VYPR

CWE-35

Path Traversal: '.../...//'

VariantIncomplete

Description

The product uses external input to construct a pathname that should be within a restricted directory, but it does not properly neutralize '.../...//' (doubled triple dot slash) sequences that can resolve to a location that is outside of that directory.

Hierarchy (View 1000)

Parents

Children

none

CVEs mapped to this weakness (180)

page 1 of 9
  • CVE-2025-8088HigKEVAug 8, 2025
    risk 0.83cvss 8.8epss 0.95

    A path traversal vulnerability affecting the Windows version of WinRAR allows the attackers to execute arbitrary code by crafting malicious archive files. This vulnerability was exploited in the wild and was discovered by Anton Cherepanov, Peter Košinár, and Peter Strýček …

  • CVE-2026-59115CriAug 7, 2026
    risk 0.64cvss 9.9epss 0.01

    '.../...//' in Microsoft Entra Provisioning Service (SyncFabric) allows an authorized attacker to elevate privileges over a network.

  • CVE-2026-6074CriApr 23, 2026
    risk 0.64cvss 9.8epss 0.01

    Intrado 911 Emergency Gateway (EGW) 5.x, 6.x, and 7.x contain a path traversal vulnerability in the download_debuglog_file.php endpoint used for Debug Logs downloads. An unauthenticated attacker can manipulate the name parameter to read arbitrary files outside the intended…

  • CVE-2025-59793CriFeb 17, 2026
    risk 0.64cvss 9.9epss 0.01

    Rocket TRUfusion Enterprise through 7.10.5 exposes the endpoint at /axis2/services/WsPortalV6UpDwAxis2Impl to authenticated users to be able to upload files. However, the application doesn't properly sanitize the jobDirectory parameter, which allows path traversal sequences to…

  • CVE-2025-41723CriOct 22, 2025
    risk 0.64cvss 9.8epss 0.01

    The importFile SOAP method is vulnerable to a directory traversal attack. An unauthenticated remote attacker bypass the path restriction and upload files to arbitrary locations.

  • CVE-2025-42937CriOct 14, 2025
    risk 0.64cvss 9.8epss 0.01

    SAP Print Service (SAPSprint) performs insufficient validation of path information provided by users. An unauthenticated attacker could traverse to the parent directory and over-write system files causing high impact on confidentiality integrity and availability of the…

  • CVE-2025-30515CriJun 9, 2025
    risk 0.64cvss 9.8epss 0.01

    CyberData 011209 Intercom could allow an authenticated attacker to upload arbitrary files to multiple locations within the system.

  • CVE-2024-39171CriJul 9, 2024
    risk 0.64cvss 9.8epss 0.01

    Directory Travel in PHPVibe v11.0.46 due to incomplete blacklist checksums and directory checks, which can lead to code execution via writing specific statements to .htaccess and code to a file with a .png suffix.

  • CVE-2020-27130CriNov 17, 2020
    risk 0.64cvss 9.1epss 0.66

    A vulnerability in Cisco Security Manager could allow an unauthenticated, remote attacker to gain access to sensitive information. The vulnerability is due to improper validation of directory traversal character sequences within requests to an affected device. An attacker could…

  • CVE-2018-3744CriMay 29, 2018
    risk 0.64cvss 9.8epss 0.02

    The html-pages node module contains a path traversal vulnerabilities that allows an attacker to read any file from the server with cURL.

  • CVE-2026-52703CriJun 15, 2026
    risk 0.62cvss 9.6epss 0.00

    Unauthenticated Path Traversal in FastDup <= 2.7.2 versions.

  • CVE-2025-53417CriAug 5, 2025
    risk 0.61cvss epss 0.11

    DIAView (v4.2.0 and prior) - Directory Traversal Information Disclosure Vulnerability

  • CVE-2024-56045CriDec 31, 2024
    risk 0.61cvss 9.3epss 0.01

    Path Traversal: '.../...//' vulnerability in VibeThemes WPLMS wplms_plugin allows Path Traversal.This issue affects WPLMS: from n/a through < 1.9.9.5.

  • CVE-2025-5598CriJun 4, 2025
    risk 0.60cvss epss 0.00

    Path Traversal vulnerability in WF Steuerungstechnik GmbH airleader MASTER allows Retrieve Embedded Sensitive Data.This issue affects airleader MASTER: 3.0046.

  • CVE-2024-40505CriJul 16, 2024
    risk 0.60cvss 9.3epss 0.00

    Directory Traversal vulnerability in D-Link DAP-1650 Firmware v.1.03 allows a local attacker to escalate privileges via the hedwig.cgi component.

  • CVE-2026-13716CriAug 11, 2026
    risk 0.59cvss 9.1epss 0.01

    Path traversal in server import and admin file upload in Crafty Controller. Allows a remote, authenticated attacker to upload files to arbitrary paths permitted to the Crafty Controller application and perform remote code execution.

  • CVE-2026-40128CriJun 9, 2026
    risk 0.59cvss 9.0epss 0.00

    SAP NetWeaver Application Server Java (Web Container) allows an unauthenticated attacker to craft a malicious HTTP logon request that manipulates file inclusion parameters, enabling path traversal and processing of the included file. Processing the included file could allow the…

  • CVE-2026-7302CriMay 18, 2026
    risk 0.59cvss 9.1epss 0.00

    SGLangs multimodal generation runtime is vulnerable to an unauthenticated path traversal vulnerability, allowing an attacker to write arbitrary files anywhere the server process has write access, by including ../ sequences in the upload filename when sent to specific endpoints.

  • CVE-2025-24786CriFeb 6, 2025
    risk 0.58cvss 10.0epss 0.03

    WhoDB is an open source database management tool. While the application only displays Sqlite3 databases present in the directory `/db`, there is no path traversal prevention in place. This allows an unauthenticated attacker to open any Sqlite3 database present on the host…

  • CVE-2026-42661HigJun 15, 2026
    risk 0.57cvss 8.8epss 0.00

    Custom role Path Traversal in WP Customer Area <= 8.3.4 versions.