← Back
CWE-22

9,540 CVEs • Abstraction: Base • Likelihood of Exploit: High

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')

The product uses external input to construct a pathname that is intended to identify a file or directory that is located underneath a restricted parent directory, but the product does not properly neutralize special elements within the pathname that can cause the pathname to resolve to a location that is outside of the restricted directory.

JSON object

Loading...

CVEs (9,540)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Rubedo Project
1Rubedo
Nov 21, 2024
Sep 11, 2018
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
Rubedo through 3.4.0 contains a Directory Traversal vulnerability in the theme component, allowing unauthenticated attackers to read and execute arbitrary files outside of the service root path, as demonstrated by a /the...Show more
Rubedo through 3.4.0 contains a Directory Traversal vulnerability in the theme component, allowing unauthenticated attackers to read and execute arbitrary files outside of the service root path, as demonstrated by a /theme/default/img/%2e%2e/..//etc/passwd URI.Show less
1Smarty
1Smarty
Nov 21, 2024
Sep 11, 2018
N/A· v4
5.9 MEDIUM· v3
7.1 HIGH· v2
Smarty before 3.1.33-dev-4 allows attackers to bypass the trusted_dir protection mechanism via a file:./../ substring in an include statement.
1Redhat
2Jboss Brms
Jboss Drools
Nov 21, 2024
Sep 10, 2018
N/A· v4
6.5 MEDIUM· v3
6.8 MEDIUM· v2
Drools Workbench contains a path traversal vulnerability. The vulnerability allows a remote, authenticated attacker to bypass the directory restrictions and retrieve arbitrary files from the affected host.
1Hongcms Project
1Hongcms
Nov 21, 2024
Sep 10, 2018
N/A· v4
7.5 HIGH· v3
6.4 MEDIUM· v2
HongCMS 3.0.0 allows arbitrary file deletion via a ../ in the file parameter to admin/index.php/language/ajax?action=delete.
1Endress
1Wirelesshart Fieldgate Swg70 Firmware
Nov 21, 2024
Sep 7, 2018
N/A· v4
5.3 MEDIUM· v3
5.0 MEDIUM· v2
Endress+Hauser WirelessHART Fieldgate SWG70 3.x devices allow Directory Traversal via the fcgi-bin/wgsetcgi filename parameter.
1Hibara
1Attachecase
Nov 21, 2024
Sep 7, 2018
N/A· v4
3.3 LOW· v3
4.3 MEDIUM· v2
Directory traversal vulnerability in ver.2.8.4.0 and earlier and ver.3.3.0.0 and earlier allows an attacker to create arbitrary files via specially crafted ATC file.
1Hibara
1Attachecase
Nov 21, 2024
Sep 7, 2018
N/A· v4
5.5 MEDIUM· v3
5.8 MEDIUM· v2
Directory traversal vulnerability in ver.2.8.4.0 and earlier and ver.3.3.0.0 and earlier allows an attacker to create or overwrite existing files via specially crafted ATC file.
2Debian
Kde
2Debian Linux
Okular
Nov 21, 2024
Sep 6, 2018
N/A· v4
5.5 MEDIUM· v3
4.3 MEDIUM· v2
okular version 18.08 and earlier contains a Directory Traversal vulnerability in function "unpackDocumentArchive(...)" in "core/document.cpp" that can result in Arbitrary file creation on the user workstation. This attac...Show more
okular version 18.08 and earlier contains a Directory Traversal vulnerability in function "unpackDocumentArchive(...)" in "core/document.cpp" that can result in Arbitrary file creation on the user workstation. This attack appear to be exploitable via he victim must open a specially crafted Okular archive. This issue appears to have been corrected in version 18.08.1Show less
1Limesurvey
1Limesurvey
Nov 21, 2024
Sep 6, 2018
N/A· v4
8.8 HIGH· v3
6.5 MEDIUM· v2
LimeSurvey version 3.14.4 and earlier contains a directory traversal in file upload that allows upload of webshell vulnerability in file upload functionality that can result in remote code execution as authenticated user...Show more
LimeSurvey version 3.14.4 and earlier contains a directory traversal in file upload that allows upload of webshell vulnerability in file upload functionality that can result in remote code execution as authenticated user. This attack appear to be exploitable via An authenticated user can upload a specially crafted zip file to get remote code execution. This vulnerability appears to have been fixed in after commit 72a02ebaaf95a80e26127ee7ee2b123cccce05a7 / version 3.14.4.Show less
1Php File Browser Script Project
1Php File Browser Script
Nov 21, 2024
Sep 5, 2018
N/A· v4
5.3 MEDIUM· v3
5.0 MEDIUM· v2
