← Back
CWE-22

9,502 CVEs • Abstraction: Base • Likelihood of Exploit: High

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')

The product uses external input to construct a pathname that is intended to identify a file or directory that is located underneath a restricted parent directory, but the product does not properly neutralize special elements within the pathname that can cause the pathname to resolve to a location that is outside of the restricted directory.

JSON object

Loading...

CVEs (9,502)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
2Apache
Jsecurity
2Jsecurity
Shiro
Apr 29, 2026
Nov 5, 2010
N/A· v4
N/A· v3
5.0 MEDIUM· v2
Apache Shiro before 1.1.0, and JSecurity 0.9.x, does not canonicalize URI paths before comparing them to entries in the shiro.ini file, which allows remote attackers to bypass intended access restrictions via a crafted r...Show more
Apache Shiro before 1.1.0, and JSecurity 0.9.x, does not canonicalize URI paths before comparing them to entries in the shiro.ini file, which allows remote attackers to bypass intended access restrictions via a crafted request, as demonstrated by the /./account/index.jsp URI.Show less
1Yaws
1Yaws
Apr 29, 2026
Nov 4, 2010
N/A· v4
N/A· v3
5.0 MEDIUM· v2
Directory traversal vulnerability in Yaws 1.89 allows remote attackers to read arbitrary files via ..\ (dot dot backslash) and other sequences.
1Rhinosoft
1Ftp Voyager
Apr 29, 2026
Nov 3, 2010
N/A· v4
N/A· v3
9.3 HIGH· v2
Directory traversal vulnerability in Rhino Software, Inc. FTP Voyager 15.2.0.11, and possibly earlier, allows remote FTP servers to write arbitrary files via a "..\" (dot dot backslash) in a filename.
1Crossftp
1Crossftp Pro
Apr 29, 2026
Nov 3, 2010
N/A· v4
N/A· v3
9.3 HIGH· v2
Directory traversal vulnerability in CrossFTP Pro 1.65a, and probably earlier, allows remote FTP servers to write arbitrary files via a "..\" (dot dot backslash) in a filename.
1Freshwebmaster
1Fresh Ftp
Apr 29, 2026
Nov 2, 2010
N/A· v4
N/A· v3
9.3 HIGH· v2
Directory traversal vulnerability in FreshWebMaster Fresh FTP 5.36, 5.37, and possibly earlier, allows remote FTP servers to write arbitrary files via a "..\" (dot dot backslash) in a filename. NOTE: some of these detai...Show more
Directory traversal vulnerability in FreshWebMaster Fresh FTP 5.36, 5.37, and possibly earlier, allows remote FTP servers to write arbitrary files via a "..\" (dot dot backslash) in a filename. NOTE: some of these details are obtained from third party information.Show less
1Anyconnect
1Anyconnect
Apr 29, 2026
Nov 2, 2010
N/A· v4
N/A· v3
9.3 HIGH· v2
Directory traversal vulnerability in AnyConnect 1.2.3.0, and possibly earlier, allows remote FTP servers to write arbitrary files via a "..\" (dot dot backslash) in a filename.
1Curl
1Curl
Apr 29, 2026
Oct 28, 2010
N/A· v4
N/A· v3
5.8 MEDIUM· v2
Absolute path traversal vulnerability in curl 7.20.0 through 7.21.1, when the --remote-header-name or -J option is used, allows remote servers to create or overwrite arbitrary files by using \ (backslash) as a separator...Show more
Absolute path traversal vulnerability in curl 7.20.0 through 7.21.1, when the --remote-header-name or -J option is used, allows remote servers to create or overwrite arbitrary files by using \ (backslash) as a separator of path components within the Content-disposition HTTP header.Show less
1Robo Ftp
1Robo Ftp
Apr 29, 2026
Oct 26, 2010
N/A· v4
N/A· v3
9.3 HIGH· v2
Directory traversal vulnerability in the FTP client in Serengeti Systems Incorporated Robo-FTP 3.7.3, and probably other versions before 3.7.5, allows remote FTP servers to write arbitrary files via a .. (dot dot) in a f...Show more
Directory traversal vulnerability in the FTP client in Serengeti Systems Incorporated Robo-FTP 3.7.3, and probably other versions before 3.7.5, allows remote FTP servers to write arbitrary files via a .. (dot dot) in a filename in a server response.Show less
1G.rodola
1Pyftpdlib
Apr 29, 2026
Oct 19, 2010
N/A· v4
N/A· v3
6.5 MEDIUM· v2
Multiple directory traversal vulnerabilities in FTPServer.py in pyftpdlib before 0.3.0 allow remote authenticated users to access arbitrary files and directories via vectors involving a symlink in a pathname to a (1) CWD...Show more
Multiple directory traversal vulnerabilities in FTPServer.py in pyftpdlib before 0.3.0 allow remote authenticated users to access arbitrary files and directories via vectors involving a symlink in a pathname to a (1) CWD, (2) DELE, (3) STOR, or (4) RETR command.Show less
1G.rodola
1Pyftpdlib
Apr 29, 2026
Oct 19, 2010
N/A· v4
N/A· v3
6.5 MEDIUM· v2
