CWE-22
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
Description
The product uses external input to construct a pathname that is intended to identify a file or directory that is located underneath a restricted parent directory, but the product does not properly neutralize special elements within the pathname that can cause the pathname to resolve to a location that is outside of the restricted directory.
Hierarchy (View 1000)
Related attack patterns (CAPEC)
CAPEC-126 · CAPEC-64 · CAPEC-76 · CAPEC-78 · CAPEC-79
CVEs mapped to this weakness (10,395)
page 80 of 520| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2022-39838 | Hig | 0.56 | 8.6 | 0.02 | Sep 5, 2022 | Systematic FIX Adapter (ALFAFX) 2.4.0.25 13/09/2017 allows remote file inclusion via a UNC share pathname, and also allows absolute path traversal to local pathnames. | ||
| CVE-2022-31566 | Hig | 0.56 | 8.6 | 0.01 | Jul 11, 2022 | The DSAB-local/DSAB repository through 2019-02-18 on GitHub allows absolute path traversal because the Flask send_file function is used unsafely. | ||
| CVE-2021-36288 | Hig | 0.56 | 8.6 | 0.01 | Apr 8, 2022 | Dell VNX2 for File version 8.1.21.266 and earlier, contain a path traversal vulnerability which may lead unauthenticated users to read/write restricted files | ||
| CVE-2021-30497 | Hig | 0.56 | 7.5 | 0.97 | Apr 6, 2022 | Ivanti Avalanche (Premise) 6.3.2 allows remote unauthenticated users to read arbitrary files via Absolute Path Traversal. The imageFilePath parameter processed by the /AvalancheWeb/image endpoint is not verified to be within the scope of the image folder, e.g., the attacker can… | ||
| CVE-2022-26960 | — | Cri | 0.56 | 9.1 | 0.51 | Mar 21, 2022 | connector.minimal.php in std42 elFinder through 2.1.60 is affected by path traversal. This allows unauthenticated remote attackers to read, write, and browse files outside the configured document root. This is due to improper handling of absolute file paths. | |
| CVE-2021-46381 | Hig | 0.56 | 7.5 | 0.59 | Mar 4, 2022 | Local File Inclusion due to path traversal in D-Link DAP-1620 leads to unauthorized internal files reading [/etc/passwd] and [/etc/shadow]. | ||
| CVE-2021-32498 | Hig | 0.56 | 8.6 | 0.01 | Dec 17, 2021 | SICK SOPAS ET before version 4.8.0 allows attackers to manipulate the pathname of the emulator and use path traversal to run an arbitrary executable located on the host system. When the user starts the emulator from SOPAS ET the corresponding executable will be started instead… | ||
| CVE-2021-41381 | Hig | 0.56 | 7.5 | 0.53 | Sep 23, 2021 | Payara Micro Community 5.2021.6 and below allows Directory Traversal. | ||
| CVE-2021-23428 | Hig | 0.56 | 8.6 | 0.02 | Sep 1, 2021 | This affects all versions of package elFinder.NetCore. The Path.Combine(...) method is used to create an absolute file path. Due to missing sanitation of the user input and a missing check of the generated path its possible to escape the Files directory via path traversal | ||
| CVE-2021-23427 | Hig | 0.56 | 8.6 | 0.01 | Sep 1, 2021 | This affects all versions of package elFinder.NetCore. The ExtractAsync function within the FileSystem is vulnerable to arbitrary extraction due to insufficient validation. | ||
| CVE-2020-24144 | Hig | 0.56 | 8.6 | 0.02 | Jul 7, 2021 | Directory traversal in the Media File Organizer (aka media-file-organizer) plugin 1.0.1 for WordPress lets an attacker get access to files that are stored outside the web root folder via the items[] parameter in a move operation. | ||
| CVE-2020-23715 | Hig | 0.56 | 8.6 | 0.02 | Jun 28, 2021 | Directory Traversal vulnerability in Webport CMS 1.19.10.17121 via the file parameter to file/download. | ||
| CVE-2020-4039 | Hig | 0.56 | 8.6 | 0.01 | Apr 30, 2021 | SUSI.AI is an intelligent Open Source personal assistant. SUSI.AI Server before version d27ed0f has a directory traversal vulnerability due to insufficient input validation. Any admin config and file readable by the app can be retrieved by the attacker. Furthermore, some files… | ||
| CVE-2020-24136 | Hig | 0.56 | 8.6 | 0.02 | Apr 7, 2021 | Directory traversal in Wcms 0.3.2 allows an attacker to read arbitrary files on the server that is running an application via the pagename parameter to wex/html.php. | ||
| CVE-2020-15012 | Hig | 0.56 | 8.6 | 0.03 | Oct 12, 2020 | A Directory Traversal issue was discovered in Sonatype Nexus Repository Manager 2.x before 2.14.19. A user that requests a crafted path can traverse up the file system to get access to content on disk (that the user running nxrm also has access to). | ||
| CVE-2020-15050 | Hig | 0.56 | 7.5 | 0.51 | Jul 13, 2020 | An issue was discovered in the Video Extension in Suprema BioStar 2 before 2.8.2. Remote attackers can read arbitrary files from the server via Directory Traversal. | ||
| CVE-2020-6768 | Hig | 0.56 | 8.6 | 0.02 | Feb 7, 2020 | A path traversal vulnerability in the Bosch Video Management System (BVMS) NoTouch deployment allows an unauthenticated remote attacker to read arbitrary files from the Central Server. This affects Bosch BVMS versions 10.0 <= 10.0.0.1225, 9.0 <= 9.0.0.827, 8.0 <= 8.0.329 and 7.5… | ||
| CVE-2019-19458 | Hig | 0.56 | 8.6 | 0.03 | Dec 3, 2019 | SALTO ProAccess SPACE 5.4.3.0 allows Directory Traversal in the Data Export feature. | ||
| CVE-2015-9406 | Hig | 0.56 | 7.5 | 0.55 | Sep 20, 2019 | Directory traversal vulnerability in the mTheme-Unus theme before 2.3 for WordPress allows an attacker to read arbitrary files via a .. (dot dot) in the files parameter to css/css.php. | ||
| CVE-2019-14322 | Hig | 0.56 | 7.5 | 0.56 | Jul 28, 2019 | In Pallets Werkzeug before 0.15.5, SharedDataMiddleware mishandles drive names (such as C:) in Windows pathnames. |
- risk 0.56cvss 8.6epss 0.02
Systematic FIX Adapter (ALFAFX) 2.4.0.25 13/09/2017 allows remote file inclusion via a UNC share pathname, and also allows absolute path traversal to local pathnames.
