CWE-22
9,540 CVEs • Abstraction: Base • Likelihood of Exploit: High
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
The product uses external input to construct a pathname that is intended to identify a file or directory that is located underneath a restricted parent directory, but the product does not properly neutralize special elements within the pathname that can cause the pathname to resolve to a location that is outside of the restricted directory.
CVEs (9,540)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
An issue was discovered in Sitecore Sitecore.NET 8.1 rev. 151207 Hotfix 141178-1 and above. The 'Log Viewer' application is vulnerable to a directory traversal attack, allowing an attacker to access arbitrary files from...Show more |
1Ibm 3Qradar Incident Forensics Qradar Network InsightsQradar Security Information And Event ManagerNov 21, 2024 Apr 26, 2018 N/A· v4 6.5 MEDIUM· v3 4.0 MEDIUM· v2 IBM Security QRadar SIEM 7.2 and 7.3 could allow a remote attacker to traverse directories on the system. An attacker could send a specially-crafted URL request containing "dot dot" sequences (/../) to view arbitrary fil...Show more |
1Cmsmadesimple 1Cms Made Simple Jun 17, 2026 Apr 23, 2018 N/A· v4 5.3 MEDIUM· v3 5.0 MEDIUM· v2 In CMS Made Simple 2.2.7, a Directory Traversal issue makes it possible to determine the existence of files and directories outside the web-site installation directory, and determine whether a file has contents matching...Show more |
1Digitalguardian 1Management Console Nov 21, 2024 Apr 20, 2018 N/A· v4 6.5 MEDIUM· v3 4.0 MEDIUM· v2 Digital Guardian Management Console 7.1.2.0015 has a Directory Traversal issue. |
2Debian Wpitchoune2Debian Linux PsensorNov 21, 2024 Apr 20, 2018 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 The create_response function in server/server.c in Psensor before 1.1.4 allows Directory Traversal because it lacks a check for whether a file is under the webserver directory. |
An issue was discovered in NcMonitorServer.exe in NC Monitor Server in NComputing vSpace Pro 10 and 11. It is possible to read arbitrary files outside the root directory of the web server. This vulnerability could be exp...Show more |
nmap version 6.49BETA6 through 7.60, up to and including SVN revision 37147 contains a Directory Traversal vulnerability in NSE script http-fetch that can result in file overwrite as the user is running it. This attack a...Show more |
1Zohocorp 1Manageengine Desktop Central Nov 21, 2024 Apr 18, 2018 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 An issue was discovered in Zoho ManageEngine Desktop Central 10.0.124 and 10.0.184: directory traversal in the SCRIPT_NAME field when modifying existing scripts. |
1Appeartv 2Xc5000 Firmware Xc5100 FirmwareJun 17, 2026 Apr 17, 2018 N/A· v4 9.8 CRITICAL· v3 7.8 HIGH· v2 On Appear TV XC5000 and XC5100 devices with firmware 3.26.217, it is possible to read OS files with a specially crafted HTTP request (such as GET /../../../../../../../../../../../../etc/passwd) to the web server (fuzzd/...Show more |
1Tibco 3Jasperreports Server JaspersoftJaspersoft Reporting And AnalyticsJun 17, 2026 Apr 17, 2018 N/A· v4 8.8 HIGH· v3 4.0 MEDIUM· v2 The Spring web flows of TIBCO Software Inc.'s TIBCO JasperReports Server, TIBCO JasperReports Server Community Edition, TIBCO JasperReports Server for ActiveMatrix BPM, TIBCO Jaspersoft for AWS with Multi-Tenancy, and TI...Show more |
Leao Consultoria e Desenvolvimento de Sistemas (LCDS) LTDA ME LAquis SCADA software versions prior to version 4.1.0.3237 do not neutralize external input to ensure that users are not calling for absolute path sequences o...Show more |
QingDao Nature Easy Soft Chanzhi Enterprise Portal System (aka chanzhieps) pro1.6 allows remote attackers to read arbitrary files via directory traversal sequences in the pathname parameter to www/file.php. |
Absolute path traversal vulnerability in Eshtery CMS allows remote attackers to read arbitrary files via a full pathname in the file parameter to FileManager.aspx. |
1Cmsmadesimple 1Cms Made Simple Nov 21, 2024 Apr 13, 2018 N/A· v4 7.5 HIGH· v3 6.4 MEDIUM· v2 CMS Made Simple (CMSMS) through 2.2.7 contains an arbitrary file deletion vulnerability in the admin dashboard via directory traversal sequences in the val parameter within a cmd=del request, because code under modules\F...Show more |
2Clusterlabs Redhat2Enterprise Linux Pacemaker Command Line InterfaceNov 21, 2024 Apr 12, 2018 N/A· v4 6.5 MEDIUM· v3 4.0 MEDIUM· v2 pcs before version 0.9.164 and 0.10 is vulnerable to a privilege escalation via authorized user malicious REST call. The REST interface of the pcsd service did not properly sanitize the file name from the /remote/put_fil...Show more |
199robots 1Wp Background Takeover Advertisements Jun 17, 2026 Apr 12, 2018 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 exports/download.php in the 99 Robots WP Background Takeover Advertisements plugin before 4.1.5 for WordPress has Directory Traversal via a .. in the filename parameter. |
Monstra CMS 3.0.4 allows remote attackers to delete files via an admin/index.php?id=filesmanager&delete_dir=./&path=uploads/ request. |
In Gxlcms QY v1.0.0713, Lib\Lib\Action\Admin\TplAction.class.php allows remote attackers to read any file via a modified pathname in an Admin-Tpl request, as demonstrated by use of '|' instead of '/' as a directory separ...Show more |
In Gxlcms QY v1.0.0713, Lib\Lib\Action\Admin\DataAction.class.php allows remote attackers to delete any file via directory traversal sequences in the id parameter of an Admin-Data-del request. |
An issue was discovered in zzcms 8.2. user/adv.php allows remote attackers to delete arbitrary files via directory traversal sequences in the oldimg parameter. This can be leveraged for database access by deleting instal...Show more |