← Back
CWE-22

9,502 CVEs • Abstraction: Base • Likelihood of Exploit: High

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')

The product uses external input to construct a pathname that is intended to identify a file or directory that is located underneath a restricted parent directory, but the product does not properly neutralize special elements within the pathname that can cause the pathname to resolve to a location that is outside of the restricted directory.

JSON object

Loading...

CVEs (9,502)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Yellosoft
1Pinky
Apr 29, 2026
Sep 22, 2010
N/A· v4
N/A· v3
5.0 MEDIUM· v2
Directory traversal vulnerability in YelloSoft Pinky 1.0 for Windows allows remote attackers to read arbitrary files via a %5C (encoded backslash) in the URL.
1Smartertools
1Smartermail
Apr 29, 2026
Sep 22, 2010
N/A· v4
N/A· v3
5.0 MEDIUM· v2
Directory traversal vulnerability in FileStorageUpload.ashx in SmarterMail 7.1.3876 allows remote attackers to read arbitrary files via a (1) ../ (dot dot slash), (2) %5C (encoded backslash), or (3) %255c (double-encoded...Show more
Directory traversal vulnerability in FileStorageUpload.ashx in SmarterMail 7.1.3876 allows remote attackers to read arbitrary files via a (1) ../ (dot dot slash), (2) %5C (encoded backslash), or (3) %255c (double-encoded backslash) in the name parameter.Show less
1Apphp
1Php Microcms
Apr 29, 2026
Sep 22, 2010
N/A· v4
N/A· v3
6.8 MEDIUM· v2
Directory traversal vulnerability in index.php in ApPHP PHP MicroCMS 1.0.1, when magic_quotes_gpc is disabled, allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the page parameter...Show more
Directory traversal vulnerability in index.php in ApPHP PHP MicroCMS 1.0.1, when magic_quotes_gpc is disabled, allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the page parameter.Show less
1Gecad
1Axigen Mail Server
Apr 29, 2026
Sep 17, 2010
N/A· v4
N/A· v3
5.0 MEDIUM· v2
Directory traversal vulnerability in the HTTP interface in AXIGEN Mail Server 7.4.1 for Windows allows remote attackers to read arbitrary files via a %5C (encoded backslash) in the URL.
1Energyscripts
1Simple Download
Apr 29, 2026
Sep 17, 2010
N/A· v4
N/A· v3
5.0 MEDIUM· v2
Directory traversal vulnerability in download.php in EnergyScripts (ES) Simple Download 1.0 allows remote attackers to read arbitrary files via a .. (dot dot) in the file parameter.
14you Studio
1Com Jphone
Apr 29, 2026
Sep 16, 2010
N/A· v4
N/A· v3
7.5 HIGH· v2
Directory traversal vulnerability in jphone.php in the JPhone (com_jphone) component 1.0 Alpha 3 for Joomla! allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the controller param...Show more
Directory traversal vulnerability in jphone.php in the JPhone (com_jphone) component 1.0 Alpha 3 for Joomla! allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the controller parameter to index.php.Show less
1Ibm
2Proventia Network Mail Security System Virtual Appliance
Proventia Network Mail Security System Virtual Appliance Firmware
Apr 29, 2026
Sep 14, 2010
N/A· v4
N/A· v3
4.0 MEDIUM· v2
Directory traversal vulnerability in sla/index.php in the Local Management Interface (LMI) on the IBM Proventia Network Mail Security System (PNMSS) appliance with firmware before 2.5 allows remote authenticated users to...Show more
Directory traversal vulnerability in sla/index.php in the Local Management Interface (LMI) on the IBM Proventia Network Mail Security System (PNMSS) appliance with firmware before 2.5 allows remote authenticated users to read arbitrary files via a .. (dot dot) in the l parameter, related to an "Insecure Direct Object Reference vulnerability."Show less
1Xmlswf
1Com Picsell
Apr 29, 2026
Sep 3, 2010
N/A· v4
N/A· v3
5.0 MEDIUM· v2
Directory traversal vulnerability in the PicSell (com_picsell) component 1.0 for Joomla! allows remote attackers to read arbitrary files via a .. (dot dot) in the dflink parameter in a prevsell dwnfree action to index.ph...Show more
Directory traversal vulnerability in the PicSell (com_picsell) component 1.0 for Joomla! allows remote attackers to read arbitrary files via a .. (dot dot) in the dflink parameter in a prevsell dwnfree action to index.php.Show less
1In Portal
1In Portal
Apr 29, 2026
Aug 25, 2010
