CWE-22— Path Traversal
The product uses external input to construct a pathname that is intended to identify a file or directory that is located underneath a restricted parent directory, but the product does not properly neutralize special elements within the pathname that can cause the pathname to resolve to a location that is outside of the restricted directory.— MITRE CWE catalog
9,431 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-22page 41 of 189
- CVE-2016-7842MEDIUMCVSS 5.5EG 5.52017-04-28
Directory traversal vulnerability in AttacheCase 2.8.2.8 and earlier and 3.2.0.4 and earlier allows remote attackers to read arbitrary files via specially crafted ATC file.
- CVE-2016-7843MEDIUMCVSS 5.5EG 5.52017-04-28
Directory traversal vulnerability in AttacheCase for Java 0.60 and earlier, AttacheCase Lite 1.4.6 and earlier, and AttacheCase Pro 1.5.7 and earlier allows remote attackers to read arbitrary files via specially crafted ATC file.
- CVE-2016-7982HIGHCVSS 7.5EG 7.52017-01-18
Directory traversal vulnerability in ecrire/exec/valider_xml.php in SPIP 3.1.2 and earlier allows remote attackers to enumerate the files on the system via the var_url parameter in a valider_xml action.
- CVE-2016-8204CRITICALCVSS 9.8EG 9.82017-01-14
A Directory Traversal vulnerability in FileReceiveServlet in the Brocade Network Advisor versions released prior to and including 14.0.2 could allow remote attackers to upload a malicious file in a section of the file system where it can b…
- CVE-2016-8205CRITICALCVSS 9.8EG 9.82017-01-14
A Directory Traversal vulnerability in DashboardFileReceiveServlet in the Brocade Network Advisor versions released prior to and including 14.0.2 could allow remote attackers to upload a malicious file in a section of the file system where…
- CVE-2016-8206HIGHCVSS 7.5EG 7.52017-01-14
A Directory Traversal vulnerability in servlet SoftwareImageUpload in the Brocade Network Advisor versions released prior to and including 14.0.2 could allow remote attackers to write to arbitrary files, and consequently delete the files.
- CVE-2016-8207HIGHCVSS 7.5EG 7.52017-01-14
A Directory Traversal vulnerability in CliMonitorReportServlet in the Brocade Network Advisor versions released prior to and including 14.0.2 could allow remote attackers to read arbitrary files including files with sensitive user informat…
- CVE-2016-8211HIGHCVSS 7.5EG 7.52017-02-03
EMC Data Protection Advisor 6.1.x, EMC Data Protection Advisor 6.2, EMC Data Protection Advisor 6.2.1, EMC Data Protection Advisor 6.2.2, EMC Data Protection Advisor 6.2.3 prior to patch 446 has a path traversal vulnerability that may pote…
- CVE-2016-8280MEDIUMCVSS 6.5EG 6.52016-10-03
Directory traversal vulnerability in Huawei eSight before V300R003C20SPC005 allows remote authenticated users to read arbitrary files via unspecified vectors.
- CVE-2016-8343HIGHCVSS 7.5EG 7.52016-10-05
Directory traversal vulnerability in INDAS Web SCADA before 3 allows remote attackers to read arbitrary files via unspecified vectors.
- CVE-2016-8593HIGHCVSS 8.8EG 8.82017-04-28
Directory traversal vulnerability in upload.cgi in Trend Micro Threat Discovery Appliance 2.6.1062r1 and earlier allows remote authenticated users to execute arbitrary code via a .. (dot dot) in the dID parameter.
- CVE-2016-8827MEDIUMCVSS 6.5EG 6.52016-12-16
NVIDIA GeForce Experience 3.x before GFE 3.1.0.52 contains a vulnerability in NVIDIA Web Helper.exe where a local web API endpoint, /VisualOPS/v.1.0./, lacks proper access control and parameter validation, allowing for information disclosu…
- CVE-2016-8913MEDIUMCVSS 6.5EG 6.52017-02-01
IBM Kenexa LMS on Cloud 13.1 and 13.2 - 13.2.4 could allow a remote attacker to traverse directories on the system. An attacker could send a specially-crafted URL request containing "dot dot" sequences (/../) to view arbitrary files on the…
- CVE-2016-8933MEDIUMCVSS 6.5EG 6.52017-02-01
IBM Kenexa LMS on Cloud could allow a remote attacker to traverse directories on the system. An attacker could send a specially-crafted URL request containing dot dot sequences (/../) to view arbitrary files on the system.
- CVE-2016-9164HIGHCVSS 7.5EG 7.52017-03-07
Directory traversal vulnerability in diag.jsp file in CA Unified Infrastructure Management (formerly CA Nimsoft Monitor) 8.4 SP1 and earlier and CA Unified Infrastructure Management Snap (formerly CA Nimsoft Monitor Snap) allows remote att…
- CVE-2016-9177HIGHCVSS 7.5EG 7.52016-11-04
Directory traversal vulnerability in Spark 2.5 allows remote attackers to read arbitrary files via a .. (dot dot) in the URI.
