← Back
CWE-22

9,483 CVEs • Abstraction: Base • Likelihood of Exploit: High

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')

The product uses external input to construct a pathname that is intended to identify a file or directory that is located underneath a restricted parent directory, but the product does not properly neutralize special elements within the pathname that can cause the pathname to resolve to a location that is outside of the restricted directory.

JSON object

Loading...

CVEs (9,483)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Whorl Ltd
1Jshop Server
Apr 23, 2026
Apr 2, 2008
N/A· v4
N/A· v3
7.5 HIGH· v2
Directory traversal vulnerability in v2demo/page.php in Jshop Server 1.x through 2.x allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the xPage parameter.
12x
1Thinclientserver
Apr 23, 2026
Apr 2, 2008
N/A· v4
N/A· v3
7.5 HIGH· v2
Directory traversal vulnerability in 2X TFTP service (TFTPd.exe) 3.2.0.0 and earlier in 2X ThinClientServer 5.0_sp1-r3497 and earlier allows remote attackers to read or overwrite arbitrary files via a ... (dot dot dot) i...Show more
Directory traversal vulnerability in 2X TFTP service (TFTPd.exe) 3.2.0.0 and earlier in 2X ThinClientServer 5.0_sp1-r3497 and earlier allows remote attackers to read or overwrite arbitrary files via a ... (dot dot dot) in the filename.Show less
1Elastic Path
1Elastic Path
Apr 23, 2026
Apr 1, 2008
N/A· v4
N/A· v3
6.0 MEDIUM· v2
Multiple directory traversal vulnerabilities in Elastic Path (EP) 4.1 and 4.1.1 allow remote attackers to (1) download arbitrary files via a .. (dot dot) in the file parameter to manager/getImportFileRedirect.jsp, (2) up...Show more
Multiple directory traversal vulnerabilities in Elastic Path (EP) 4.1 and 4.1.1 allow remote attackers to (1) download arbitrary files via a .. (dot dot) in the file parameter to manager/getImportFileRedirect.jsp, (2) upload arbitrary files via a "..\" (dot dot backslash) in the file parameter to importData.jsp, and (3) list directory contents via a .. (dot dot) in the dir parameter to manager/fileManager.jsp.Show less
2Hotscripts
Phpbb
2Pjirc
Pjirc Module
Apr 23, 2026
Mar 31, 2008
N/A· v4
N/A· v3
7.5 HIGH· v2
Directory traversal vulnerability in forum/irc/irc.php in the PJIRC 0.5 module for phpBB allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the phpEx parameter.
1File Transfer
1File Transfer
Apr 23, 2026
Mar 31, 2008
N/A· v4
N/A· v3
4.3 MEDIUM· v2
Directory traversal vulnerability in Dan Costin File Transfer before 1.2f allows remote attackers to read arbitrary files via a "..\" (dot dot backslash) in the filename.
1Bolinos
1Bolinos
Apr 23, 2026
Mar 31, 2008
N/A· v4
N/A· v3
6.8 MEDIUM· v2
Directory traversal vulnerability in system/_b/contentFiles/gbincluder.php in BolinOS 4.6.1 allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the _bFileToInclude parameter.
1Topper
1Toppermod
Apr 23, 2026
Mar 31, 2008
N/A· v4
N/A· v3
6.8 MEDIUM· v2
Directory traversal vulnerability in mod.php in TopperMod 1.0 allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the to parameter.
1His
1Webshop
Apr 23, 2026
Mar 28, 2008
N/A· v4
N/A· v3
4.3 MEDIUM· v2
Directory traversal vulnerability in cgi-bin/his-webshop.pl in HIS Webshop 2.50 allows remote attackers to read arbitrary files via a .. (dot dot) in the t parameter.
1Powerscripts
1Powerbook
Apr 23, 2026
Mar 28, 2008
N/A· v4
N/A· v3
6.8 MEDIUM· v2
Directory traversal vulnerability in pb_inc/admincenter/index.php in PowerScripts PowerBook 1.21 allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the page parameter. NOTE: in s...Show more
Directory traversal vulnerability in pb_inc/admincenter/index.php in PowerScripts PowerBook 1.21 allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the page parameter. NOTE: in some environments, this can be leveraged for remote file inclusion by using a UNC share pathname or an ftp, ftps, or ssh2.sftp URL.Show less
1Powerscripts
1Powerphpboard
Apr 23, 2026
Mar 28, 2008
N/A· v4
N/A· v3
7.5 HIGH· v2
Multiple directory traversal vulnerabilities in PowerPHPBoard 1.00b allow remote attackers to include and execute arbitrary local files via a .. (dot dot) in the (1) settings[footer] parameter to footer.inc.php and the (...Show more