N/A· v4
N/A· v3
6.8 MEDIUM· v2
Directory traversal vulnerability in index.php in In-Portal 4.3.1, when magic_quotes_gpc is disabled, allows remote attackers to read arbitrary files via a .. (dot dot) in the env parameter.
1Tufat
1Mybackup
Apr 29, 2026
Aug 25, 2010
N/A· v4
N/A· v3
5.0 MEDIUM· v2
Directory traversal vulnerability in down.php in MyBackup 1.4.0 allows remote attackers to read arbitrary files via a .. (dot dot) in the filename parameter.
1Deskshare
1Auto Ftp Manager
Apr 29, 2026
Aug 21, 2010
N/A· v4
N/A· v3
9.3 HIGH· v2
Directory traversal vulnerability in DeskShare AutoFTP Manager 4.31, and probably earlier versions, allows remote FTP servers to write arbitrary files via a "..\" (dot dot backslash) in a filename.
1Ftpgetter
1Ftpgetter
Apr 29, 2026
Aug 21, 2010
N/A· v4
N/A· v3
9.3 HIGH· v2
Directory traversal vulnerability in FTPGetter Team FTPGetter 3.51.0.05, and probably earlier versions, allows remote FTP servers to write arbitrary files via a "..\" (dot dot backslash) in a filename.
13dftp
13d Ftp Client
Apr 29, 2026
Aug 21, 2010
N/A· v4
N/A· v3
9.3 HIGH· v2
Directory traversal vulnerability in SiteDesigner Technologies, Inc. 3D-FTP Client 9.0 build 2, and probably earlier versions, allows remote FTP servers to write arbitrary files via a "..\" (dot dot backslash) in a filen...Show more
Directory traversal vulnerability in SiteDesigner Technologies, Inc. 3D-FTP Client 9.0 build 2, and probably earlier versions, allows remote FTP servers to write arbitrary files via a "..\" (dot dot backslash) in a filename.Show less
1Ftpx
1Ftp Explorer
Apr 29, 2026
Aug 21, 2010
N/A· v4
N/A· v3
9.3 HIGH· v2
Directory traversal vulnerability in FTPx Corp FTP Explorer 10.5.19.1 for Windows, and probably earlier versions, allows remote FTP servers to write arbitrary files via a "..\" (dot dot backslash) in a filename.
1Portaplus
1Porta+ Ftp Client
Apr 29, 2026
Aug 20, 2010
N/A· v4
N/A· v3
9.3 HIGH· v2
Directory traversal vulnerability in Porta+ FTP Client 4.1, and possibly other versions, allows remote FTP servers to overwrite arbitrary files via a directory traversal sequences in a filename.
1Smartftp
1Smartftp
Apr 29, 2026
Aug 20, 2010
N/A· v4
N/A· v3
9.3 HIGH· v2
Directory traversal vulnerability in SmartSoft Ltd SmartFTP Client 4.0.1124.0, and possibly other versions before 4.0 Build 1133, allows remote FTP servers to overwrite arbitrary files via a "..\" (dot dot backslash) in...Show more
Directory traversal vulnerability in SmartSoft Ltd SmartFTP Client 4.0.1124.0, and possibly other versions before 4.0 Build 1133, allows remote FTP servers to overwrite arbitrary files via a "..\" (dot dot backslash) in a filename. NOTE: some of these details are obtained from third party information.Show less
1Ftprush
1Ftprush
Apr 29, 2026
Aug 20, 2010
N/A· v4
N/A· v3
9.3 HIGH· v2
Directory traversal vulnerability in IoRush Software FTP Rush 1.1.3 and possibly earlier allows remote FTP servers to overwrite arbitrary files via a "..\" (dot dot backslash) in a filename.
1Winfrigate
1Frigate 3
Apr 29, 2026
Aug 20, 2010
N/A· v4
N/A· v3
9.3 HIGH· v2
Directory traversal vulnerability in WinFrigate Frigate 3 FTP client 3.36 and earlier allows remote FTP servers to overwrite arbitrary files via a "..\" (dot dot backslash) in a filename.
1Softx
1Ftp Client
Apr 29, 2026
Aug 20, 2010
N/A· v4
N/A· v3
9.3 HIGH· v2
Directory traversal vulnerability in SoftX FTP Client 3.3 and possibly earlier allows remote FTP servers to write arbitrary files via "..\" (dot dot backslash) sequences in a filename.
1Adobe
1Coldfusion
Apr 21, 2026
Aug 11, 2010
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
Multiple directory traversal vulnerabilities in the administrator console in Adobe ColdFusion 9.0.1 and earlier allow remote attackers to read arbitrary files via the locale parameter to (1) CFIDE/administrator/settings/...Show more
Multiple directory traversal vulnerabilities in the administrator console in Adobe ColdFusion 9.0.1 and earlier allow remote attackers to read arbitrary files via the locale parameter to (1) CFIDE/administrator/settings/mappings.cfm, (2) logging/settings.cfm, (3) datasources/index.cfm, (4) j2eepackaging/editarchive.cfm, and (5) enter.cfm in CFIDE/administrator/.Show less