CWE-22
9,540 CVEs • Abstraction: Base • Likelihood of Exploit: High
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
The product uses external input to construct a pathname that is intended to identify a file or directory that is located underneath a restricted parent directory, but the product does not properly neutralize special elements within the pathname that can cause the pathname to resolve to a location that is outside of the restricted directory.
CVEs (9,540)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
In blynk-server in Blynk before 0.39.7, Directory Traversal exists via a ../ in a URI that has /static or /static/js at the beginning, as demonstrated by reading the /etc/passwd file. |
For some Iomega, Lenovo, LenovoEMC NAS devices versions 4.1.402.34662 and earlier, the file upload functionality of the Content Explorer application is vulnerable to path traversal. As a result, users can upload files an...Show more |
1Asset Pipeline Project 1Asset Pipeline Nov 21, 2024 Sep 28, 2018 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 An issue was discovered in the Asset Pipeline plugin before 3.0.4 for Grails. An attacker can perform directory traversal via a crafted request when a servlet-based application is executed in Jetty, because there is a cl...Show more |
CMS ISWEB 3.5.3 is vulnerable to directory traversal and local file download, as demonstrated by moduli/downloadFile.php?file=oggetto_documenti/../.././inc/config.php (one can take the control of the application because...Show more |
1Hp 1Intelligent Management Center Jun 17, 2026 Sep 27, 2018 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 A security vulnerability in HPE Intelligent Management Center (iMC) PLAT E0506P09, createFabricAutoCfgFile could be remotely exploited via directory traversal to allow remote arbitrary file modification. |
SeaCMS 6.64 and 7.2 allows remote attackers to delete arbitrary files via the filedir parameter. |
1Citrix 1Sharefile Storagezones Controller Nov 21, 2024 Sep 26, 2018 N/A· v4 3.1 LOW· v3 3.5 LOW· v2 Citrix ShareFile StorageZones Controller before 5.4.2 allows Directory Traversal. |
This vulnerability allows local attackers to escalate privileges on vulnerable installations of Samsung Notes Fixed in version 2.0.02.31. An attacker must first obtain the ability to execute low-privileged code on the ta...Show more |
1Localize My Post Project 1Localize My Post Nov 21, 2024 Sep 24, 2018 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 The Localize My Post plugin 1.0 for WordPress allows Directory Traversal via the ajax/include.php file parameter. |
1Wechat Brodcast Project 1Wechat Brodcast Nov 21, 2024 Sep 24, 2018 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 The Wechat Broadcast plugin 1.2.0 and earlier for WordPress allows Directory Traversal via the Image.php url parameter. |
The unzip function in ZipUtil.java in Hutool before 4.1.12 allows remote attackers to overwrite arbitrary files via directory traversal sequences in a filename within a ZIP archive. |
1Hp 1Arcsight Management Center Jun 17, 2026 Sep 20, 2018 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 A potential Directory Traversal Security vulnerability has been identified in ArcSight Management Center (ArcMC) in all versions prior to 2.81. This vulnerability could be remotely exploited to allow Directory Traversal. |
1Blackberry 1Enterprise Mobility Server Jun 17, 2026 Sep 19, 2018 N/A· v4 4.7 MEDIUM· v3 4.7 MEDIUM· v2 A directory traversal vulnerability in the Connect Service of the BlackBerry Enterprise Mobility Server (BEMS) 2.8.17.29 and earlier could allow an attacker to retrieve arbitrary files in the context of a BEMS administra...Show more |
In Apache Tika 0.9 to 1.18, in a rare edge case where a user does not specify an extract directory on the commandline (--extract-dir=) and the input file has an embedded file with an absolute path, such as "C:/evil.bat",...Show more |
admin/index.php in Monstra CMS 3.0.4 allows arbitrary directory listing via id=filesmanager&path=uploads/.......//./.......//./ requests. |
admin/index.php in Monstra CMS 3.0.4 allows arbitrary file deletion via id=filesmanager&path=uploads/.......//./.......//./&delete_file= requests. |
2Debian Smarty2Debian Linux SmartyNov 21, 2024 Sep 18, 2018 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 Smarty_Security::isTrustedResourceDir() in Smarty before 3.1.33 is prone to a path traversal vulnerability due to insufficient template code sanitization. This allows attackers controlling the executed template code to b...Show more |
Apache Camel's Mail 2.20.0 through 2.20.3, 2.21.0 through 2.21.1 and 2.22.0 is vulnerable to path traversal. |
CScms 4.1 allows arbitrary directory deletion via a dir=..\\ substring to plugins\sys\admin\Plugins.php. |
A vulnerability in the one-X Portal component of Avaya IP Office allows an authenticated attacker to read and delete arbitrary files on the system. Affected versions of Avaya IP Office include 9.1 through 9.1 SP12, 10.0...Show more |