Multiple directory traversal vulnerabilities in FTPServer.py in pyftpdlib before 0.2.0 allow remote authenticated users to access arbitrary files and directories via a .. (dot dot) in a (1) LIST, (2) STOR, or (3) RETR co...Show more
Multiple directory traversal vulnerabilities in FTPServer.py in pyftpdlib before 0.2.0 allow remote authenticated users to access arbitrary files and directories via a .. (dot dot) in a (1) LIST, (2) STOR, or (3) RETR command.Show less
1Rene Tegel
1Visual Synapse
Apr 29, 2026
Oct 8, 2010
N/A· v4
N/A· v3
5.0 MEDIUM· v2
Directory traversal vulnerability in Visual Synapse HTTP Server 1.0 RC1 through RC3, and 0.60 and earlier, allows remote attackers to read arbitrary files via a .. (dot dot) in the URI.
1Cmsmadesimple
1Cms Made Simple
Apr 29, 2026
Oct 8, 2010
N/A· v4
N/A· v3
7.5 HIGH· v2
Directory traversal vulnerability in lib/translation.functions.php in CMS Made Simple before 1.8.1 allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the default_cms_lang parameter...Show more
Directory traversal vulnerability in lib/translation.functions.php in CMS Made Simple before 1.8.1 allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the default_cms_lang parameter to an admin script, as demonstrated by admin/addbookmark.php, a different vulnerability than CVE-2008-5642.Show less
1Apereo
1Phpcas
Apr 29, 2026
Oct 7, 2010
N/A· v4
N/A· v3
6.4 MEDIUM· v2
Directory traversal vulnerability in the callback function in client.php in phpCAS before 1.1.3, when proxy mode is enabled, allows remote attackers to create or overwrite arbitrary files via directory traversal sequence...Show more
Directory traversal vulnerability in the callback function in client.php in phpCAS before 1.1.3, when proxy mode is enabled, allows remote attackers to create or overwrite arbitrary files via directory traversal sequences in a Proxy Granting Ticket IOU (PGTiou) parameter.Show less
1Netartmedia
1Websiteadmin
Apr 29, 2026
Sep 29, 2010
N/A· v4
N/A· v3
7.5 HIGH· v2
Directory traversal vulnerability in ADMIN/login.php in NetArtMEDIA WebSiteAdmin allows remote emote attackers to include and execute arbitrary local files via directory traversal sequences in the lng parameter.
1Blueriver
2Mura Cms
Sava Cms
Apr 29, 2026
Sep 29, 2010
N/A· v4
N/A· v3
5.0 MEDIUM· v2
Directory traversal vulnerability in fileManager.cfc in Mura CMS 5.1 before 5.1.498 and 5.2 before 5.2.2809, and Sava CMS 5 through 5.2, allows remote attackers to read arbitrary files via a .. (dot dot) in the FILEID pa...Show more
Directory traversal vulnerability in fileManager.cfc in Mura CMS 5.1 before 5.1.498 and 5.2 before 5.2.2809, and Sava CMS 5 through 5.2, allows remote attackers to read arbitrary files via a .. (dot dot) in the FILEID parameter to the default URI under tasks/render/file/.Show less
1Sangoma
1Freepbx
Apr 29, 2026
Sep 28, 2010
N/A· v4
N/A· v3
6.5 MEDIUM· v2
Directory traversal vulnerability in page.recordings.php in the System Recordings component in the configuration interface in FreePBX 2.8.0 and earlier allows remote authenticated administrators to create arbitrary files...Show more
Directory traversal vulnerability in page.recordings.php in the System Recordings component in the configuration interface in FreePBX 2.8.0 and earlier allows remote authenticated administrators to create arbitrary files via a .. (dot dot) in the usersnum parameter to admin/config.php, as demonstrated by creating a .php file under the web root.Show less
1Netartmedia
1Real Estate Portal
Apr 29, 2026
Sep 24, 2010
N/A· v4
N/A· v3
6.8 MEDIUM· v2
Multiple directory traversal vulnerabilities in AGENTS/index.php in NetArt MEDIA Real Estate Portal 2.0 allow remote emote attackers to include and execute arbitrary local files via directory traversal sequences in the (...Show more
Multiple directory traversal vulnerabilities in AGENTS/index.php in NetArt MEDIA Real Estate Portal 2.0 allow remote emote attackers to include and execute arbitrary local files via directory traversal sequences in the (1) folder and (2) action parameters.Show less
1Salvo G. Tomaselli
1Weborf
Apr 29, 2026
Sep 24, 2010
N/A· v4
N/A· v3
5.0 MEDIUM· v2
Directory traversal vulnerability in the modURL function in instance.c in Weborf before 0.12.3 allows remote attackers to read arbitrary files via ..%2f sequences in a URI.
1Rsa
1Authentication Agent For Web
Apr 29, 2026
Sep 24, 2010
N/A· v4
N/A· v3
5.0 MEDIUM· v2
Directory traversal vulnerability in RSA Authentication Agent 7.0 before P2 for Web allows remote attackers to read unspecified data via unknown vectors.
1Houbysoft
1Quickshare
Apr 29, 2026
Sep 22, 2010
N/A· v4
N/A· v3
5.0 MEDIUM· v2
Directory traversal vulnerability in QuickShare 1.0 allows remote attackers to read arbitrary files via a ... (triple dot) in the URL.