← Back
CWE-22

9,485 CVEs • Abstraction: Base • Likelihood of Exploit: High

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')

The product uses external input to construct a pathname that is intended to identify a file or directory that is located underneath a restricted parent directory, but the product does not properly neutralize special elements within the pathname that can cause the pathname to resolve to a location that is outside of the restricted directory.

JSON object

Loading...

CVEs (9,485)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Adminnewstools
1Admin News Tools
Apr 23, 2026
Jul 21, 2009
N/A· v4
N/A· v3
5.0 MEDIUM· v2
Directory traversal vulnerability in system/download.php in Admin News Tools 2.5 allows remote attackers to read arbitrary files via a .. (dot dot) in the fichier parameter.
1Supersimple
1Super Simple Blog Script
Apr 23, 2026
Jul 20, 2009
N/A· v4
N/A· v3
6.8 MEDIUM· v2
Multiple directory traversal vulnerabilities in comments.php in Super Simple Blog Script 2.5.4 allow remote attackers to overwrite, include, and execute arbitrary local files via the entry parameter.
1Anelectron
1Advanced Electron Forum
Apr 23, 2026
Jul 20, 2009
N/A· v4
N/A· v3
4.3 MEDIUM· v2
Directory traversal vulnerability in Advanced Electron Forum (AEF) 1.x allows remote attackers to determine the existence of arbitrary files via the avatargalfile parameter when changing an avatar, which leaks the existe...Show more
Directory traversal vulnerability in Advanced Electron Forum (AEF) 1.x allows remote attackers to determine the existence of arbitrary files via the avatargalfile parameter when changing an avatar, which leaks the existence of the file in an error message. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.Show less
1Marcelo Costa
1Fileserver
Apr 23, 2026
Jul 20, 2009
N/A· v4
N/A· v3
6.8 MEDIUM· v2
Directory traversal vulnerability in the Marcelo Costa FileServer component 1.0 for Microsoft Windows Live Messenger and Messenger Plus! Live (MPL) allows remote authenticated users to list arbitrary directories and read...Show more
Directory traversal vulnerability in the Marcelo Costa FileServer component 1.0 for Microsoft Windows Live Messenger and Messenger Plus! Live (MPL) allows remote authenticated users to list arbitrary directories and read arbitrary files via a .. (dot dot) in a pathname.Show less
1Cisco
6Crs
Customer Response ApplicationsIp Qm+3 more
Apr 23, 2026
Jul 16, 2009
N/A· v4
N/A· v3
9.0 HIGH· v2
Directory traversal vulnerability in the Administration interface in Cisco Customer Response Solutions (CRS) before 7.0(1) SR2 in Cisco Unified Contact Center Express (aka CCX) server allows remote authenticated users to...Show more
Directory traversal vulnerability in the Administration interface in Cisco Customer Response Solutions (CRS) before 7.0(1) SR2 in Cisco Unified Contact Center Express (aka CCX) server allows remote authenticated users to read, modify, or delete arbitrary files via unspecified vectors.Show less
1Adbnewssender
1Adbnewssender
Apr 23, 2026
Jul 13, 2009
N/A· v4
N/A· v3
7.5 HIGH· v2
Directory traversal vulnerability in maillinglist/admin/change_config.php in ADbNewsSender before 1.5.6 allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the path_to_lang paramete...Show more
Directory traversal vulnerability in maillinglist/admin/change_config.php in ADbNewsSender before 1.5.6 allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the path_to_lang parameter.Show less
1Adbnewssender
1Adbnewssender
Apr 23, 2026
Jul 13, 2009
N/A· v4
N/A· v3
7.5 HIGH· v2
Directory traversal vulnerability in maillinglist/setup/step1.php.inc in ADbNewsSender before 1.5.6, and 2.0 before RC2, allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the path...Show more
Directory traversal vulnerability in maillinglist/setup/step1.php.inc in ADbNewsSender before 1.5.6, and 2.0 before RC2, allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the path_to_lang parameter to setup/index.php.Show less
1Php Sugar
1Php Sugar
Apr 23, 2026
Jul 9, 2009
N/A· v4
N/A· v3
5.0 MEDIUM· v2
Directory traversal vulnerability in test/index.php in PHP-Sugar 0.80 allows remote attackers to read arbitrary files via a ..// (dot dot slash slash) in the t parameter.
1Audioarticledirectory
1Audio Article Directory
Apr 23, 2026
Jul 9, 2009
N/A· v4
N/A· v3
5.0 MEDIUM· v2
Directory traversal vulnerability in download.php in Audio Article Directory allows remote attackers to read arbitrary files via directory traversal sequences in the file parameter.
1Bigace
1Bigace Cms
Apr 23, 2026
Jul 8, 2009
N/A· v4
N/A· v3
6.8 MEDIUM· v2