HScripts PHP File Browser Script v1.0 allows Directory Traversal via the index.php path parameter.
1Gxlcms
1Gxlcms
Nov 21, 2024
Sep 5, 2018
N/A· v4
4.9 MEDIUM· v3
4.0 MEDIUM· v2
Gxlcms 2.0 before bug fix 20180915 has Directory Traversal exploitable by an administrator.
2Ubnt
Ui
12Af5 Firmware
Af5x FirmwareAirfiber Af24 Firmware+9 more
Nov 21, 2024
Sep 5, 2018
N/A· v4
9.8 CRITICAL· v3
10.0 HIGH· v2
The web management interface of Ubiquiti airMAX, airFiber, airGateway and EdgeSwitch XP (formerly TOUGHSwitch) allows an unauthenticated attacker to upload and write arbitrary files using directory traversal techniques....Show more
The web management interface of Ubiquiti airMAX, airFiber, airGateway and EdgeSwitch XP (formerly TOUGHSwitch) allows an unauthenticated attacker to upload and write arbitrary files using directory traversal techniques. An attacker can exploit this vulnerability to gain root privileges. This vulnerability is fixed in the following product versions (fixes released in July 2015, all prior versions are affected): airMAX AC 7.1.3; airMAX M (and airRouter) 5.6.2 XM/XW/TI, 5.5.11 XM/TI, and 5.5.10u2 XW; airGateway 1.1.5; airFiber AF24/AF24HD 2.2.1, AF5x 3.0.2.1, and AF5 2.2.1; airOS 4 XS2/XS5 4.0.4; and EdgeSwitch XP (formerly TOUGHSwitch) 1.3.2.Show less
1Primx
2Zed!
Zed! Free
Nov 21, 2024
Sep 5, 2018
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
A directory traversal vulnerability with remote code execution in Prim'X Zed! FREE through 1.0 build 186 and Zed! Limited Edition through 6.1 build 2208 allows creation of arbitrary files on a user's workstation using cr...Show more
A directory traversal vulnerability with remote code execution in Prim'X Zed! FREE through 1.0 build 186 and Zed! Limited Edition through 6.1 build 2208 allows creation of arbitrary files on a user's workstation using crafted ZED! containers because the watermark loading function can place an executable file into a Startup folder.Show less
4Debian
GlusterOpensuse+1 more
6Debian Linux
Enterprise LinuxEnterprise Linux Server+3 more
Nov 21, 2024
Sep 4, 2018
N/A· v4
8.8 HIGH· v3
6.5 MEDIUM· v2
A flaw was found in RPC request using gfs3_mknod_req supported by glusterfs server. An authenticated attacker could use this flaw to write files to an arbitrary location via path traversal and execute arbitrary code on a...Show more
A flaw was found in RPC request using gfs3_mknod_req supported by glusterfs server. An authenticated attacker could use this flaw to write files to an arbitrary location via path traversal and execute arbitrary code on a glusterfs server node.Show less
1Ponsoftware
1Explzh
Nov 21, 2024
Sep 4, 2018
N/A· v4
7.8 HIGH· v3
6.8 MEDIUM· v2
Directory traversal vulnerability in Explzh v.7.58 and earlier allows an attacker to read arbitrary files via unspecified vectors.
1Seamcms
1Seacms
Nov 21, 2024
Sep 4, 2018
N/A· v4
7.5 HIGH· v3
6.4 MEDIUM· v2
An issue was discovered in SeaCMS through 6.61. adm1n/admin_database.php allows remote attackers to delete arbitrary files via directory traversal sequences in the bakfiles parameter. This can allow the product to be rei...Show more
An issue was discovered in SeaCMS through 6.61. adm1n/admin_database.php allows remote attackers to delete arbitrary files via directory traversal sequences in the bakfiles parameter. This can allow the product to be reinstalled by deleting install_lock.txt.Show less
1Qduoj
1Onlinejudge
Nov 21, 2024
Sep 2, 2018
N/A· v4
9.9 CRITICAL· v3
9.0 HIGH· v2
In OnlineJudge 2.0, the sandbox has an incorrect access control vulnerability that can write a file anywhere. A user can write a directory listing to /tmp, and can leak file data with a #include.
1Zzcms
1Zzcms
Nov 21, 2024
Sep 2, 2018
N/A· v4
7.5 HIGH· v3
6.4 MEDIUM· v2
An issue was discovered in zzcms 8.3. It allows remote attackers to delete arbitrary files via directory traversal sequences in the flv parameter. This can be leveraged for database access by deleting install.lock.
1Idreamsoft
1Icms
Nov 21, 2024
Sep 1, 2018
N/A· v4
7.2 HIGH· v3
6.5 MEDIUM· v2
idreamsoft iCMS 7.0.11 allows admincp.php?app=config Directory Traversal, resulting in execution of arbitrary PHP code from a ZIP file.
1Simplehttpserver Project
1Simplehttpserver
Nov 21, 2024
Aug 31, 2018
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
Path traversal in simplehttpserver <v0.2.1 allows listing any file on the server.