 0.00cvss 9.8epss 0.03
Power-Response before 2019-02-02 allows directory traversal (up to the application's main directory) via a plugin.
- risk 0.00cvss 5.3epss 0.02
Swoole before 4.2.13 allows directory traversal in swPort_http_static_handler.