← Back
CWE-22

9,540 CVEs • Abstraction: Base • Likelihood of Exploit: High

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')

The product uses external input to construct a pathname that is intended to identify a file or directory that is located underneath a restricted parent directory, but the product does not properly neutralize special elements within the pathname that can cause the pathname to resolve to a location that is outside of the restricted directory.

JSON object

Loading...

CVEs (9,540)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Damicms
1Damicms
Nov 21, 2024
Aug 30, 2018
N/A· v4
2.7 LOW· v3
4.0 MEDIUM· v2
An issue was discovered in damiCMS V6.0.1. There is Directory Traversal via '|' characters in the s parameter to admin.php, as demonstrated by an admin.php?s=Tpl/Add/id/c:|windows|win.ini URI.
1Argussurveillance
1Dvr
Nov 21, 2024
Aug 30, 2018
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
Argus Surveillance DVR 4.0.0.0 devices allow Unauthenticated Directory Traversal, leading to File Disclosure via a ..%2F in the WEBACCOUNT.CGI RESULTPAGE parameter.
1Xovis
3Pc2 Firmware
Pc2r FirmwarePc3 Firmware
Nov 21, 2024
Aug 30, 2018
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
Xovis PC2, PC2R, and PC3 devices through 3.6.0 allow Directory Traversal.
1Thinkcmf
1Thinkcmfx
Nov 21, 2024
Aug 30, 2018
N/A· v4
6.5 MEDIUM· v3
5.5 MEDIUM· v2
ThinkCMF X2.2.3 has an arbitrary file deletion vulnerability in do_avatar in \application\User\Controller\ProfileController.class.php via an imgurl parameter with a ..\ sequence. A member user can delete any file on a Wi...Show more
ThinkCMF X2.2.3 has an arbitrary file deletion vulnerability in do_avatar in \application\User\Controller\ProfileController.class.php via an imgurl parameter with a ..\ sequence. A member user can delete any file on a Windows server.Show less
1Cybrotech
1Cybrohttpserver
Nov 21, 2024
Aug 29, 2018
N/A· v4
5.3 MEDIUM· v3
5.0 MEDIUM· v2
Cybrotech CyBroHttpServer 1.0.3 allows Directory Traversal via a ../ in the URI.
1Visiology
1Flipbox
Nov 21, 2024
Aug 27, 2018
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
Visiology Flipbox Software Suite before 2.7.0 allows directory traversal via %5c%2e%2e%2f because it does not sanitize filename parameters.
1Asustor
1Data Master
Nov 21, 2024
Aug 27, 2018
N/A· v4
6.5 MEDIUM· v3
8.5 HIGH· v2
ASUSTOR Data Master 3.1.5 and below allows authenticated remote non-administrative users to delete any file on the file system due to a path traversal vulnerability in wallpaper.cgi.
1Asustor
1Data Master
Nov 21, 2024
Aug 27, 2018
N/A· v4
7.5 HIGH· v3
6.0 MEDIUM· v2
ASUSTOR Data Master 3.1.5 and below allows authenticated remote non-administrative users to upload files to arbitrary locations due to a path traversal vulnerability. This could lead to code execution if the "Web Server"...Show more
ASUSTOR Data Master 3.1.5 and below allows authenticated remote non-administrative users to upload files to arbitrary locations due to a path traversal vulnerability. This could lead to code execution if the "Web Server" feature is enabled.Show less
1Tecrail
1Responsive Filemanager
Nov 21, 2024
Aug 24, 2018
N/A· v4
5.5 MEDIUM· v3
5.8 MEDIUM· v2
/filemanager/ajax_calls.php in tecrail Responsive FileManager before 9.13.4 does not properly validate file paths in archives, allowing for the extraction of crafted archives to overwrite arbitrary files via an extract a...Show more
/filemanager/ajax_calls.php in tecrail Responsive FileManager before 9.13.4 does not properly validate file paths in archives, allowing for the extraction of crafted archives to overwrite arbitrary files via an extract action, aka Directory Traversal.Show less
1Tecrail
1Responsive Filemanager
Nov 21, 2024
Aug 24, 2018
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
/filemanager/ajax_calls.php in tecrail Responsive FileManager before 9.13.4 uses external input to construct a pathname that should be within a restricted directory, but it does not properly neutralize get_file sequences...Show more
/filemanager/ajax_calls.php in tecrail Responsive FileManager before 9.13.4 uses external input to construct a pathname that should be within a restricted directory, but it does not properly neutralize get_file sequences such as ".." that can resolve to a location that is outside of that directory, aka Directory Traversal.Show less
