CWE-22— Path Traversal
The product uses external input to construct a pathname that is intended to identify a file or directory that is located underneath a restricted parent directory, but the product does not properly neutralize special elements within the pathname that can cause the pathname to resolve to a location that is outside of the restricted directory.— MITRE CWE catalog
9,434 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-22page 42 of 189
- CVE-2017-10949HIGHCVSS 7.5EG 7.52017-08-04
Directory Traversal in Dell Storage Manager 2016 R2.1 causes Information Disclosure when the doGet method of the EmWebsiteServlet class doesn't properly validate user provided path before using it in file operations. Was ZDI-CAN-4459.
- CVE-2017-10974HIGHCVSS 7.5EG 8.92017-07-07
Yaws 1.91 allows Unauthenticated Remote File Disclosure via HTTP Directory Traversal with /%5C../ to port 8080. NOTE: this CVE is only about use of an initial /%5C sequence to defeat traversal protection mechanisms; the initial /%5C sequen…
- CVE-2017-10993HIGHCVSS 8.8EG 8.82017-07-21
Contao before 3.5.28 and 4.x before 4.4.1 allows remote attackers to include and execute arbitrary local PHP files via a crafted parameter in a URL, aka Directory Traversal.
- CVE-2017-11152HIGHCVSS 7.5EG 7.52017-08-08
Directory traversal vulnerability in PixlrEditorHandler.php in Synology Photo Station before 6.7.3-3432 and 6.3-2967 allows remote attackers to write arbitrary files via the path parameter.
- CVE-2017-11162MEDIUMCVSS 6.5EG 6.52017-09-08
Directory traversal vulnerability in synphotoio in Synology Photo Station before 6.7.4-3433 and 6.3-2968 allows remote authenticated users to read arbitrary files via unspecified vectors.
- CVE-2017-11348MEDIUMCVSS 5.7EG 5.72017-07-17
In Octopus Deploy 3.x before 3.15.4, an authenticated user with PackagePush permission to upload packages could upload a maliciously crafted NuGet package, potentially overwriting other packages or modifying system files. This is a directo…
- CVE-2017-11389CRITICALCVSS 9.8EG 9.82017-08-02
Directory traversal vulnerability in Trend Micro Control Manager 6.0 allows remote code execution by attackers able to drop arbitrary files in a web-facing directory. Formerly ZDI-CAN-4684.
- CVE-2017-11440MEDIUMCVSS 4.9EG 4.92017-07-19
In Sitecore 8.2, there is absolute path traversal via the shell/Applications/Layouts/IDE.aspx fi parameter and the admin/LinqScratchPad.aspx Reference parameter.
- CVE-2017-11456HIGHCVSS 7.5EG 7.52017-07-19
Geneko GWR routers allow directory traversal sequences starting with a /../ substring, as demonstrated by unauthenticated read access to the configuration file.
- CVE-2017-11469HIGHCVSS 7.5EG 7.52017-07-20
get2post.php in IDERA Uptime Monitor 7.8 has directory traversal in the file_name parameter.
- CVE-2017-11500HIGHCVSS 7.5EG 7.52017-07-20
A directory traversal vulnerability exists in MetInfo 5.3.17. A remote attacker can use ..\ to delete any .zip file via the filenames parameter to /admin/system/database/filedown.php.
- CVE-2017-11511HIGHCVSS 7.5EG 7.52017-11-08
The ManageEngine ServiceDesk 9.3.9328 is vulnerable to arbitrary file downloads due to improper restrictions of the pathname used in the filepath parameter for the download-file URL. An unauthenticated remote attacker can use this vulnerab…
- CVE-2017-11512HIGHCVSS 7.5EG 8.92017-11-08
The ManageEngine ServiceDesk 9.3.9328 is vulnerable to arbitrary file downloads due to improper restrictions of the pathname used in the name parameter for the download-snapshot URL. An unauthenticated remote attacker can use this vulnerab…
- CVE-2017-11587HIGHCVSS 7.5EG 7.52017-07-24
On Cisco DDR2200 ADSL2+ Residential Gateway DDR2200B-NA-AnnexA-FCC-V00.00.03.45.4E and DDR2201v1 ADSL2+ Residential Gateway DDR2201v1-NA-AnnexA-FCC-V00.00.03.28.3 devices, there is directory traversal in the filename parameter to the /down…
- CVE-2017-11589CRITICALCVSS 9.8EG 9.82017-07-24
On Cisco DDR2200 ADSL2+ Residential Gateway DDR2200B-NA-AnnexA-FCC-V00.00.03.45.4E and DDR2201v1 ADSL2+ Residential Gateway DDR2201v1-NA-AnnexA-FCC-V00.00.03.28.3 devices, there is no access control for info.html, wancfg.cmd, rtroutecfg.cm…
- CVE-2017-11630HIGHCVSS 7.5EG 7.52017-07-26
dapur\apps\app_config\controller\backuper.php in Fiyo CMS 2.0.7 allows remote attackers to delete arbitrary files via directory traversal sequences in the file parameter in a type=database request, a different vulnerability than CVE-2017-8…
- CVE-2017-11658HIGHCVSS 7.5EG 7.52017-07-26
In the WP Rocket plugin 2.9.3 for WordPress, the Local File Inclusion mitigation technique is to trim traversal characters (..) -- however, this is insufficient to stop remote attacks and can be bypassed by using 0x00 bytes, as demonstrate…
- CVE-2017-11723HIGHCVSS 7.5EG 7.52017-07-29
Directory traversal vulnerability in plugins/ImageManager/backend.php in Xinha 0.96, as used in Jojo 4.4.0, allows remote attackers to delete any folder via directory traversal sequences in the deld parameter.