Directory traversal vulnerability in public/index.php in BIGACE Web CMS 2.6 allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the cmd parameter.
1Freewebshop
1Freewebshop
Apr 23, 2026
Jul 7, 2009
N/A· v4
N/A· v3
6.8 MEDIUM· v2
Directory traversal vulnerability in includes/startmodules.inc.php in FreeWebshop.org 2.2.9 R2, when register_globals is enabled, allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in...Show more
Directory traversal vulnerability in includes/startmodules.inc.php in FreeWebshop.org 2.2.9 R2, when register_globals is enabled, allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the lang_file parameter.Show less
1Cms.tut.su
1Cms Chainuk
Apr 23, 2026
Jul 5, 2009
N/A· v4
N/A· v3
7.5 HIGH· v2
Multiple directory traversal vulnerabilities in CMS Chainuk 1.2 and earlier allow remote attackers to include and execute arbitrary local files via a .. (dot dot) in (1) the menu parameter to admin/admin_menu.php, and th...Show more
Multiple directory traversal vulnerabilities in CMS Chainuk 1.2 and earlier allow remote attackers to include and execute arbitrary local files via a .. (dot dot) in (1) the menu parameter to admin/admin_menu.php, and the id parameter to (2) index.php and (3) admin/admin_edit.php; and (4) delete arbitrary local files via a .. (dot dot) in the id parameter to admin/admin_delete.php. NOTE: vector 2 can be leveraged for static code injection by sending a crafted menu parameter to admin/admin_menu.php, and then sending an id=../menu.csv request to index.php.Show less
1Clicknet
1Clicknet Cms
Apr 23, 2026
Jul 5, 2009
N/A· v4
N/A· v3
5.0 MEDIUM· v2
Directory traversal vulnerability in index.php in Clicknet CMS 2.1 allows remote attackers to read arbitrary files via a .. (dot dot) in the side parameter.
1Fckeditor
1Fckeditor
Apr 23, 2026
Jul 5, 2009
N/A· v4
N/A· v3
7.5 HIGH· v2
Multiple directory traversal vulnerabilities in FCKeditor before 2.6.4.1 allow remote attackers to create executable files in arbitrary directories via directory traversal sequences in the input to unspecified connector...Show more
Multiple directory traversal vulnerabilities in FCKeditor before 2.6.4.1 allow remote attackers to create executable files in arbitrary directories via directory traversal sequences in the input to unspecified connector modules, as exploited in the wild for remote code execution in July 2009, related to the file browser and the editor/filemanager/connectors/ directory.Show less
1Jinzora
1Jinzora
Apr 23, 2026
Jul 2, 2009
N/A· v4
N/A· v3
7.5 HIGH· v2
Directory traversal vulnerability in index.php in Jinzora Media Jukebox 2.8 and earlier allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the name parameter.
2Cpanel
Netenberg
2Cpanel
Fantastico De Luxe
Apr 23, 2026
Jul 2, 2009
N/A· v4
N/A· v3
5.0 MEDIUM· v2
Directory traversal vulnerability in index.php in Fantastico, as used with cPanel 11.x, allows remote attackers to read arbitrary files via a .. (dot dot) in the sup3r parameter.
1Pluck Cms
1Pluck
Apr 23, 2026
Jul 2, 2009
N/A· v4
N/A· v3
6.8 MEDIUM· v2
Directory traversal vulnerability in data/modules/blog/module_pages_site.php in Pluck 4.6.1 allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the post parameter.
1Cpanel
1Cpanel
Apr 23, 2026
Jul 1, 2009
N/A· v4
N/A· v3
5.0 MEDIUM· v2
Directory traversal vulnerability in frontend/x3/stats/lastvisit.html in cPanel allows remote attackers to read arbitrary files via a .. (dot dot) in the domain parameter.
1Awesomephp
1Mega File Manager
Apr 23, 2026
Jun 30, 2009
N/A· v4
N/A· v3
7.5 HIGH· v2
Directory traversal vulnerability in index.php in Awesome PHP Mega File Manager 1.0 allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the page parameter. NOTE: in some environmen...Show more
Directory traversal vulnerability in index.php in Awesome PHP Mega File Manager 1.0 allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the page parameter. NOTE: in some environments, this can be leveraged for remote file inclusion by using a UNC share pathname or an ftp, ftps, or ssh2.sftp URL.Show less
1Netgear
2Dg632
Dg632 Firmware
Apr 23, 2026
Jun 30, 2009
N/A· v4
N/A· v3
7.8 HIGH· v2
Directory traversal vulnerability in cgi-bin/webcm in the administrative web interface on the Netgear DG632 with firmware 3.4.0_ap allows remote attackers to list arbitrary directories via a .. (dot dot) in the nextpage...Show more
Directory traversal vulnerability in cgi-bin/webcm in the administrative web interface on the Netgear DG632 with firmware 3.4.0_ap allows remote attackers to list arbitrary directories via a .. (dot dot) in the nextpage parameter.Show less