CWE-22— Path Traversal
The product uses external input to construct a pathname that is intended to identify a file or directory that is located underneath a restricted parent directory, but the product does not properly neutralize special elements within the pathname that can cause the pathname to resolve to a location that is outside of the restricted directory.— MITRE CWE catalog
9,434 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-22page 43 of 189
- CVE-2017-15276HIGHCVSS 8.8EG 8.82017-10-13
OpenText Documentum Content Server (formerly EMC Documentum Content Server) through 7.3 contains the following design gap, which allows an authenticated user to gain superuser privileges: Content Server allows uploading content using batch…
- CVE-2017-15309HIGHCVSS 7.1EG 7.12017-12-22
Huawei iReader app before 8.0.2.301 has a path traversal vulnerability due to insufficient validation on file storage paths. An attacker can exploit this vulnerability to store downloaded malicious files in an arbitrary directory.
- CVE-2017-15359MEDIUMCVSS 6.5EG 6.52017-10-18
In the 3CX Phone System 15.5.3554.1, the Management Console typically listens to port 5001 and is prone to a directory traversal attack: "/api/RecordingList/DownloadRecord?file=" and "/api/SupportInfo?file=" are the vulnerable parameters. …
- CVE-2017-15363HIGHCVSS 7.5EG 7.52017-10-15
Directory traversal vulnerability in public/examples/resources/getsource.php in Luracast Restler through 3.0.0, as used in the restler extension before 1.7.1 for TYPO3, allows remote attackers to read arbitrary files via the file parameter.
- CVE-2017-1548MEDIUMCVSS 5.3EG 5.32017-12-11
IBM Sterling File Gateway 2.2 could allow a remote attacker to traverse directories on the system. An attacker could send a specially-crafted URL request containing "dot dot" sequences (/../) to view arbitrary files on the system. IBM X-Fo…
- CVE-2017-15527MEDIUMCVSS 6.8EG 6.82017-11-20
Prior to ITMS 8.1 RU4, the Symantec Management Console can be susceptible to a directory traversal exploit, which is a type of attack that can occur when there is insufficient security validation / sanitization of user-supplied input file …
- CVE-2017-15532MEDIUMCVSS 5.7EG 5.72017-12-20
Prior to 10.6.4, Symantec Messaging Gateway may be susceptible to a path traversal attack (also known as directory traversal). These types of attacks aim to access files and directories that are stored outside the web root folder. By manip…
- CVE-2017-15550HIGHCVSS 8.8EG 8.82018-01-05
An issue was discovered in EMC Avamar Server 7.1.x, 7.2.x, 7.3.x, 7.4.x, 7.5.0; EMC NetWorker Virtual Edition (NVE) 9.0.x, 9.1.x, 9.2.x; and EMC Integrated Data Protection Appliance 2.0. A remote authenticated malicious user with low privi…
- CVE-2017-15607CRITICALCVSS 9.8EG 9.82017-12-01
Inedo Otter before 1.7.4 has directory traversal in filesystem-based rafts via vectors involving '/' characters or initial '.' characters, aka OT-181.
- CVE-2017-15647HIGHCVSS 7.5EG 7.52017-10-19
On FiberHome routers, Directory Traversal exists in /cgi-bin/webproc via the getpage parameter in conjunction with a crafted var:page value.
- CVE-2017-15681CRITICALCVSS 9.8EG 9.82020-11-27
In Crafter CMS Crafter Studio 3.0.1 a directory traversal vulnerability exists which allows unauthenticated attackers to overwrite files from the operating system which can lead to RCE.
- CVE-2017-15684HIGHCVSS 7.5EG 7.52020-11-27
Crafter CMS Crafter Studio 3.0.1 has a directory traversal vulnerability which allows unauthenticated attackers to view files from the operating system.
- CVE-2017-15712MEDIUMCVSS 6.5EG 6.52018-02-19
Vulnerability allows a user of Apache Oozie 3.1.3-incubating to 4.3.0 and 5.0.0-beta1 to expose private files on the Oozie server process. The malicious user can construct a workflow XML file containing XML directives and configuration tha…
- CVE-2017-1577HIGHCVSS 7.5EG 7.52017-09-28
IBM WebSphere Portal 7.0, 8.0, 8.5, and 9.0 could allow a remote attacker to traverse directories on the system. An attacker could send a specially-crafted URL request containing "dot dot" sequences (/../) to view arbitrary files on the sy…
- CVE-2017-15805HIGHCVSS 7.5EG 7.52017-10-23
Cisco Small Business SA520 and SA540 devices with firmware 2.1.71 and 2.2.0.7 allow ../ directory traversal in scgi-bin/platform.cgi via the thispage parameter, for reading arbitrary files.
- CVE-2017-15893MEDIUMCVSS 6.5EG 6.52017-12-08
Directory traversal vulnerability in the SYNO.FileStation.Extract in Synology File Station before 1.1.1-0099 allows remote authenticated users to write arbitrary files via the dest_folder_path parameter.
- CVE-2017-15894MEDIUMCVSS 6.5EG 6.52017-12-08
Directory traversal vulnerability in the SYNO.FileStation.Extract in Synology DiskStation Manager (DSM) 6.0.x before 6.0.3-8754-3 and before 5.2-5967-6 allows remote authenticated users to write arbitrary files via the dest_folder_path par…
- CVE-2017-15895MEDIUMCVSS 6.5EG 6.52017-12-08
Directory traversal vulnerability in the SYNO.FileStation.Extract in Synology Router Manager (SRM) before 1.1.5-6542-4 allows remote authenticated users to write arbitrary files via the dest_folder_path parameter.
