← Back
CWE-22

9,540 CVEs • Abstraction: Base • Likelihood of Exploit: High

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')

The product uses external input to construct a pathname that is intended to identify a file or directory that is located underneath a restricted parent directory, but the product does not properly neutralize special elements within the pathname that can cause the pathname to resolve to a location that is outside of the restricted directory.

JSON object

Loading...

CVEs (9,540)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Oracle
1Jdeveloper
Nov 21, 2024
Jan 18, 2018
N/A· v4
4.7 MEDIUM· v3
3.7 LOW· v2
Vulnerability in the Oracle JDeveloper component of Oracle Fusion Middleware (subcomponent: Deployment). Supported versions that are affected are 11.1.1.7.0, 11.1.1.7.1, 11.1.1.9.0, 11.1.2.4.0, 12.1.3.0.0 and 12.2.1.2.0....Show more
Vulnerability in the Oracle JDeveloper component of Oracle Fusion Middleware (subcomponent: Deployment). Supported versions that are affected are 11.1.1.7.0, 11.1.1.7.1, 11.1.1.9.0, 11.1.2.4.0, 12.1.3.0.0 and 12.2.1.2.0. Difficult to exploit vulnerability allows high privileged attacker with logon to the infrastructure where Oracle JDeveloper executes to compromise Oracle JDeveloper. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle JDeveloper, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle JDeveloper accessible data as well as unauthorized read access to a subset of Oracle JDeveloper accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Oracle JDeveloper. CVSS 3.0 Base Score 4.7 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.0/AV:L/AC:H/PR:H/UI:R/S:C/C:L/I:L/A:L).Show less
2Minizip Project
Zlib Ng
2Minizip
Minizip Ng
Mar 24, 2026
Jan 16, 2018
N/A· v4
5.5 MEDIUM· v3
4.3 MEDIUM· v2
Directory traversal vulnerability in the do_extract_currentfile function in miniunz.c in miniunzip in minizip before 1.1-5 might allow remote attackers to write to arbitrary files via a crafted entry in a ZIP archive.
1Magicwinmail
1Winmail Server
Jun 17, 2026
Jan 14, 2018
N/A· v4
8.8 HIGH· v3
6.5 MEDIUM· v2
Winmail Server through 6.2 allows remote code execution by authenticated users who leverage directory traversal in a netdisk.php copy_folder_file call (in inc/class.ftpfolder.php) to move a .php file from the FTP folder...Show more
Winmail Server through 6.2 allows remote code execution by authenticated users who leverage directory traversal in a netdisk.php copy_folder_file call (in inc/class.ftpfolder.php) to move a .php file from the FTP folder into a web folder.Show less
1Skyboxsecurity
1Skybox Platform
Nov 21, 2024
Jan 12, 2018
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
An issue was discovered in Skybox Platform before 7.5.201. Directory Traversal exists in /skyboxview/webskybox/attachmentdownload and /skyboxview/webskybox/filedownload via the tempFileName parameter.
1Microsemi
1S350i Firmware
Nov 21, 2024
Jan 11, 2018
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
Directory traversal vulnerability in the web application in Symmetricom s350i 2.70.15 allows remote attackers to read arbitrary files via a (1) ../ (dot dot slash) or (2) ..\ (dot dot forward slash) before a file name.
1Yawcam
1Yawcam
Nov 21, 2024
Jan 10, 2018
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
Directory traversal in the HTTP server on Yawcam 0.2.6 through 0.6.0 devices allows attackers to read arbitrary files through a sequence of the form '.x./' or '....\x/' where x is a pattern composed of one or more (zero...Show more
Directory traversal in the HTTP server on Yawcam 0.2.6 through 0.6.0 devices allows attackers to read arbitrary files through a sequence of the form '.x./' or '....\x/' where x is a pattern composed of one or more (zero or more for the second pattern) of either \ or ..\ -- for example a '.\./', '....\/' or '...\./' sequence. For files with no extension, a single dot needs to be appended to ensure the HTTP server does not alter the request, e.g., a "GET /.\./.\./.\./.\./.\./.\./.\./windows/system32/drivers/etc/hosts." request.Show less
1Ibm
1Security Key Lifecycle Manager
Nov 21, 2024
Jan 9, 2018
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
IBM Tivoli Key Lifecycle Manager 2.5, 2.6, and 2.7 could allow a remote attacker to traverse directories on the system. An attacker could send a specially-crafted URL request containing "dot dot" sequences (/../) to view...Show more
IBM Tivoli Key Lifecycle Manager 2.5, 2.6, and 2.7 could allow a remote attacker to traverse directories on the system. An attacker could send a specially-crafted URL request containing "dot dot" sequences (/../) to view arbitrary files on the system. IBM X-Force ID: 133638.Show less