- CVE-2016-9199MEDIUMCVSS 6.5EG 6.52016-12-14
A vulnerability in the Cisco application-hosting framework (CAF) of Cisco IOx could allow an authenticated, remote attacker to read arbitrary files on a targeted system. Affected Products: This vulnerability affects specific releases of th…
- CVE-2016-9208MEDIUMCVSS 6.5EG 6.52016-12-14
A vulnerability in the File Management Utility, the Download File form, and the Serviceability application of Cisco Emergency Responder could allow an authenticated, remote attacker to access files in arbitrary locations on the file system…
- CVE-2016-9210HIGHCVSS 7.5EG 7.52016-12-14
A vulnerability in the Cisco Unified Reporting upload tool accessed via the Cisco Unified Communications Manager could allow an unauthenticated, remote attacker to modify arbitrary files on the file system. More Information: CSCvb61698. Kn…
- CVE-2016-9339MEDIUMCVSS 5.3EG 5.32017-02-13
An issue was discovered in INTERSCHALT Maritime Systems VDR G4e Versions 5.220 and prior. External input is used to construct paths to files and directories without properly neutralizing special elements within the pathname that could allo…
- CVE-2016-9351HIGHCVSS 7.0EG 7.02017-02-13
An issue was discovered in Advantech SUISAccess Server Version 3.0 and prior. The directory traversal/file upload error allows an attacker to upload and unpack a zip file.
- CVE-2016-9357MEDIUMCVSS 5.3EG 5.32017-02-13
An issue was discovered in certain legacy Eaton ePDUs -- the affected products are past end-of-life (EoL) and no longer supported: EAMxxx prior to June 30, 2015, EMAxxx prior to January 31, 2014, EAMAxx prior to January 31, 2014, EMAAxx pr…
- CVE-2016-9364HIGHCVSS 7.5EG 7.52017-02-13
An issue was discovered in Fidelix FX-20 series controllers, versions prior to 11.50.19. Arbitrary file reading via path traversal allows an attacker to access arbitrary files and directories on the server.
- CVE-2016-9484HIGHCVSS 7.5EG 7.52018-07-13
The generated PHP form code does not properly validate user input folder directories, allowing a remote unauthenticated attacker to perform a path traversal and access arbitrary files on the server. The PHP FormMail Generator website does …
- CVE-2016-9878HIGHCVSS 7.5EG 7.52016-12-29
An issue was discovered in Pivotal Spring Framework before 3.2.18, 4.2.x before 4.2.9, and 4.3.x before 4.3.5. Paths provided to the ResourceServlet were not properly sanitized and as a result exposed to directory traversal attacks.
- CVE-2016-9950HIGHCVSS 7.8EG 7.82016-12-17
An issue was discovered in Apport before 2.20.4. There is a path traversal issue in the Apport crash file "Package" and "SourcePackage" fields. These fields are used to build a path to the package specific hook files in the /usr/share/appo…
- CVE-2017-0901HIGHCVSS 7.5EG 7.52017-08-31
RubyGems version 2.6.12 and earlier fails to validate specification names, allowing a maliciously crafted gem to potentially overwrite any file on the filesystem.
- CVE-2017-0918HIGHCVSS 8.8EG 8.82018-03-21
Gitlab Community Edition version 10.3 is vulnerable to a path traversal issue in the GitLab CI runner component resulting in remote code execution.
- CVE-2017-0930MEDIUMCVSS 6.5EG 6.52018-06-04
augustine node module suffers from a Path Traversal vulnerability due to lack of validation of url, which allows a malicious user to read content of any file with known path.
- CVE-2017-1000002CRITICALCVSS 9.8EG 9.82017-07-17
ATutor versions 2.2.1 and earlier are vulnerable to a directory traversal and file extension check bypass in the Course component resulting in code execution. ATutor versions 2.2.1 and earlier are vulnerable to a directory traversal vulner…
- CVE-2017-1000026HIGHCVSS 7.5EG 7.52017-07-17
Chef Software's mixlib-archive versions 0.3.0 and older are vulnerable to a directory traversal attack allowing attackers to overwrite arbitrary files by using ".." in tar archive entries
- CVE-2017-1000028CRITICALCVSS 7.5EG 9.02017-07-17
Oracle, GlassFish Server Open Source Edition 4.1 is vulnerable to both authenticated and unauthenticated Directory Traversal vulnerability, that can be exploited by issuing a specially crafted HTTP GET request.
