← Back
CWE-22

9,505 CVEs • Abstraction: Base • Likelihood of Exploit: High

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')

The product uses external input to construct a pathname that is intended to identify a file or directory that is located underneath a restricted parent directory, but the product does not properly neutralize special elements within the pathname that can cause the pathname to resolve to a location that is outside of the restricted directory.

JSON object

Loading...

CVEs (9,505)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Juan Ramon
1Osclass
Apr 29, 2026
Sep 26, 2012
N/A· v4
N/A· v3
6.4 MEDIUM· v2
Directory traversal vulnerability in combine.php in OSClass before 2.3.6 allows remote attackers to read and write arbitrary files via a .. (dot dot) in the type parameter. NOTE: this vulnerability can be leveraged to u...Show more
Directory traversal vulnerability in combine.php in OSClass before 2.3.6 allows remote attackers to read and write arbitrary files via a .. (dot dot) in the type parameter. NOTE: this vulnerability can be leveraged to upload arbitrary files.Show less
1Ibm
2Db2
Db2 Connect
Apr 29, 2026
Sep 25, 2012
N/A· v4
N/A· v3
9.0 HIGH· v2
Directory traversal vulnerability in the UTL_FILE module in IBM DB2 and DB2 Connect 10.1 before FP1 on Windows allows remote authenticated users to modify, delete, or read arbitrary files via a pathname in the file field...Show more
Directory traversal vulnerability in the UTL_FILE module in IBM DB2 and DB2 Connect 10.1 before FP1 on Windows allows remote authenticated users to modify, delete, or read arbitrary files via a pathname in the file field.Show less
1Ibm
1Websphere Application Server
Apr 29, 2026
Sep 25, 2012
N/A· v4
N/A· v3
6.4 MEDIUM· v2
Directory traversal vulnerability in IBM WebSphere Application Server (WAS) 6.1 before 6.1.0.47, 7.0 before 7.0.0.25, 8.0 before 8.0.0.5, and 8.5 before 8.5.0.1 allows remote attackers to overwrite arbitrary files via a...Show more
Directory traversal vulnerability in IBM WebSphere Application Server (WAS) 6.1 before 6.1.0.47, 7.0 before 7.0.0.25, 8.0 before 8.0.0.5, and 8.5 before 8.5.0.1 allows remote attackers to overwrite arbitrary files via a crafted application file.Show less
1Fultek
1Wintr Scada
Apr 29, 2026
Sep 25, 2012
N/A· v4
N/A· v3
7.8 HIGH· v2
Directory traversal vulnerability in the web server in Fultek WinTr Scada 4.0.5 and earlier allows remote attackers to read arbitrary files via a crafted request.
1Luizpicanco
1Hserver
Apr 29, 2026
Sep 23, 2012
N/A· v4
N/A· v3
5.0 MEDIUM· v2
Directory traversal vulnerability in HServer 0.1.1 allows remote attackers to read arbitrary files via a (1) ..%5c (dot dot encoded backslash) or (2) %2e%2e%5c (encoded dot dot backslash) in the PATH_INFO.
1Anecms
1Anecms
Apr 29, 2026
Sep 19, 2012
N/A· v4
N/A· v3
7.5 HIGH· v2
Directory traversal vulnerability in acp/index.php in AneCMS allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the p parameter.
1Flatnux
1Flatnux
Apr 29, 2026
Sep 6, 2012
N/A· v4
N/A· v3
5.0 MEDIUM· v2
Absolute path traversal vulnerability in controlcenter.php in FlatnuX CMS 2011 08.09.2 allows remote administrators to read arbitrary files via a full pathname in the dir parameter in a contents/Files action.
1Pkp
1Open Journal Systems
Apr 29, 2026
Sep 6, 2012
N/A· v4
N/A· v3
6.5 MEDIUM· v2
Multiple directory traversal vulnerabilities in the iBrowser plugin library, as used in Open Journal Systems before 2.3.7, allow remote authenticated users to (1) delete or (2) rename arbitrary files via a .. (dot dot) i...Show more
Multiple directory traversal vulnerabilities in the iBrowser plugin library, as used in Open Journal Systems before 2.3.7, allow remote authenticated users to (1) delete or (2) rename arbitrary files via a .. (dot dot) in the param parameter to lib/pkp/lib/tinymce/jscripts/tiny_mce/plugins/ibrowser/scripts/rfiles.php.Show less
1Open Realty
1Open Realty
Apr 29, 2026
Sep 6, 2012
N/A· v4
N/A· v3
6.8 MEDIUM· v2
Directory traversal vulnerability in Open-Realty CMS 2.5.8 and earlier allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the select_users_template parameter to index.php.
1Vtiger
1Vtiger Crm
Apr 29, 2026
Sep 6, 2012
N/A· v4
N/A· v3
5.0 MEDIUM· v2
Directory traversal vulnerability in modules/com_vtiger_workflow/sortfieldsjson.php in vtiger CRM 5.1.0 allows remote attackers to read arbitrary files via a .. (dot dot) in the module_name parameter.
1Wikkawiki
1Wikkawiki
Apr 29, 2026
Sep 5, 2012
N/A· v4
N/A· v3
6.4 MEDIUM· v2