- CVE-2017-12074MEDIUMCVSS 6.5EG 6.52017-08-24
Directory traversal vulnerability in the SYNO.DNSServer.Zone.MasterZoneConf in Synology DNS Server before 2.2.1-3042 allows remote authenticated attackers to write arbitrary files via the domain_name parameter.
- CVE-2017-12188HIGHCVSS 7.8EG 7.82017-10-11
arch/x86/kvm/mmu.c in the Linux kernel through 4.13.5, when nested virtualisation is used, does not properly traverse guest pagetable entries to resolve a guest virtual address, which allows L1 guest OS users to execute arbitrary code on t…
- CVE-2017-12263HIGHCVSS 7.5EG 7.52017-10-05
A vulnerability in the web interface of Cisco License Manager software could allow an unauthenticated, remote attacker to download and view files within the application that should be restricted, aka Directory Traversal. The issue is due t…
- CVE-2017-12285MEDIUMCVSS 5.3EG 5.82017-10-19
A vulnerability in the web interface of Cisco Network Analysis Module Software could allow an unauthenticated, remote attacker to delete arbitrary files from an affected system, aka Directory Traversal. The vulnerability exists because the…
- CVE-2017-12559MEDIUMCVSS 6.5EG 6.52018-02-15
A Remote Denial of Service vulnerability in HPE Intelligent Management Center (iMC) PLAT version iMC Plat 7.3 E0504P2 was found.
- CVE-2017-12560MEDIUMCVSS 6.5EG 6.52018-02-15
A Remote Denial of Service vulnerability in HPE Intelligent Management Center (iMC) PLAT version iMC Plat 7.3 E0504P2 was found.
- CVE-2017-12586MEDIUMCVSS 6.5EG 6.52017-08-06
SLiMS 8 Akasia through 8.3.1 has an arbitrary file reading issue because of directory traversal in the url parameter to admin/help.php. It can be exploited by remote authenticated librarian users.
- CVE-2017-12637CRITICALCVSS 7.5EG 9.0⚠ KEV2017-08-07
Directory traversal vulnerability in scheduler/ui/js/ffffffffbca41eb4/UIUtilJavaScriptJS in SAP NetWeaver Application Server Java 7.5 allows remote attackers to read arbitrary files via a .. (dot dot) in the query string, as exploited in t…
- CVE-2017-12694HIGHCVSS 7.5EG 7.52017-08-25
A Directory Traversal issue was discovered in SpiderControl SCADA Web Server. An attacker may be able to use a simple GET request to perform a directory traversal into system files.
- CVE-2017-1279MEDIUMCVSS 6.5EG 6.52018-01-26
IBM Tealeaf Customer Experience 8.7, 8.8, and 9.0.2 could allow a remote attacker to traverse directories on the system. An attacker could send a specially-crafted URL request containing "dot dot" sequences (/../) to view arbitrary files o…
- CVE-2017-12791CRITICALCVSS 9.8EG 9.82017-08-23
Directory traversal vulnerability in minion id validation in SaltStack Salt before 2016.11.7 and 2017.7.x before 2017.7.1 allows remote minions with incorrect credentials to authenticate to a master via a crafted minion ID.
- CVE-2017-12815CRITICALCVSS 10.0EG 10.02018-03-26
Analysis of the Bomgar Remote Support Portal JavaStart.jar Applet 52790 and earlier revealed that it is vulnerable to a path traversal vulnerability. The archive can be downloaded from a given Bomgar Remote Support Portal deployment at htt…
- CVE-2017-12938HIGHCVSS 7.5EG 7.52017-08-18
UnRAR before 5.5.7 allows remote attackers to bypass a directory-traversal protection mechanism via vectors involving a symlink to the . directory, a symlink to the .. directory, and a regular file.
- CVE-2017-12943CRITICALCVSS 9.8EG 9.82017-08-18
D-Link DIR-600 Rev Bx devices with v2.x firmware allow remote attackers to read passwords via a model/__show_info.php?REQUIRE_FILE= absolute path traversal attack, as demonstrated by discovering the admin password.