- risk 0.56cvss 8.6epss 0.01
The DSAB-local/DSAB repository through 2019-02-18 on GitHub allows absolute path traversal because the Flask send_file function is used unsafely.
- risk 0.56cvss 8.6epss 0.01
Dell VNX2 for File version 8.1.21.266 and earlier, contain a path traversal vulnerability which may lead unauthenticated users to read/write restricted files
- risk 0.56cvss 7.5epss 0.97
Ivanti Avalanche (Premise) 6.3.2 allows remote unauthenticated users to read arbitrary files via Absolute Path Traversal. The imageFilePath parameter processed by the /AvalancheWeb/image endpoint is not verified to be within the scope of the image folder, e.g., the attacker can…
- risk 0.56cvss 9.1epss 0.51
connector.minimal.php in std42 elFinder through 2.1.60 is affected by path traversal. This allows unauthenticated remote attackers to read, write, and browse files outside the configured document root. This is due to improper handling of absolute file paths.
- risk 0.56cvss 7.5epss 0.59
Local File Inclusion due to path traversal in D-Link DAP-1620 leads to unauthorized internal files reading [/etc/passwd] and [/etc/shadow].
- risk 0.56cvss 8.6epss 0.01
SICK SOPAS ET before version 4.8.0 allows attackers to manipulate the pathname of the emulator and use path traversal to run an arbitrary executable located on the host system. When the user starts the emulator from SOPAS ET the corresponding executable will be started instead…
- risk 0.56cvss 7.5epss 0.53
Payara Micro Community 5.2021.6 and below allows Directory Traversal.
- risk 0.56cvss 8.6epss 0.02
This affects all versions of package elFinder.NetCore. The Path.Combine(...) method is used to create an absolute file path. Due to missing sanitation of the user input and a missing check of the generated path its possible to escape the Files directory via path traversal
- risk 0.56cvss 8.6epss 0.01
This affects all versions of package elFinder.NetCore. The ExtractAsync function within the FileSystem is vulnerable to arbitrary extraction due to insufficient validation.
- risk 0.56cvss 8.6epss 0.02
Directory traversal in the Media File Organizer (aka media-file-organizer) plugin 1.0.1 for WordPress lets an attacker get access to files that are stored outside the web root folder via the items[] parameter in a move operation.
- risk 0.56cvss 8.6epss 0.02
Directory Traversal vulnerability in Webport CMS 1.19.10.17121 via the file parameter to file/download.
- risk 0.56cvss 8.6epss 0.01
SUSI.AI is an intelligent Open Source personal assistant. SUSI.AI Server before version d27ed0f has a directory traversal vulnerability due to insufficient input validation. Any admin config and file readable by the app can be retrieved by the attacker. Furthermore, some files…
- risk 0.56cvss 8.6epss 0.02
Directory traversal in Wcms 0.3.2 allows an attacker to read arbitrary files on the server that is running an application via the pagename parameter to wex/html.php.
- risk 0.56cvss 8.6epss 0.03
A Directory Traversal issue was discovered in Sonatype Nexus Repository Manager 2.x before 2.14.19. A user that requests a crafted path can traverse up the file system to get access to content on disk (that the user running nxrm also has access to).
- risk 0.56cvss 7.5epss 0.51
An issue was discovered in the Video Extension in Suprema BioStar 2 before 2.8.2. Remote attackers can read arbitrary files from the server via Directory Traversal.
- risk 0.56cvss 8.6epss 0.02
A path traversal vulnerability in the Bosch Video Management System (BVMS) NoTouch deployment allows an unauthenticated remote attacker to read arbitrary files from the Central Server. This affects Bosch BVMS versions 10.0 <= 10.0.0.1225, 9.0 <= 9.0.0.827, 8.0 <= 8.0.329 and 7.5…
- risk 0.56cvss 8.6epss 0.03
SALTO ProAccess SPACE 5.4.3.0 allows Directory Traversal in the Data Export feature.
- risk 0.56cvss 7.5epss 0.55
Directory traversal vulnerability in the mTheme-Unus theme before 2.3 for WordPress allows an attacker to read arbitrary files via a .. (dot dot) in the files parameter to css/css.php.
- risk 0.56cvss 7.5epss 0.56
In Pallets Werkzeug before 0.15.5, SharedDataMiddleware mishandles drive names (such as C:) in Windows pathnames.