VYPR

CWE-35

Path Traversal: '.../...//'

VariantIncomplete

Description

The product uses external input to construct a pathname that should be within a restricted directory, but it does not properly neutralize '.../...//' (doubled triple dot slash) sequences that can resolve to a location that is outside of that directory.

Hierarchy (View 1000)

Parents

Children

none

CVEs mapped to this weakness (180)

page 7 of 9
  • CVE-2024-41972MedNov 18, 2024
    risk 0.42cvss 6.5epss 0.01

    A low privileged remote attacker can overwrite an arbitrary file on the filesystem which may lead to an arbitrary file read with root privileges.

  • CVE-2024-49258MedOct 16, 2024
    risk 0.42cvss 6.5epss 0.01

    Path Traversal: '.../...//' vulnerability in Limbcode WordPress Gallery Plugin – Limb Image Gallery limb-gallery.This issue affects WordPress Gallery Plugin – Limb Image Gallery: from n/a through <= 1.5.7.

  • CVE-2024-45190MedAug 23, 2024
    risk 0.42cvss 6.5epss 0.01

    Mage AI allows remote users with the "Viewer" role to leak arbitrary files from the Mage server due to a path traversal in the "Pipeline Interaction" request

  • CVE-2024-38706MedJul 12, 2024
    risk 0.42cvss 6.5epss 0.01

    Path Traversal: '.../...//' vulnerability in DevItems HT Mega ht-mega-for-elementor.This issue affects HT Mega: from n/a through <= 2.5.7.

  • CVE-2024-34191MedMay 14, 2024
    risk 0.42cvss 6.5epss 0.01

    htmly v2.9.6 was discovered to contain an arbitrary file deletion vulnerability via the delete_post() function at admin.php. This vulnerability allows attackers to delete arbitrary files via a crafted request.

  • CVE-2023-5885MedNov 27, 2023
    risk 0.42cvss 6.5epss 0.01

    The discontinued FFS Colibri product allows a remote user to access files on the system including files containing login credentials for other users.

  • CVE-2023-21415MedOct 16, 2023
    risk 0.42cvss 6.5epss 0.01

    Sandro Poppi, member of the AXIS OS Bug Bounty Program, has found that the VAPIX API overlay_del.cgi is vulnerable to path traversal attacks that allows for file deletion. This flaw can only be exploited after authenticating with an operator- or administrator-privileged service…

  • CVE-2021-1364MedJan 20, 2021
    risk 0.42cvss 6.5epss 0.01

    Multiple vulnerabilities in Cisco Unified Communications Manager IM & Presence Service (Unified CM IM&P) could allow an attacker to conduct path traversal attacks and SQL injection attacks on an affected system. One of the SQL injection vulnerabilities that affects…

  • CVE-2021-1357MedJan 20, 2021
    risk 0.42cvss 6.5epss 0.01

    Multiple vulnerabilities in Cisco Unified Communications Manager IM & Presence Service (Unified CM IM&P) could allow an attacker to conduct path traversal attacks and SQL injection attacks on an affected system. One of the SQL injection vulnerabilities that affects…

  • CVE-2021-1355MedJan 20, 2021
    risk 0.42cvss 6.5epss 0.01

    Multiple vulnerabilities in Cisco Unified Communications Manager IM & Presence Service (Unified CM IM&P) could allow an attacker to conduct path traversal attacks and SQL injection attacks on an affected system. One of the SQL injection vulnerabilities that affects…

  • CVE-2021-1282MedJan 20, 2021
    risk 0.42cvss 6.5epss 0.01

    Multiple vulnerabilities in Cisco Unified Communications Manager IM & Presence Service (Unified CM IM&P) could allow an attacker to conduct path traversal attacks and SQL injection attacks on an affected system. One of the SQL injection vulnerabilities that affects…

  • CVE-2025-20320MedJul 7, 2025
    risk 0.41cvss 6.3epss 0.00

    In Splunk Enterprise versions below 9.4.3, 9.3.5, 9.2.7 and 9.1.10, and Splunk Cloud Platform versions below 9.3.2411.107, 9.3.2408.117, and 9.2.2406.121, a low-privileged user that does not hold the "admin" or "power" Splunk roles could craft a malicious payload through the…

  • CVE-2025-26940MedMar 15, 2025
    risk 0.41cvss 6.3epss 0.00

    Path Traversal vulnerability in NotFound Pie Register Premium. This issue affects Pie Register Premium: from n/a through 3.8.3.2.

  • CVE-2024-2863MedMar 25, 2024
    risk 0.40cvss 5.3epss 0.64

    This vulnerability allows remote attackers to traverse paths via file upload on the affected LG LED Assistant.

  • CVE-2022-36928MedJan 9, 2023
    risk 0.40cvss 6.1epss 0.00

    Zoom for Android clients before version 5.13.0 contain a path traversal vulnerability. A third party app could exploit this vulnerability to read and write to the Zoom application data directory.

  • CVE-2022-46826MedDec 8, 2022
    risk 0.40cvss 6.2epss 0.00

    In JetBrains IntelliJ IDEA before 2022.3 the built-in web server allowed an arbitrary file to be read by exploiting a path traversal vulnerability.

  • CVE-2023-43802HigOct 18, 2023
    risk 0.39cvss 7.1epss 0.00

    Arduino Create Agent is a package to help manage Arduino development. This vulnerability affects the endpoint `/upload` which handles request with the `filename` parameter. A user who has the ability to perform HTTP requests to the localhost interface, or is able to bypass the…

  • CVE-2025-0858MedFeb 5, 2025
    risk 0.38cvss epss 0.00

    A vulnerability was discovered in the firmware builds up to 8.2.1.0820 in certain Poly devices. The firmware flaw does not properly prevent path traversal and could lead to information disclosure.

  • CVE-2024-7608MedAug 27, 2024
    risk 0.38cvss 5.9epss 0.00

    An authenticated user can access the restricted files from NX, EX, FX, AX, IVX and CMS using path traversal.

  • CVE-2025-66004MedDec 10, 2025
    risk 0.37cvss 5.7epss 0.00

    A Path Traversal vulnerability in usbmuxd allows local users to escalate to the service user.This issue affects usbmuxd: before 3ded00c9985a5108cfc7591a309f9a23d57a8cba.