- CVE-2017-13780HIGHCVSS 7.5EG 7.52017-08-30
The EyesOfNetwork web interface (aka eonweb) 5.1-0 allows directory traversal attacks for reading arbitrary files via the module/admin_conf/download.php file parameter.
- CVE-2017-13982HIGHCVSS 8.8EG 8.82017-09-30
A directory traversal vulnerability in HPE BSM Platform Application Performance Management System Health product versions 9.26, 9.30 and 9.40, allows users to upload unrestricted files.
- CVE-2017-13985MEDIUMCVSS 6.5EG 6.52017-09-30
An authentication vulnerability in HPE BSM Platform Application Performance Management System Health product versions 9.26, 9.30 and 9.40, allows remote users to traverse directory leading to disclosure of information.
- CVE-2017-13996HIGHCVSS 8.8EG 8.82017-10-05
A Relative Path Traversal issue was discovered in LOYTEC LVIS-3ME versions prior to 6.2.0. The web user interface fails to prevent access to critical files that non administrative users should not have access to, which could allow an attac…
- CVE-2017-14120HIGHCVSS 7.5EG 7.52017-09-03
unrar 0.0.1 (aka unrar-free or unrar-gpl) suffers from a directory traversal vulnerability for RAR v2 archives: pathnames of the form ../[filename] are unpacked into the upper directory.
- CVE-2017-14196HIGHCVSS 7.5EG 7.52017-11-30
An issue was discovered in Squiz Matrix from 5.3 through to 5.3.6.1 and 5.4.1.3. An information disclosure caused by a Path Traversal issue in the 'File Bridge' plugin allowed the existence of files outside of the bridged path to be confir…
- CVE-2017-14384MEDIUMCVSS 6.5EG 6.52018-03-16
In Dell Storage Manager versions earlier than 16.3.20, the EMConfigMigration service is affected by a directory traversal vulnerability. A remote malicious user could potentially exploit this vulnerability to read unauthorized files by sup…
- CVE-2017-14513MEDIUMCVSS 5.3EG 5.32017-09-17
Directory traversal vulnerability in MetInfo 5.3.17 allows remote attackers to read information from any ini format file via the f_filename parameter in a fingerprintdo action to admin/app/physical/physical.php.
- CVE-2017-14514HIGHCVSS 7.5EG 7.52017-09-17
Directory Traversal on Tenda W15E devices before 15.11.0.14 allows remote attackers to read unencrypted files via a crafted URL.
- CVE-2017-14537MEDIUMCVSS 6.5EG 6.92018-02-16
trixbox 2.8.0.4 has path traversal via the xajaxargs array parameter to /maint/index.php?packages or the lang parameter to /maint/modules/home/index.php.
- CVE-2017-14614MEDIUMCVSS 6.5EG 6.52017-10-10
Directory traversal vulnerability in the Visor GUI Console in GridGain before 1.7.16, 1.8.x before 1.8.12, 1.9.x before 1.9.7, and 8.x before 8.1.5 allows remote authenticated users to read arbitrary files on remote cluster nodes via a cra…
- CVE-2017-14695CRITICALCVSS 9.8EG 9.82017-10-24
Directory traversal vulnerability in minion id validation in SaltStack Salt before 2016.3.8, 2016.11.x before 2016.11.8, and 2017.7.x before 2017.7.2 allows remote minions with incorrect credentials to authenticate to a master via a crafte…
- CVE-2017-14719HIGHCVSS 7.5EG 7.52017-09-23
Before version 4.8.2, WordPress was vulnerable to a directory traversal attack during unzip operations in the ZipArchive and PclZip components.
- CVE-2017-14722HIGHCVSS 7.5EG 7.52017-09-23
Before version 4.8.2, WordPress allowed a Directory Traversal attack in the Customizer component via a crafted theme filename.
- CVE-2017-14754MEDIUMCVSS 6.5EG 6.52017-10-03
OpenText Document Sciences xPression (formerly EMC Document Sciences xPression) v4.5SP1 Patch 13 (older versions might be affected as well) is prone to Arbitrary File Read: /xAdmin/html/cm_datasource_group_xsd.jsp, parameter: xsd_datasourc…
- CVE-2017-14804CRITICALCVSS 9.9EG 9.92018-03-01
The build package before 20171128 did not check directory names during extraction of build results that allowed untrusted builds to write outside of the target system,allowing escape out of buildroots.
- CVE-2017-14849HIGHCVSS 7.5EG 8.22017-09-28
Node.js 8.5.0 before 8.6.0 allows remote attackers to access unintended files, because a change to ".." handling was incompatible with the pathname validation used by unspecified community modules.
- CVE-2017-15079HIGHCVSS 7.5EG 7.52017-10-06
The Smush Image Compression and Optimization plugin before 2.7.6 for WordPress allows directory traversal.
Map vulnerabilities like CWE-22 to your infrastructure
EchelonGraph correlates every CVE — across CWE-22 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →