CWE-22
9,540 CVEs • Abstraction: Base • Likelihood of Exploit: High
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
The product uses external input to construct a pathname that is intended to identify a file or directory that is located underneath a restricted parent directory, but the product does not properly neutralize special elements within the pathname that can cause the pathname to resolve to a location that is outside of the restricted directory.
CVEs (9,540)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
1Roxyfileman 1Roxy Fileman Nov 21, 2024 Mar 21, 2019 N/A· v4 9.1 CRITICAL· v3 6.4 MEDIUM· v2 Roxy Fileman 1.4.5 allows Directory Traversal in copydir.php, copyfile.php, and fileslist.php. |
In Webgalamb through 7.0, a system/ajax.php "wgmfile restore" directory traversal vulnerability could lead to arbitrary code execution by authenticated administrator users, because PHP files are restored under the docume...Show more |
The REST API in Wowza Streaming Engine 4.7.4.01 allows traversal of the directory structure and retrieval of a file via a remote, specifically crafted HTTP request. |
When accessing the heron-ui webpage, people can modify the file paths outside of the current container to access any file on the host. Example woule be modifying the parameter path= to go to the directory you would like...Show more |
4Fedoraproject OpensuseOpenwsman Project+1 more11Enterprise Linux Enterprise Linux DesktopEnterprise Linux Eus+8 moreJun 17, 2026 Mar 14, 2019 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 Openwsman, versions up to and including 2.6.9, are vulnerable to arbitrary file disclosure because the working directory of openwsmand daemon was set to root directory. A remote, unauthenticated attacker can exploit this...Show more |
Directory traversal vulnerability in iChain Insurance Wallet App for iOS Version 1.3.0 and earlier allows remote attackers to read arbitrary files via unspecified vectors. |
pacman before 5.1.3 allows directory traversal when installing a remote package via a specified URL "pacman -U <url>" due to an unsanitized file name received from a Content-Disposition header. pacman renames the downloa...Show more |
An issue was discovered in JTBC(PHP) 3.0.1.8. Its cache management module is flawed. An arbitrary file ending in "inc.php" can be deleted via a console/cache/manage.php?type=action&action=batch&batch=delete&ids=../ subst...Show more |
1Simplemachines 1Simple Machines Forum Nov 21, 2024 Mar 7, 2019 N/A· v4 8.8 HIGH· v3 6.5 MEDIUM· v2 Simple Machines Forum (SMF) 2.0.4 allows local file inclusion, with resultant remote code execution, in install.php via ../ directory traversal in the db_type parameter if install.php remains present after installation. |
1Tibco 4Jasperreports Library Jasperreports ServerJaspersoft+1 moreNov 7, 2025 Mar 7, 2019 N/A· v4 6.5 MEDIUM· v3 4.0 MEDIUM· v2 The default server implementation of TIBCO Software Inc.'s TIBCO JasperReports Library, TIBCO JasperReports Library Community Edition, TIBCO JasperReports Library for ActiveMatrix BPM, TIBCO JasperReports Server, TIBCO J...Show more |
eBrigade through 4.5 allows Arbitrary File Download via ../ directory traversal in the showfile.php file parameter, as demonstrated by reading the user-data/save/backup.sql file. |
An issue was discovered in OFCMS before 1.1.3. It allows admin/cms/template/getTemplates.html?res_path=res directory traversal, with ../ in the dir parameter, to write arbitrary content (in the file_content parameter) in...Show more |
An issue was discovered in OFCMS before 1.1.3. It has admin/cms/template/getTemplates.html?res_path=res&up_dir=../ directory traversal, related to the getTemplates function in TemplateController.java. |
1Medical Store Script Project 1Medical Store Script Jun 17, 2026 Mar 6, 2019 N/A· v4 5.3 MEDIUM· v3 5.0 MEDIUM· v2 PHP Scripts Mall Medical Store Script 3.0.3 allows Path Traversal by navigating to the parent directory of a jpg or png file. |
util/src/zip.rs in Grin before 1.0.2 mishandles suspicious files. An attacker can execute arbitrary code via directory traversal in a ZIP archive. |
1Tecrail 1Responsive Filemanager Nov 21, 2024 Feb 25, 2019 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 tecrail Responsive FileManager 9.13.4 allows remote attackers to read arbitrary files via path traversal with the path parameter, through the copy_cut action in ajax_calls.php and the paste_clipboard action in execute.ph...Show more |
1Tecrail 1Responsive Filemanager Nov 21, 2024 Feb 25, 2019 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 tecrail Responsive FileManager 9.13.4 allows remote attackers to write to an arbitrary image file (jpg/jpeg/png) via path traversal with the path parameter, through the save_img action in ajax_calls.php. |
1Tecrail 1Responsive Filemanager Nov 21, 2024 Feb 25, 2019 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 tecrail Responsive FileManager 9.13.4 allows remote attackers to write to an arbitrary file as a consequence of a paths[0] path traversal mitigation bypass, through the create_file action in execute.php. |
1Tecrail 1Responsive Filemanager Nov 21, 2024 Feb 25, 2019 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 tecrail Responsive FileManager 9.13.4 allows remote attackers to read arbitrary file via path traversal with the path parameter, through the get_file action in ajax_calls.php. |
1Tecrail 1Responsive Filemanager Nov 21, 2024 Feb 25, 2019 N/A· v4 7.5 HIGH· v3 6.4 MEDIUM· v2 tecrail Responsive FileManager 9.13.4 allows remote attackers to delete an arbitrary file as a consequence of a paths[0] path traversal mitigation bypass through the delete_file action in execute.php. |