1Media From Ftp Project
1Media From Ftp
Nov 21, 2024
Jan 9, 2018
N/A· v4
6.5 MEDIUM· v3
4.0 MEDIUM· v2
In the "Media from FTP" plugin before 9.85 for WordPress, Directory Traversal exists via the searchdir parameter to the wp-admin/admin.php?page=mediafromftp-search-register URI.
1Photos In Wifi Project
1Photos In Wifi
Nov 21, 2024
Jan 8, 2018
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
The Photos in Wifi application 1.0.1 for iOS has directory traversal via the ext parameter to assets-library://asset/asset.php.
1Gd Rating System Project
1Gd Rating System
Nov 21, 2024
Jan 8, 2018
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
The GD Rating System plugin 2.3 for WordPress has Directory Traversal in the wp-admin/admin.php panel parameter for the gd-rating-system-tools page.
1Gd Rating System Project
1Gd Rating System
Nov 21, 2024
Jan 8, 2018
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
The GD Rating System plugin 2.3 for WordPress has Directory Traversal in the wp-admin/admin.php panel parameter for the gd-rating-system-transfer page.
1Gd Rating System Project
1Gd Rating System
Nov 21, 2024
Jan 8, 2018
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
The GD Rating System plugin 2.3 for WordPress has Directory Traversal in the wp-admin/admin.php panel parameter for the gd-rating-system-information page.
1Gd Rating System Project
1Gd Rating System
Nov 21, 2024
Jan 8, 2018
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
The GD Rating System plugin 2.3 for WordPress has Directory Traversal in the wp-admin/admin.php panel parameter for the gd-rating-system-about page.
1Emc
3Avamar Server
Integrated Data Protection ApplianceNetworker
Nov 21, 2024
Jan 5, 2018
N/A· v4
8.8 HIGH· v3
9.0 HIGH· v2
An issue was discovered in EMC Avamar Server 7.1.x, 7.2.x, 7.3.x, 7.4.x, 7.5.0; EMC NetWorker Virtual Edition (NVE) 9.0.x, 9.1.x, 9.2.x; and EMC Integrated Data Protection Appliance 2.0. A remote authenticated malicious...Show more
An issue was discovered in EMC Avamar Server 7.1.x, 7.2.x, 7.3.x, 7.4.x, 7.5.0; EMC NetWorker Virtual Edition (NVE) 9.0.x, 9.1.x, 9.2.x; and EMC Integrated Data Protection Appliance 2.0. A remote authenticated malicious user with low privileges could access arbitrary files on the server file system in the context of the running vulnerable application via Path traversal.Show less
1Advantech
1Webaccess
Nov 21, 2024
Jan 5, 2018
N/A· v4
9.8 CRITICAL· v3
10.0 HIGH· v2
A Path Traversal issue was discovered in WebAccess versions 8.3.2 and earlier. An attacker has access to files within the directory structure of the target device.
2Debian
Pocoproject
2Debian Linux
Poco
Nov 21, 2024
Jan 3, 2018
N/A· v4
6.5 MEDIUM· v3
5.8 MEDIUM· v2
The ZipCommon::isValidPath() function in Zip/src/ZipCommon.cpp in POCO C++ Libraries before 1.8 does not properly restrict the filename value in the ZIP header, which allows attackers to conduct absolute path traversal a...Show more
The ZipCommon::isValidPath() function in Zip/src/ZipCommon.cpp in POCO C++ Libraries before 1.8 does not properly restrict the filename value in the ZIP header, which allows attackers to conduct absolute path traversal attacks during the ZIP decompression, and possibly create or overwrite arbitrary files, via a crafted ZIP file, related to a "file path injection vulnerability".Show less
2Acquia
Mautic
2Mautic
Mautic
Nov 21, 2024
Jan 3, 2018
N/A· v4
6.5 MEDIUM· v3
4.0 MEDIUM· v2
Mautic versions 1.0.0 - 2.11.0 are vulnerable to allowing any authorized Mautic user session (must be logged into Mautic) to use the Filemanager to download any file from the server that the web user has access to.
2Awstats
Debian
2Awstats
Debian Linux
Nov 21, 2024
Jan 3, 2018
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
Awstats version 7.6 and earlier is vulnerable to a path traversal flaw in the handling of the "config" and "migrate" parameters resulting in unauthenticated remote code execution.
1Structured Data
1Structured Data Linter
Nov 21, 2024
Jan 2, 2018
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
Structured Data Linter versions 2.4.1 and older are vulnerable to a directory traversal attack in the URL input field resulting in the possibility of disclosing information about the remote host.
1Schneider Electric
1Pelco Videoxpert
Nov 21, 2024
Jan 2, 2018
N/A· v4
5.8 MEDIUM· v3
5.0 MEDIUM· v2
An exposure of sensitive information vulnerability exists in Schneider Electric's Pelco VideoXpert Enterprise versions 2.0 and prior. Using a directory traversal attack, an unauthorized person can view web server files.