- CVE-2017-1000047CRITICALCVSS 9.8EG 9.82017-07-17
rbenv (all current versions) is vulnerable to Directory Traversal in the specification of Ruby version resulting in arbitrary code execution
- CVE-2017-1000062HIGHCVSS 7.5EG 7.52017-07-17
kittoframework kitto 0.5.1 is vulnerable to directory traversal in the router resulting in remote code execution
- CVE-2017-1000170HIGHCVSS 7.5EG 8.32017-11-17
jqueryFileTree 2.1.5 and older Directory Traversal
- CVE-2017-1000448HIGHCVSS 7.5EG 7.52018-01-02
Structured Data Linter versions 2.4.1 and older are vulnerable to a directory traversal attack in the URL input field resulting in the possibility of disclosing information about the remote host.
- CVE-2017-1000472MEDIUMCVSS 6.5EG 6.52018-01-03
The ZipCommon::isValidPath() function in Zip/src/ZipCommon.cpp in POCO C++ Libraries before 1.8 does not properly restrict the filename value in the ZIP header, which allows attackers to conduct absolute path traversal attacks during the Z…
- CVE-2017-1000490MEDIUMCVSS 6.5EG 6.52018-01-03
Mautic versions 1.0.0 - 2.11.0 are vulnerable to allowing any authorized Mautic user session (must be logged into Mautic) to use the Filemanager to download any file from the server that the web user has access to.
- CVE-2017-1000501CRITICALCVSS 9.8EG 9.82018-01-03
Awstats version 7.6 and earlier is vulnerable to a path traversal flaw in the handling of the "config" and "migrate" parameters resulting in unauthenticated remote code execution.
- CVE-2017-10273MEDIUMCVSS 4.7EG 4.72018-01-18
Vulnerability in the Oracle JDeveloper component of Oracle Fusion Middleware (subcomponent: Deployment). Supported versions that are affected are 11.1.1.7.0, 11.1.1.7.1, 11.1.1.9.0, 11.1.2.4.0, 12.1.3.0.0 and 12.2.1.2.0. Difficult to explo…
- CVE-2017-10665HIGHCVSS 7.8EG 7.82017-08-18
Directory traversal vulnerability in ajaxfileupload.php in Kayson Group Ltd. phpGrid before 7.2.5 allows remote attackers to execute arbitrary code by uploading a crafted file with a .. (dot dot) in the file name.
- CVE-2017-10708HIGHCVSS 7.8EG 7.82017-07-18
An issue was discovered in Apport through 2.20.x. In apport/report.py, Apport sets the ExecutablePath field and it then uses the path to run package specific hooks without protecting against path traversal. This allows remote attackers to …
- CVE-2017-10834MEDIUMCVSS 6.5EG 6.52017-08-29
Directory traversal vulnerability in "Dokodemo eye Smart HD" SCR02HD Firmware 1.0.3.1000 and earlier allows authenticated attackers to read arbitrary files via unspecified vectors.
- CVE-2017-10841MEDIUMCVSS 4.9EG 4.92017-08-29
Directory traversal vulnerability in WebCalendar 1.2.7 and earlier allows authenticated attackers to read arbitrary files via unspecified vectors.
- CVE-2017-10861CRITICALCVSS 9.1EG 9.12017-12-01
Directory traversal vulnerability in QND Advance/Standard allows an attacker to read arbitrary files via a specially crafted command.
- CVE-2017-1087HIGHCVSS 7.8EG 7.82017-11-16
In FreeBSD 10.x before 10.4-STABLE, 10.4-RELEASE-p3, and 10.3-RELEASE-p24 named paths are globally scoped, meaning a process located in one jail can read and modify the content of POSIX shared memory objects created by a process in another…
- CVE-2017-10907MEDIUMCVSS 4.3EG 4.32017-12-22
Directory traversal vulnerability in OneThird CMS Show Off v1.85 and earlier. Show Off v1.85 en and earlier allows an attacker to read arbitrary files via unspecified vectors.
- CVE-2017-10931HIGHCVSS 7.5EG 7.52017-09-19
The ZXR10 1800-2S before v3.00.40 incorrectly restricts the download of the file directory range for WEB users, resulting in the ability to download any files and cause information leaks such as system configuration.
- CVE-2017-10933HIGHCVSS 7.5EG 7.52017-10-19
All versions prior to V2.06.00.00 of ZTE ZXDT22 SF01, an monitoring system of ZTE energy product, are impacted by directory traversal vulnerability that allows remote attackers to read arbitrary files on the system via a full path name aft…
- CVE-2017-10940HIGHCVSS 8.8EG 8.82017-10-31
This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Joyent Smart Data Center prior to agentsshar@1.0.0-release-20160901-20160901T051624Z-g3fd5adf (e469cf49-4de3-4658-8419-ab42837916ad). An at…
Map vulnerabilities like CWE-22 to your infrastructure
EchelonGraph correlates every CVE — across CWE-22 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →