CWE-22
9,540 CVEs • Abstraction: Base • Likelihood of Exploit: High
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
The product uses external input to construct a pathname that is intended to identify a file or directory that is located underneath a restricted parent directory, but the product does not properly neutralize special elements within the pathname that can cause the pathname to resolve to a location that is outside of the restricted directory.
CVEs (9,540)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
1Fast Http Cli Project 1Fast Http Cli Nov 21, 2024 Jun 7, 2018 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 fast-http-cli is the command line interface for fast-http, a simple web server. fast-http-cli is vulnerable to a directory traversal issue, giving an attacker access to the filesystem by placing "../" in the url. |
earlybird is a web server module for early development. earlybird is vulnerable to a directory traversal issue, giving an attacker access to the filesystem by placing "../" in the url. |
1Static Html Server Project 1Static Html Server Nov 21, 2024 Jun 7, 2018 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 static-html-server is a static file server. static-html-server is vulnerable to a directory traversal issue, giving an attacker access to the filesystem by placing "../" in the url. |
1Wanggoujing123 Project 1Wanggoujing123 Nov 21, 2024 Jun 7, 2018 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 wanggoujing123 is a simple webserver. wanggoujing123 is vulnerable to a directory traversal issue, giving an attacker access to the filesystem by placing "../" in the url. |
zwserver is a weather web server. zwserver is vulnerable to a directory traversal issue, giving an attacker access to the filesystem by placing "../" in the url. |
serve46 is a static file server. serve46 is vulnerable to a directory traversal issue, giving an attacker access to the filesystem by placing "../" in the url. |
1Shit Server Project 1Shit Server Nov 21, 2024 Jun 7, 2018 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 shit-server is a file server. shit-server is vulnerable to a directory traversal issue, giving an attacker access to the filesystem by placing "../" in the url. |
mockserve is a file server. mockserve is vulnerable to a directory traversal issue, giving an attacker access to the filesystem by placing "../" in the url. |
sspa is a server dedicated to single-page apps. sspa is vulnerable to a directory traversal issue, giving an attacker access to the filesystem by placing "../" in the url. |
1Myserver.alexcthomas18 Project 1Myserver.alexcthomas18 Nov 21, 2024 Jun 7, 2018 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 myserver.alexcthomas18 is a file server. myserver.alexcthomas18 is vulnerable to a directory traversal issue, giving an attacker access to the filesystem by placing "../" in the url. |
1Commentapp.stetsonwood Project 1Commentapp.stetsonwood Nov 21, 2024 Jun 7, 2018 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 commentapp.stetsonwood is an http server. commentapp.stetsonwood is vulnerable to a directory traversal issue, giving an attacker access to the filesystem by placing "../" in the url. |
1Infraserver Project 1Infraserver Nov 21, 2024 Jun 7, 2018 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 infraserver is a RESTful server. infraserver is vulnerable to a directory traversal issue, giving an attacker access to the filesystem by placing "../" in the url. |
1Lab6drewfusbyu Project 1Lab6drewfusbyu Nov 21, 2024 Jun 7, 2018 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 lab6drewfusbyu is an http server. lab6drewfusbyu is vulnerable to a directory traversal issue, giving an attacker access to the filesystem by placing "../" in the url. |
1Lab6.brit95 Project 1Lab6.brit95 Nov 21, 2024 Jun 7, 2018 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 lab6.brit95 is a file server. lab6.brit95 is vulnerable to a directory traversal issue, giving an attacker access to the filesystem by placing "../" in the url. |
jikes is a file server. jikes is vulnerable to a directory traversal issue, giving an attacker access to the filesystem by placing "../" in the url. Accessible files are restricted to files with .htm and .js extensions. |
serverzyy is a static file server. serverzyy is vulnerable to a directory traversal issue, giving an attacker access to the filesystem by placing "../" in the url. |
1Http Static Simple Project 1Http Static Simple Nov 21, 2024 Jun 7, 2018 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 http_static_simple is an http server. http_static_simple is vulnerable to a directory traversal issue, giving an attacker access to the filesystem by placing "../" in the url. |
goserv is an http server. goserv is vulnerable to a directory traversal issue, giving an attacker access to the filesystem by placing "../" in the url. |
1Simple Npm Registry Project 1Simple Npm Registry Nov 21, 2024 Jun 7, 2018 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 simple-npm-registry is a local npm package cache. simple-npm-registry is vulnerable to a directory traversal issue, giving an attacker access to the filesystem by placing "../" in the url. |
1Unicorn List Project 1Unicorn List Nov 21, 2024 Jun 7, 2018 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 unicorn-list is a web framework. unicorn-list is vulnerable to a directory traversal issue, giving an attacker access to the filesystem by placing "../" in the url. |