Directory traversal vulnerability in handlers/files.xml/files.xml.php in WikkaWiki 1.3.1 and 1.3.2 allows remote attackers to read or delete arbitrary files via a non-initial .. (dot dot) in the file parameter, as demons...Show more
Directory traversal vulnerability in handlers/files.xml/files.xml.php in WikkaWiki 1.3.1 and 1.3.2 allows remote attackers to read or delete arbitrary files via a non-initial .. (dot dot) in the file parameter, as demonstrated by the /../../wikka.config.php pathname in a download action.Show less
1Egroupware
2Egroupware
Egroupware Enterprise Line
Apr 29, 2026
Aug 31, 2012
N/A· v4
N/A· v3
5.0 MEDIUM· v2
Directory traversal vulnerability in admin/remote.php in EGroupware Enterprise Line (EPL) before 11.1.20110804-1 and EGroupware Community Edition before 1.8.001.20110805 allows remote attackers to read arbitrary files vi...Show more
Directory traversal vulnerability in admin/remote.php in EGroupware Enterprise Line (EPL) before 11.1.20110804-1 and EGroupware Community Edition before 1.8.001.20110805 allows remote attackers to read arbitrary files via a ..%2f (encoded dot dot slash) in the type parameter.Show less
1Obm
1Open Business Management
Apr 29, 2026
Aug 31, 2012
N/A· v4
N/A· v3
6.0 MEDIUM· v2
Directory traversal vulnerability in exportcsv/exportcsv_index.php in Open Business Management (OBM) 2.4.0-rc13 and earlier allows remote authenticated users to include and execute arbitrary local files via a .. (dot dot...Show more
Directory traversal vulnerability in exportcsv/exportcsv_index.php in Open Business Management (OBM) 2.4.0-rc13 and earlier allows remote authenticated users to include and execute arbitrary local files via a .. (dot dot) in the module parameter in an export_page action.Show less
1Wargio
1Naxsi
Apr 29, 2026
Aug 31, 2012
N/A· v4
N/A· v3
2.1 LOW· v2
Directory traversal vulnerability in naxsi-ui/nx_extract.py in the Naxsi module before 0.46-1 for Nginx allows local users to read arbitrary files via unspecified vectors.
1Ioserver
1Ioserver
Apr 29, 2026
Aug 27, 2012
N/A· v4
N/A· v3
4.3 MEDIUM· v2
Directory traversal vulnerability in the XML Server in IOServer before 1.0.19.0, when the Root Directory pathname lacks a trailing \ (backslash) character, allows remote attackers to read arbitrary files or list arbitrar...Show more
Directory traversal vulnerability in the XML Server in IOServer before 1.0.19.0, when the Root Directory pathname lacks a trailing \ (backslash) character, allows remote attackers to read arbitrary files or list arbitrary directories via a .. (dot dot) in a URI.Show less
1Bluecoat
1Reporter
Apr 29, 2026
Aug 26, 2012
N/A· v4
N/A· v3
10.0 HIGH· v2
Directory traversal vulnerability in Blue Coat Reporter 9.x before 9.2.4.13, 9.2.5.x before 9.2.5.1, and 9.3 before 9.3.1.2 on Windows allows remote attackers to read arbitrary files, and consequently execute arbitrary c...Show more
Directory traversal vulnerability in Blue Coat Reporter 9.x before 9.2.4.13, 9.2.5.x before 9.2.5.1, and 9.3 before 9.3.1.2 on Windows allows remote attackers to read arbitrary files, and consequently execute arbitrary code, via an unspecified HTTP request.Show less
1Pluxml
1Pluxml
Apr 29, 2026
Aug 26, 2012
N/A· v4
N/A· v3
7.5 HIGH· v2
Directory traversal vulnerability in update/index.php in PluXml before 5.1.6 allows remote attackers to include and execute arbitrary local files via a ..%2F (encoded dot dot slash) in the default_lang parameter.
1Mcafee
1Email Gateway
Apr 29, 2026
Aug 22, 2012
N/A· v4
N/A· v3
4.3 MEDIUM· v2
Directory traversal vulnerability in McAfee Email Gateway (MEG) 7.0.0 and 7.0.1 allows remote authenticated users to bypass intended access restrictions and download arbitrary files via a crafted URL.
1Sielcosistemi
2Winlog Lite
Winlog Pro
Apr 29, 2026
Aug 19, 2012
N/A· v4
N/A· v3
4.3 MEDIUM· v2
Multiple directory traversal vulnerabilities in Sielco Sistemi Winlog Pro SCADA before 2.07.17 and Winlog Lite SCADA before 2.07.17 allow remote attackers to read arbitrary files via port-46824 TCP packets specifying a f...Show more
Multiple directory traversal vulnerabilities in Sielco Sistemi Winlog Pro SCADA before 2.07.17 and Winlog Lite SCADA before 2.07.17 allow remote attackers to read arbitrary files via port-46824 TCP packets specifying a file-open operation with opcode 0x78 and a .. (dot dot) in a pathname, followed by a file-read operation with opcode (1) 0x96, (2) 0x97, or (3) 0x98.Show less
1Piwigo
1Piwigo
Apr 29, 2026
Aug 14, 2012
N/A· v4
N/A· v3
7.5 HIGH· v2
Directory traversal vulnerability in upgrade.php in Piwigo before 2.3.4 allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the language parameter.