2Openstack
Redhat
2Openstack
Tripleo Common
Nov 21, 2024
Aug 22, 2018
N/A· v4
8.2 HIGH· v3
7.2 HIGH· v2
A flaw was found in openstack-tripleo-common as shipped with Red Hat Openstack Enterprise 10 and 11. The sudoers file as installed with OSP's openstack-tripleo-common package is much too permissive. It contains several l...Show more
A flaw was found in openstack-tripleo-common as shipped with Red Hat Openstack Enterprise 10 and 11. The sudoers file as installed with OSP's openstack-tripleo-common package is much too permissive. It contains several lines for the mistral user that have wildcards that allow directory traversal with '..' and it grants full passwordless root access to the validations user.Show less
1Emerson
1Deltav
Nov 21, 2024
Aug 21, 2018
N/A· v4
8.8 HIGH· v3
6.5 MEDIUM· v2
DeltaV Versions 11.3.1, 12.3.1, 13.3.0, 13.3.1, and R5 is vulnerable due to improper path validation which may allow an attacker to replace executable files.
3Ibm
OracleRedhat
6Enterprise Linux Desktop
Enterprise Linux ServerEnterprise Linux Workstation+3 more
Nov 21, 2024
Aug 20, 2018
N/A· v4
6.5 MEDIUM· v3
4.3 MEDIUM· v2
The IBM Java Runtime Environment's Diagnostic Tooling Framework for Java (DTFJ) (IBM SDK, Java Technology Edition 6.0 , 7.0, and 8.0) does not protect against path traversal attacks when extracting compressed dump files....Show more
The IBM Java Runtime Environment's Diagnostic Tooling Framework for Java (DTFJ) (IBM SDK, Java Technology Edition 6.0 , 7.0, and 8.0) does not protect against path traversal attacks when extracting compressed dump files. IBM X-Force ID: 144882.Show less
1Tridium
2Niagara
Niagara Ax Framework
Nov 21, 2024
Aug 20, 2018
N/A· v4
7.2 HIGH· v3
6.5 MEDIUM· v2
A path traversal vulnerability in Tridium Niagara AX Versions 3.8 and prior and Niagara 4 systems Versions 4.4 and prior installed on Microsoft Windows Systems can be exploited by leveraging valid platform (administrator...Show more
A path traversal vulnerability in Tridium Niagara AX Versions 3.8 and prior and Niagara 4 systems Versions 4.4 and prior installed on Microsoft Windows Systems can be exploited by leveraging valid platform (administrator) credentials.Show less
1Librehealth
1Librehealth Ehr
Nov 21, 2024
Aug 20, 2018
N/A· v4
7.1 HIGH· v3
5.5 MEDIUM· v2
LibreHealthIO lh-ehr version REL-2.0.0 contains a Authenticated Unrestricted File Deletion vulnerability in Import template that can result in Denial of service. This attack appear to be exploitable via User controlled p...Show more
LibreHealthIO lh-ehr version REL-2.0.0 contains a Authenticated Unrestricted File Deletion vulnerability in Import template that can result in Denial of service. This attack appear to be exploitable via User controlled parameter.Show less
1Tecrail
1Responsive Filemanager
Nov 21, 2024
Aug 18, 2018
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
/filemanager/upload.php in Responsive FileManager before 9.13.3 allows Directory Traversal and SSRF because the url parameter is used directly in a curl_exec call, as demonstrated by a file:///etc/passwd value.
1Trendmicro
1Control Manager
Nov 21, 2024
Aug 15, 2018
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
A Directory Traversal Remote Code Execution vulnerability in Trend Micro Control Manager (versions 6.0 and 7.0) could allow an attacker to execute arbitrary code on vulnerable installations.
1Citrix
1Xenserver
Nov 21, 2024
Aug 15, 2018
N/A· v4
9.8 CRITICAL· v3
10.0 HIGH· v2
Citrix XenServer 7.1 and newer allows Directory Traversal.
1Ericssonlg
1Ipecs Nms
Nov 21, 2024
Aug 15, 2018
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
Ericsson-LG iPECS NMS 30M allows directory traversal via ipecs-cm/download?filename=../ URIs.
1Pulpproject
1Pulp
Nov 21, 2024
Aug 15, 2018
N/A· v4
6.5 MEDIUM· v3
4.0 MEDIUM· v2
pulp 2.16.x and possibly older is vulnerable to an improper path parsing. A malicious user or a malicious iso feed repository can write to locations accessible to the 'apache' user. This may lead to overwrite of publishe...Show more
pulp 2.16.x and possibly older is vulnerable to an improper path parsing. A malicious user or a malicious iso feed repository can write to locations accessible to the 'apache' user. This may lead to overwrite of published content on other iso repositories.Show less