← Back
CWE-22

9,486 CVEs • Abstraction: Base • Likelihood of Exploit: High

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')

The product uses external input to construct a pathname that is intended to identify a file or directory that is located underneath a restricted parent directory, but the product does not properly neutralize special elements within the pathname that can cause the pathname to resolve to a location that is outside of the restricted directory.

JSON object

Loading...

CVEs (9,486)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Ringsworld
1Flashlight Free Edition
Apr 23, 2026
Dec 4, 2009
N/A· v4
N/A· v3
7.5 HIGH· v2
Directory traversal vulnerability in admin.php in Flashlight Free Edition allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the action parameter.
1Omilenitsolutions
1Com Omphotogallery
Apr 23, 2026
Dec 4, 2009
N/A· v4
N/A· v3
7.5 HIGH· v2
Directory traversal vulnerability in the Omilen Photo Gallery (com_omphotogallery) component Beta 0.5 for Joomla! allows remote attackers to include and execute arbitrary local files via directory traversal sequences in...Show more
Directory traversal vulnerability in the Omilen Photo Gallery (com_omphotogallery) component Beta 0.5 for Joomla! allows remote attackers to include and execute arbitrary local files via directory traversal sequences in the controller parameter to index.php.Show less
1Kmint21
1Golden Ftp Server
Apr 23, 2026
Dec 3, 2009
N/A· v4
8.1 HIGH· v3
6.0 MEDIUM· v2
Directory traversal vulnerability in Golden FTP Server 4.30 Free and Professional, 4.50, and possibly other versions allows remote authenticated users to delete arbitrary files via a .. (dot dot) in the DELE command. NO...Show more
Directory traversal vulnerability in Golden FTP Server 4.30 Free and Professional, 4.50, and possibly other versions allows remote authenticated users to delete arbitrary files via a .. (dot dot) in the DELE command. NOTE: some of these details are obtained from third party information.Show less
1Interspire
1Knowledge Manager
Apr 23, 2026
Dec 3, 2009
N/A· v4
N/A· v3
5.0 MEDIUM· v2
Directory traversal vulnerability in dialog/file_manager.php in Interspire Knowledge Manager 5 allows remote attackers to read arbitrary files via a .. (dot dot) in the p parameter. NOTE: the provenance of this informat...Show more
Directory traversal vulnerability in dialog/file_manager.php in Interspire Knowledge Manager 5 allows remote attackers to read arbitrary files via a .. (dot dot) in the p parameter. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.Show less
1Elxis
1Elxis Cms
Apr 23, 2026
Dec 2, 2009
N/A· v4
N/A· v3
5.0 MEDIUM· v2
Directory traversal vulnerability in includes/feedcreator.class.php in Elxis CMS allows remote attackers to read arbitrary files via a .. (dot dot) in the filename parameter.
1Cutephp
1Cutenews
Apr 23, 2026
Nov 30, 2009
N/A· v4
N/A· v3
3.5 LOW· v2
Multiple directory traversal vulnerabilities in CutePHP CuteNews 1.4.6, when magic_quotes_gpc is disabled, allow remote authenticated users with editor or administrative application access to read arbitrary files via a ....Show more
Multiple directory traversal vulnerabilities in CutePHP CuteNews 1.4.6, when magic_quotes_gpc is disabled, allow remote authenticated users with editor or administrative application access to read arbitrary files via a .. (dot dot) in the source parameter in a (1) list or (2) editnews action to the Editnews module, and (3) the save_con[skin] parameter in the Options module. NOTE: vector 3 can be leveraged for code execution by using a .. to include and execute arbitrary local files.Show less
1Telepark
1Telepark.wiki
Apr 23, 2026
Nov 29, 2009
N/A· v4
N/A· v3
6.8 MEDIUM· v2
Multiple directory traversal vulnerabilities in telepark.wiki 2.4.23 and earlier allow remote attackers to read arbitrary files via directory traversal sequences in the css parameter to (1) getjs.php and (2) getcsslocal....Show more
Multiple directory traversal vulnerabilities in telepark.wiki 2.4.23 and earlier allow remote attackers to read arbitrary files via directory traversal sequences in the css parameter to (1) getjs.php and (2) getcsslocal.php; and include and execute arbitrary local files via the (3) group parameter to upload.php.Show less
2F5
Nginx
2Nginx
Nginx
Apr 23, 2026
Nov 24, 2009
N/A· v4
N/A· v3
4.9 MEDIUM· v2
Directory traversal vulnerability in src/http/modules/ngx_http_dav_module.c in nginx (aka Engine X) before 0.7.63, and 0.8.x before 0.8.17, allows remote authenticated users to create or overwrite arbitrary files via a ....Show more
Directory traversal vulnerability in src/http/modules/ngx_http_dav_module.c in nginx (aka Engine X) before 0.7.63, and 0.8.x before 0.8.17, allows remote authenticated users to create or overwrite arbitrary files via a .. (dot dot) in the Destination HTTP header for the WebDAV (1) COPY or (2) MOVE method.Show less
1Betsy
1Betsy Cms
Apr 23, 2026
Nov 24, 2009
N/A· v4
N/A· v3
7.5 HIGH· v2
