CWE-22
9,540 CVEs • Abstraction: Base • Likelihood of Exploit: High
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
The product uses external input to construct a pathname that is intended to identify a file or directory that is located underneath a restricted parent directory, but the product does not properly neutralize special elements within the pathname that can cause the pathname to resolve to a location that is outside of the restricted directory.
CVEs (9,540)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
2Jenkins Redhat2Jenkins Openshift Container PlatformNov 21, 2024 Dec 10, 2018 N/A· v4 8.2 HIGH· v3 6.4 MEDIUM· v2 A data modification vulnerability exists in Jenkins 2.153 and earlier, LTS 2.138.3 and earlier in User.java, IdStrategy.java that allows attackers to submit crafted user names that can cause an improper migration of user...Show more |
Tarantella Enterprise before 3.11 allows Directory Traversal. |
OpenRefine before 3.2 beta allows directory traversal via a relative pathname in a ZIP archive. |
Directory Traversal in downloadwallpaper.cgi in ASUSTOR ADM version 3.1.1 allows attackers to download arbitrary files by manipulating the "file" and "folder" URL parameters. |
Directory Traversal in upload.cgi in ASUSTOR ADM version 3.1.1 allows attackers to upload files to arbitrary locations by modifying the "path" URL parameter. NOTE: the "filename" POST parameter is covered by CVE-2018-11...Show more |
Directory Traversal in File Explorer in ASUSTOR ADM version 3.1.1 allows attackers to view arbitrary files by modifying the "file1" URL parameter, a similar issue to CVE-2018-11344. |
1Simplehttpserver Project 1Simplehttpserver Nov 21, 2024 Dec 4, 2018 N/A· v4 5.3 MEDIUM· v3 5.0 MEDIUM· v2 A Path Traversal in simplehttpserver versions <=0.2.1 allows to list any file in another folder of web root. |
Directory traversal in the Drobo Pix web application on Drobo 5N2 NAS version 4.0.5-13.28.96115 allows unauthenticated attackers to upload files to arbitrary locations. |
An exploitable information disclosure vulnerability exists in the HTTP server functionality of the TP-Link TL-R600VPN. A specially crafted URL can cause a directory traversal, resulting in the disclosure of sensitive sys...Show more |
1Schneider Electric 1Struxureware Data Center Expert Jun 17, 2026 Nov 30, 2018 N/A· v4 8.8 HIGH· v3 6.5 MEDIUM· v2 Data Center Expert, versions 7.5.0 and earlier, allows for the upload of a zip file from its user interface to the server. A carefully crafted, malicious file could be mistakenly uploaded by an authenticated user via thi...Show more |
1Schneider Electric 1Struxureware Data Center Operation Jun 17, 2026 Nov 30, 2018 N/A· v4 8.8 HIGH· v3 6.5 MEDIUM· v2 Data Center Operation allows for the upload of a zip file from its user interface to the server. A carefully crafted, malicious file could be mistakenly uploaded by an authenticated user via this feature which could cont...Show more |
app/plug/attachment/controller/admincontroller.php in SDCMS 1.6 allows reading arbitrary files via a /?m=plug&c=admin&a=index&p=attachment&root= directory traversal. The value of the root parameter must be base64 encoded...Show more |
The agent in OSSEC through 3.1.0 on Windows allows local users to gain NT AUTHORITY\SYSTEM access via Directory Traversal by leveraging full access to the associated OSSEC server. |
1Terra Master 1Terramaster Operating System Nov 21, 2024 Nov 27, 2018 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 Directory Traversal in the explorer application in TerraMaster TOS version 3.1.03 allows attackers to upload files to arbitrary locations via the "path" URL parameter. |
NUUO CMS All versions 3.3 and prior the application allows external input to construct a pathname that is able to be resolved outside the intended directory. This could allow an attacker to impersonate a legitimate user,...Show more |
1Buffalo 1Ts5600d1206 Firmware Nov 21, 2024 Nov 26, 2018 N/A· v4 6.5 MEDIUM· v3 4.0 MEDIUM· v2 Directory traversal in list_folders method in Buffalo TS5600D1206 version 3.61-0.10 allows attackers to list directory contents via the "path" parameter. |
GreenCMS v2.3.0603 allows remote authenticated administrators to delete arbitrary files by modifying a base64-encoded pathname in an m=admin&c=media&a=delfilehandle&id= call, related to the m=admin&c=media&a=restorefile...Show more |
LAOBANCMS 2.0 allows install/mysql_hy.php?riqi=../ Directory Traversal. |
Zyxel VMG1312-B10D devices before 5.13(AAXA.8)C0 allow ../ Directory Traversal, as demonstrated by reading /etc/passwd. |
1Ibm 1Websphere Application Server Nov 21, 2024 Nov 16, 2018 N/A· v4 5.5 MEDIUM· v3 4.3 MEDIUM· v2 IBM WebSphere Application Server 7.0, 8.0, 8.5, and 9.0 using Enterprise bundle Archives (EBA) could allow a local attacker to traverse directories on the system. By persuading a victim to extract a specially-crafted ZIP...Show more |