← Back
CWE-29

64 CVEs • Abstraction: Variant

Path Traversal: '\..\filename'

The product uses external input to construct a pathname that should be within a restricted directory, but it does not properly neutralize '\..\filename' (leading backslash dot dot) sequences that can resolve to a location that is outside of that directory.

JSON object

Loading...

CVEs (64)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Salesagility
1Suitecrm
Jun 17, 2026
Feb 25, 2023
N/A· v4
8.8 HIGH· v3
N/A· v2
Path Traversal: '\..\filename' in GitHub repository salesagility/suitecrm prior to 7.12.9.
1Weintek
1Easybuilder Pro
Jun 17, 2026
Feb 22, 2023
N/A· v4
7.8 HIGH· v3
N/A· v2
The listed versions for Weintek EasyBuilder Pro are vulnerable to a ZipSlip attack caused by decompiling a malicious project file. This may allow an attacker to gain control of the user’s computer or gain access to sens...Show more
The listed versions for Weintek EasyBuilder Pro are vulnerable to a ZipSlip attack caused by decompiling a malicious project file. This may allow an attacker to gain control of the user’s computer or gain access to sensitive data.   Show less
1Froxlor
1Froxlor
Jun 17, 2026
Jan 16, 2023
N/A· v4
5.5 MEDIUM· v3
N/A· v2
Path Traversal: '\..\filename' in GitHub repository froxlor/froxlor prior to 2.0.0.
1Emerson
1Electric's Proficy
Jun 17, 2026
Aug 19, 2022
N/A· v4
7.3 HIGH· v3
N/A· v2
Emerson Electric's Proficy Machine Edition Version 9.80 and prior is vulnerable to CWE-29 Path Traversal: '\..\Filename', also known as a ZipSlip attack, through an upload procedure which enables attackers to implant a m...Show more
Emerson Electric's Proficy Machine Edition Version 9.80 and prior is vulnerable to CWE-29 Path Traversal: '\..\Filename', also known as a ZipSlip attack, through an upload procedure which enables attackers to implant a malicious .BLZ file on the PLC. The file can transfer through the engineering station onto Windows in a way that executes the malicious code.Show less