Multiple directory traversal vulnerabilities in PowerPHPBoard 1.00b allow remote attackers to include and execute arbitrary local files via a .. (dot dot) in the (1) settings[footer] parameter to footer.inc.php and the (2) settings[header] parameter to header.inc.php.Show less
1Phpbb
1Module Xs
Apr 23, 2026
Mar 25, 2008
N/A· v4
N/A· v3
7.5 HIGH· v2
Directory traversal vulnerability in admin/admin_xs.php in eXtreme Styles module (XS-Mod) 2.3.1 and 2.4.0 for phpBB allows remote attackers to include and execute arbitrary files via a .. (dot dot) in the phpEx parameter...Show more
Directory traversal vulnerability in admin/admin_xs.php in eXtreme Styles module (XS-Mod) 2.3.1 and 2.4.0 for phpBB allows remote attackers to include and execute arbitrary files via a .. (dot dot) in the phpEx parameter. NOTE: some of these details are obtained from third party information.Show less
1Cuteflow Bin
1Cuteflow Bin
Apr 23, 2026
Mar 25, 2008
N/A· v4
N/A· v3
7.5 HIGH· v2
Directory traversal vulnerability in login.php in Cuteflow Bin 1.5.0 allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the language parameter.
1Riceball
1Multiple Time Sheets
Apr 23, 2026
Mar 20, 2008
N/A· v4
N/A· v3
5.0 MEDIUM· v2
Directory traversal vulnerability in index.php in Multiple Time Sheets (MTS) 5.0 and earlier allows remote attackers to read arbitrary files via "../..//" (modified dot dot) sequences in the tab parameter.
1Acronis
1Snap Deploy
Apr 23, 2026
Mar 20, 2008
N/A· v4
N/A· v3
4.3 MEDIUM· v2
Directory traversal vulnerability in the PXE Server (pxesrv.exe) in Acronis Snap Deploy 2.0.0.1076 and earlier allows remote attackers to read arbitrary files via directory traversal sequences to the TFTP service.
1Exero
1Exero Cms
Apr 23, 2026
Mar 20, 2008
N/A· v4
N/A· v3
7.5 HIGH· v2
Multiple directory traversal vulnerabilities in the Default theme in Exero CMS 1.0.1 allow remote attackers to include and execute arbitrary local files via directory traversal sequences in the theme parameter to (1) ind...Show more
Multiple directory traversal vulnerabilities in the Default theme in Exero CMS 1.0.1 allow remote attackers to include and execute arbitrary local files via directory traversal sequences in the theme parameter to (1) index.php, (2) editpassword.php, and (3) avatar.php in usercp/; (4) custompage.php; (5) errors/404.php; (6) memberslist.php and (7) profile.php in members/; (8) index.php and (9) fullview.php in news/; and (10) nopermission.php.Show less
1Mg Soft
1Net Inspector
Apr 23, 2026
Mar 20, 2008
N/A· v4
N/A· v3
5.0 MEDIUM· v2
Directory traversal vulnerability in the Net Inspector HTTP Server (mghttpd) in MG-SOFT Net Inspector 6.5.0.828 and earlier for Windows allows remote attackers to read arbitrary files via a "..\" (dot dot backslash) or "...Show more
Directory traversal vulnerability in the Net Inspector HTTP Server (mghttpd) in MG-SOFT Net Inspector 6.5.0.828 and earlier for Windows allows remote attackers to read arbitrary files via a "..\" (dot dot backslash) or "../" (dot dot slash) in the URI.Show less
1Apple
2Mac Os X
Mac Os X Server
Apr 23, 2026
Mar 18, 2008
N/A· v4
N/A· v3
8.5 HIGH· v2
Directory traversal vulnerability in ContentServer.py in the Wiki Server in Apple Mac OS X 10.5.2 (aka Leopard) allows remote authenticated users to write arbitrary files via ".." sequences in file attachments.
1Drake Team
1Drake Cms
Apr 23, 2026
Mar 18, 2008
N/A· v4
N/A· v3
3.6 LOW· v2
Absolute path traversal vulnerability in install/index.php in Drake CMS 0.4.11 RC8 allows remote attackers to read and execute arbitrary files via a full pathname in the d_root parameter. NOTE: the provenance of this in...Show more
Absolute path traversal vulnerability in install/index.php in Drake CMS 0.4.11 RC8 allows remote attackers to read and execute arbitrary files via a full pathname in the d_root parameter. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.Show less
1Hangzhou Network Technology Development
1Ediorcms
Apr 23, 2026
Mar 17, 2008
N/A· v4
N/A· v3
5.0 MEDIUM· v2
Directory traversal vulnerability in search.php in EdiorCMS (ecms) 3.0 allows remote attackers to read arbitrary files via a .. (dot dot) in the _SearchTemplate parameter during a Title search.
1Sco
1Unixware
Apr 23, 2026
Mar 17, 2008
N/A· v4
N/A· v3
4.9 MEDIUM· v2
Directory traversal vulnerability in (1) pkgadd and (2) pkgrm in SCO UnixWare 7.1.4 allows local users to gain privileges via unknown vectors.