CWE-22
9,540 CVEs • Abstraction: Base • Likelihood of Exploit: High
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
The product uses external input to construct a pathname that is intended to identify a file or directory that is located underneath a restricted parent directory, but the product does not properly neutralize special elements within the pathname that can cause the pathname to resolve to a location that is outside of the restricted directory.
CVEs (9,540)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
An issue was discovered in the SFTP Server component in Core FTP 2.0 Build 674. Using the MDTM FTP command, a remote attacker can use a directory traversal technique (..\..\) to browse outside the root directory to deter...Show more |
1Cisco 4Ip Conference Phone 8832 Firmware Ip Phone 8800 FirmwareIp Phone 8821 Ex Firmware+1 moreJun 17, 2026 Mar 22, 2019 N/A· v4 6.5 MEDIUM· v3 4.0 MEDIUM· v2 A vulnerability in the web-based management interface of Session Initiation Protocol (SIP) Software for Cisco IP Phone 8800 Series could allow an authenticated, remote attacker to write arbitrary files to the filesystem....Show more |
An issue was discovered in the SFTP Server component in Core FTP 2.0 Build 674. A directory traversal vulnerability exists using the SIZE command along with a \..\..\ substring, allowing an attacker to enumerate file exi...Show more |
In Vanilla before 2.6.4, a flaw exists within the getSingleIndex function of the AddonManager class. The issue results in a require call using a crafted type value, leading to Directory Traversal with File Inclusion. An...Show more |
An issue was discovered in BlogEngine.NET through 3.3.6.0. A path traversal and Local File Inclusion vulnerability in PostList.ascx.cs can cause unauthenticated users to load a PostView.ascx component from a potentially...Show more |
1Gl Inet 1Gl Ar300m Lite Firmware Jun 17, 2026 Mar 21, 2019 N/A· v4 8.8 HIGH· v3 6.5 MEDIUM· v2 Directory traversal vulnerability in storage_cgi in GL.iNet GL-AR300M-Lite devices with firmware 2.27 allows remote attackers to have unspecified impact via directory traversal sequences. |
1Gl Inet 1Gl Ar300m Lite Firmware Jun 17, 2026 Mar 21, 2019 N/A· v4 6.5 MEDIUM· v3 4.0 MEDIUM· v2 download_file in GL.iNet GL-AR300M-Lite devices with firmware 2.27 allows remote attackers to download arbitrary files. |
A path traversal vulnerability in serve npm package version 7.0.1 allows the attackers to read content of arbitrary files on the remote server. |
1Localhost Now Project 1Localhost Now Jun 17, 2026 Mar 21, 2019 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 A path traversal vulnerability in localhost-now npm package version 1.0.2 allows the attackers to read content of arbitrary files on the remote server. |
Apache Karaf kar deployer reads .kar archives and extracts the paths from the "repository/" and "resources/" entries in the zip file. It then writes out the content of these paths to the Karaf repo and resources director...Show more |
1Car Rental Script Project 1Car Rental Script Nov 21, 2024 Mar 21, 2019 N/A· v4 6.5 MEDIUM· v3 4.0 MEDIUM· v2 PHP Scripts Mall Car Rental Script 2.0.8 has directory traversal via a direct request for a listing of an image directory such as an images/ directory. |
1Basic B2b Script Project 1Basic B2b Script Nov 21, 2024 Mar 21, 2019 N/A· v4 6.5 MEDIUM· v3 4.0 MEDIUM· v2 PHP Scripts Mall Basic B2B Script 2.0.9 has has directory traversal via a direct request for a listing of an image directory such as an uploads/ directory. |
1Entrepreneur Job Portal Script Project 1Entrepreneur Job Portal Script Nov 21, 2024 Mar 21, 2019 N/A· v4 6.5 MEDIUM· v3 4.0 MEDIUM· v2 PHP Scripts Mall Entrepreneur Job Portal Script 3.0.1 has directory traversal via a direct request for a listing of an image directory such as an assets/ directory. |
1Chartered Accountant \ 1 Auditor Website Project Nov 21, 2024 Mar 21, 2019 N/A· v4 6.5 MEDIUM· v3 4.0 MEDIUM· v2 PHP Scripts Mall Chartered Accountant : Auditor Website 2.0.1 has directory traversal via a direct request for a listing of an image directory such as an assets/ directory. |
1Advance B2b Script Project 1Advance B2b Script Nov 21, 2024 Mar 21, 2019 N/A· v4 4.3 MEDIUM· v3 4.0 MEDIUM· v2 PHP Scripts Mall Advance B2B Script 2.1.4 has directory traversal via a direct request for a listing of an image directory such as an assets/ directory. |
1Website Seller Script Project 1Website Seller Script Nov 21, 2024 Mar 21, 2019 N/A· v4 5.3 MEDIUM· v3 5.0 MEDIUM· v2 PHP Scripts Mall Website Seller Script 2.0.5 allows full Path Disclosure via a request for an arbitrary image URL such as a .png file. |
1Advance Crowdfunding Script Project 1Advance Crowdfunding Script Nov 21, 2024 Mar 21, 2019 N/A· v4 5.3 MEDIUM· v3 5.0 MEDIUM· v2 PHP Scripts Mall Advance Crowdfunding Script 2.0.3 has directory traversal via a direct request for a listing of an uploads directory such as the wp-content/uploads/2018/12 directory. |
1Charity Donation Script Project 1Charity Donation Script Nov 21, 2024 Mar 21, 2019 N/A· v4 5.3 MEDIUM· v3 5.0 MEDIUM· v2 PHP Scripts Mall Charity Donation Script readymadeb2bscript has directory traversal via a direct request for a listing of an uploads directory such as the wp-content/uploads/2018/12 directory. |
1Charity Foundation Script Project 1Charity Foundation Script Nov 21, 2024 Mar 21, 2019 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 PHP Scripts Mall Charity Foundation Script 1 through 3 allows directory traversal via a direct request for a listing of an uploads directory such as the wp-content/uploads/2018/12 directory. |
1Consumer Reviews Script Project 1Consumer Reviews Script Nov 21, 2024 Mar 21, 2019 N/A· v4 6.5 MEDIUM· v3 4.0 MEDIUM· v2 PHP Scripts Mall Consumer Reviews Script 4.0.3 has directory traversal via a direct request for a listing of an uploads directory such as the wp-content/uploads/2018/12 directory. |