CWE-36
130 CVEs • Abstraction: Base
Absolute Path Traversal
The product uses external input to construct a pathname that should be within a restricted directory, but it does not properly neutralize absolute path sequences such as "/abs/path" that can resolve to a location that is outside of that directory.
CVEs (130)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
A vulnerability was found in ZhongBangKeJi CRMEB 5.2.2. It has been classified as problematic. This affects the function openfile of the file /adminapi/system/file/openfile. The manipulation leads to absolute path traver...Show more |
IBM InfoSphere Information Server 11.7 could allow an authenticated privileged user to obtain the absolute path of the web server installation which could aid in further attacks against the system. IBM X-Force ID: 2757...Show more |
1Honeywell 2Controledge Unit Operations Controller Firmware Controledge Virtual Unit Operations Controller FirmwareJun 17, 2026 Jan 31, 2024 N/A· v4 5.3 MEDIUM· v3 N/A· v2 An attacker could potentially exploit this vulnerability, leading to files being read from the Honeywell Experion ControlEdge VirtualUOC and ControlEdge UOC. This exploit could be used to read files from the controller t...Show more |
1Palantir 2Gotham Blackbird Witchcraft Gotham Static Assets ServletJun 17, 2026 Jan 29, 2024 N/A· v4 6.5 MEDIUM· v3 N/A· v2 Gotham Table service and Forward App were found to be vulnerable to a Path traversal issue allowing an authenticated user to read arbitrary files on the file system.
|
2Debian Redhat4Ansible Automation Platform Ansible DeveloperAnsible Inside+1 moreJun 17, 2026 Dec 18, 2023 N/A· v4 6.3 MEDIUM· v3 N/A· v2 An absolute path traversal attack exists in the Ansible automation platform. This flaw allows an attacker to craft a malicious Ansible role and make the victim execute the role. A symlink can be used to overwrite a file...Show more |
1Microsoft 1Skype For Business Server Jun 17, 2026 Oct 10, 2023 N/A· v4 7.2 HIGH· v3 N/A· v2 Skype for Business Remote Code Execution Vulnerability |
A vulnerability has been found in DedeCMS up to 5.7.100 and classified as critical. Affected by this vulnerability is an unknown functionality of the file /include/dialog/select_templets_post.php. The manipulation of the...Show more |
In Splunk Enterprise versions lower than 8.2.12, 9.0.6, and 9.1.1, an attacker can exploit an absolute path traversal to execute arbitrary code that is located on a separate disk. |
1Cdwanjiang 1Flash Flood Disaster Monitoring And Warning System Jun 17, 2026 Aug 5, 2023 N/A· v4 7.5 HIGH· v3 4.0 MEDIUM· v2 A vulnerability, which was classified as problematic, has been found in Chengdu Flash Flood Disaster Monitoring and Warning System 2.0. This issue affects some unknown processing of the file \Service\FileHandler.ashx. Th...Show more |
Absolute Path Traversal in GitHub repository mlflow/mlflow prior to 2.5.0. |
1Sonicwall 2Analytics Global Management SystemJun 17, 2026 Jul 13, 2023 N/A· v4 6.5 MEDIUM· v3 N/A· v2 Path Traversal vulnerability in SonicWall GMS and Analytics allows a remote authenticated attacker to read arbitrary files from the underlying file system via web service. This issue affects GMS: 9.3.2-SP1 and earlier ve...Show more |
1Microsoft 11Windows 10 1507 Windows 10 1607Windows 10 1809+8 moreJun 17, 2026 Jul 11, 2023 N/A· v4 7.3 HIGH· v3 N/A· v2 Volume Shadow Copy Elevation of Privilege Vulnerability |
A vulnerability has been found in Weaver OA up to 9.5 and classified as problematic. This vulnerability affects unknown code of the file /E-mobile/App/System/File/downfile.php. The manipulation of the argument url leads...Show more |
A vulnerability, which was classified as problematic, has been found in moxi624 Mogu Blog v2 up to 5.2. This issue affects the function uploadPictureByUrl of the file /mogu-picture/file/uploadPicsByUrl. The manipulation...Show more |
Absolute Path Traversal in GitHub repository mlflow/mlflow prior to 2.2.2. |
1Cisco 1Broadworks Commpilot Application Jun 17, 2026 Nov 4, 2022 N/A· v4 8.8 HIGH· v3 N/A· v2 A vulnerability in the web-based management interface of Cisco BroadWorks CommPilot application could allow an unauthenticated, remote attacker to perform a server-side request forgery (SSRF) attack on an affected device...Show more |
1Cisco 2Unified Communications Manager Unified Communications Manager Im And Presence ServiceJun 17, 2026 Jul 6, 2022 N/A· v4 6.5 MEDIUM· v3 4.0 MEDIUM· v2 A vulnerability in the database user privileges of Cisco Unified Communications Manager (Unified CM), Cisco Unified Communications Manager Session Management Edition (Unified CM SME), and Cisco Unified Communications Man...Show more |
1Fluxcd 2Flux2 Kustomize ControllerJun 17, 2026 May 6, 2022 N/A· v4 8.8 HIGH· v3 6.5 MEDIUM· v2 Flux is an open and extensible continuous delivery solution for Kubernetes. Path Traversal in the kustomize-controller via a malicious `kustomization.yaml` allows an attacker to expose sensitive data from the controller’...Show more |
Path Traversal due to `send_file` call in GitHub repository clinical-genomics/scout prior to 4.52. |
1Cisco 16Ip Conference Phone 7832 Firmware Ip Conference Phone 8832 FirmwareIp Phone 7811 Firmware+13 moreJun 17, 2026 Oct 6, 2021 N/A· v4 5.5 MEDIUM· v3 2.1 LOW· v2 A vulnerability in the debug shell of Cisco IP Phone software could allow an authenticated, local attacker to read any file on the device file system. This vulnerability is due to insufficient input validation. An attack...Show more |