Directory traversal vulnerability in admin/popup.php in Betsy CMS 3.5 allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the popup parameter.
1Home Ftp Server Project
1Home Ftp Server
Apr 23, 2026
Nov 23, 2009
N/A· v4
6.5 MEDIUM· v3
4.0 MEDIUM· v2
Multiple directory traversal vulnerabilities in Home FTP Server 1.10.1.139 allow remote authenticated users to (1) create arbitrary directories via directory traversal sequences in an MKD command or (2) create files with...Show more
Multiple directory traversal vulnerabilities in Home FTP Server 1.10.1.139 allow remote authenticated users to (1) create arbitrary directories via directory traversal sequences in an MKD command or (2) create files with any contents in arbitrary directories via directory traversal sequences in a file upload request. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.Show less
1Phpmybackuppro
1Phpmybackuppro
Apr 23, 2026
Nov 23, 2009
N/A· v4
N/A· v3
5.0 MEDIUM· v2
Directory traversal vulnerability in get_file.php in phpMyBackupPro 2.1 allows remote attackers to read arbitrary files via directory traversal sequences in the view parameter. NOTE: the provenance of this information i...Show more
Directory traversal vulnerability in get_file.php in phpMyBackupPro 2.1 allows remote attackers to read arbitrary files via directory traversal sequences in the view parameter. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.Show less
1Sun
2Jre
Openjdk
Apr 23, 2026
Nov 9, 2009
N/A· v4
N/A· v3
5.0 MEDIUM· v2
Directory traversal vulnerability in the ICC_Profile.getInstance method in Java Runtime Environment (JRE) in Sun Java SE 5.0 before Update 22 and 6 before Update 17, and OpenJDK, allows remote attackers to determine the...Show more
Directory traversal vulnerability in the ICC_Profile.getInstance method in Java Runtime Environment (JRE) in Sun Java SE 5.0 before Update 22 and 6 before Update 17, and OpenJDK, allows remote attackers to determine the existence of local International Color Consortium (ICC) profile files via a .. (dot dot) in a pathname, aka Bug Id 6631533.Show less
1Tftgallery
1Tftgallery
Apr 23, 2026
Nov 9, 2009
N/A· v4
N/A· v3
5.0 MEDIUM· v2
Directory traversal vulnerability in index.php in TFTgallery 0.13 allows remote attackers to read arbitrary files via a ..%2F (encoded dot dot slash) in the album parameter.
1Cherokee
1Cherokee Httpd
Apr 23, 2026
Nov 6, 2009
N/A· v4
N/A· v3
5.0 MEDIUM· v2
Directory traversal vulnerability in Cherokee Web Server 0.5.4 and earlier for Windows allows remote attackers to read arbitrary files via a /\.. (slash backslash dot dot) in the URL.
1Vmware
3Esx
EsxiServer
Apr 23, 2026
Nov 2, 2009
N/A· v4
N/A· v3
5.0 MEDIUM· v2
Directory traversal vulnerability in VMware Server 1.x before 1.0.10 build 203137 and 2.x before 2.0.2 build 203138 on Linux, VMware ESXi 3.5, and VMware ESX 3.0.3 and 3.5 allows remote attackers to read arbitrary files...Show more
Directory traversal vulnerability in VMware Server 1.x before 1.0.10 build 203137 and 2.x before 2.0.2 build 203138 on Linux, VMware ESXi 3.5, and VMware ESX 3.0.3 and 3.5 allows remote attackers to read arbitrary files via unspecified vectors.Show less
1Thomas Graber
1Gencms
Apr 23, 2026
Oct 28, 2009
N/A· v4
N/A· v3
7.5 HIGH· v2
Multiple directory traversal vulnerabilities in GenCMS 2006 allow remote attackers to include and execute arbitrary local files via a .. (dot dot) in the (1) p parameter to show.php and the (2) Template parameter to admi...Show more
Multiple directory traversal vulnerabilities in GenCMS 2006 allow remote attackers to include and execute arbitrary local files via a .. (dot dot) in the (1) p parameter to show.php and the (2) Template parameter to admin/pages/SiteNew.php.Show less
1Michael J Greenwood
1Php Content Manager
Apr 23, 2026
Oct 28, 2009
N/A· v4
N/A· v3
7.5 HIGH· v2
Directory traversal vulnerability in include/processor.php in Greenwood PHP Content Manager 0.3.2 allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the content_path parameter.
1Ac4p
1Mobilelib Gold
Apr 23, 2026
Oct 28, 2009
N/A· v4
N/A· v3
4.3 MEDIUM· v2
Directory traversal vulnerability in myhtml.php in Mobilelib GOLD 3.0, when magic_quotes_gpc is enabled, allows remote attackers to read arbitrary files via a .. (dot dot) in the GLOBALS[page] parameter.
1Vivvo
1Vivvo
Apr 23, 2026
Oct 26, 2009
N/A· v4
N/A· v3
5.0 MEDIUM· v2
files.php in Vivvo CMS 4.1.5.1 allows remote attackers to conduct directory traversal attacks and read arbitrary files via the file parameter with "logs/" in between two . (dot) characters, which is filtered into a "../"...Show more
files.php in Vivvo CMS 4.1.5.1 allows remote attackers to conduct directory traversal attacks and read arbitrary files via the file parameter with "logs/" in between two . (dot) characters, which is filtered into a "../" sequence.Show less
1Sahana
1Sahana
Apr 23, 2026
Oct 26, 2009
N/A· v4
N/A· v3
7.5 HIGH· v2
Directory traversal vulnerability in www/index.php in Sahana 0.6.2.2 allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the mod parameter.