- CVE-2017-16029HIGHCVSS 7.5EG 7.52018-06-04
hostr is a simple web server that serves up the contents of the current directory. There is a directory traversal vulnerability in hostr 2.3.5 and earlier that allows an attacker to read files outside the current directory by sending `../`…
- CVE-2017-16036HIGHCVSS 7.5EG 7.52018-06-04
`badjs-sourcemap-server` receives files sent by `badjs-sourcemap`. `badjs-sourcemap-server` is vulnerable to a directory traversal issue, giving an attacker access to the filesystem by placing "../" in the url.
- CVE-2017-16037HIGHCVSS 7.5EG 7.52018-06-04
`gomeplus-h5-proxy` is vulnerable to a directory traversal issue, allowing attackers to access any file in the system by placing '../' in the URL.
- CVE-2017-16038HIGHCVSS 7.5EG 7.52018-06-04
`f2e-server` 1.12.11 and earlier is vulnerable to a directory traversal issue, giving an attacker access to the filesystem by placing "../" in the url. This is compounded by `f2e-server` requiring elevated privileges to run.
- CVE-2017-16039HIGHCVSS 7.5EG 7.52018-06-04
`hftp` is a static http or ftp server `hftp` is vulnerable to a directory traversal issue, giving an attacker access to the filesystem by placing "../" in the url.
- CVE-2017-16083HIGHCVSS 7.5EG 7.52018-06-07
node-simple-router is a minimalistic router for Node. node-simple-router is vulnerable to a directory traversal issue, giving an attacker access to the filesystem by placing "../" in the URL.
- CVE-2017-16084HIGHCVSS 7.5EG 7.52018-06-07
list-n-stream is a server for static files to list and stream local videos. list-n-stream v0.0.10 or lower is vulnerable to a directory traversal issue, giving an attacker access to the filesystem by placing "../" in the url.
- CVE-2017-16085HIGHCVSS 7.5EG 7.52018-06-07
tinyserver2 is a webserver for static files. tinyserver2 is vulnerable to a directory traversal issue, giving an attacker access to the filesystem by placing "../" in the URL.
- CVE-2017-16089HIGHCVSS 7.5EG 7.52018-06-07
serverlyr is a simple http server. serverlyr is vulnerable to a directory traversal issue, giving an attacker access to the filesystem by placing "../" in the URL.
- CVE-2017-16090HIGHCVSS 7.5EG 7.52018-06-07
fsk-server is a simple http server. fsk-server is vulnerable to a directory traversal issue, giving an attacker access to the filesystem by placing "../" in the url.
- CVE-2017-16091HIGHCVSS 7.5EG 7.52018-06-07
xtalk helps your browser talk to nodex, a simple web framework. xtalk is vulnerable to a directory traversal issue, giving an attacker access to the filesystem by placing "../" in the URL.
- CVE-2017-16092HIGHCVSS 7.5EG 7.52018-06-07
Sencisho is a simple http server for local development. Sencisho is vulnerable to a directory traversal issue, giving an attacker access to the filesystem by placing "../" in the URL.
- CVE-2017-16093HIGHCVSS 7.5EG 7.52018-06-07
cyber-js is a simple http server. A cyberjs server is vulnerable to a directory traversal issue, giving an attacker access to the filesystem by placing "../" in the url.
- CVE-2017-16094HIGHCVSS 7.5EG 7.52018-06-07
iter-http is a server for static files. iter-http is vulnerable to a directory traversal issue, giving an attacker access to the filesystem by placing "../" in the url.
- CVE-2017-16095HIGHCVSS 7.5EG 7.52018-06-07
serverliujiayi1 is a simple http server. serverliujiayi1 is vulnerable to a directory traversal issue, giving an attacker access to the filesystem by placing "../" in the URL.
- CVE-2017-16096HIGHCVSS 7.5EG 7.52018-06-07
serveryaozeyan is a simple HTTP server. serveryaozeyan is vulnerable to a directory traversal issue, giving an attacker access to the filesystem by placing "../" in the URL.
- CVE-2017-16097HIGHCVSS 7.5EG 7.52018-06-07
tiny-http is a simple http server. tiny-http is vulnerable to a directory traversal issue, giving an attacker access to the filesystem by placing "../" in the url.
- CVE-2017-16101HIGHCVSS 7.5EG 7.52018-06-07
serverwg is a simple http server. serverwg is vulnerable to a directory traversal issue, giving an attacker access to the filesystem by placing "../" in the URL.
- CVE-2017-16102HIGHCVSS 7.5EG 7.52018-06-07
serverhuwenhui is a simple http server. serverhuwenhui is vulnerable to a directory traversal issue, giving an attacker access to the filesystem by placing "../" in the URL.
- CVE-2017-16103HIGHCVSS 7.5EG 7.52018-06-07
serveryztyzt is a simple http server. serveryztyzt is vulnerable to a directory traversal issue, giving an attacker access to the filesystem by placing "../" in the URL.
- CVE-2017-16104HIGHCVSS 7.5EG 7.52018-06-07
citypredict.whauwiller is vulnerable to a directory traversal issue, giving an attacker access to the filesystem by placing "../" in the url.
- CVE-2017-16105HIGHCVSS 7.5EG 7.52018-06-07
serverwzl is a simple http server. serverwzl is vulnerable to a directory traversal issue, giving an attacker access to the filesystem by placing "../" in the URL.
- CVE-2017-16106HIGHCVSS 7.5EG 7.52018-06-07
tmock is a static file server. tmock is vulnerable to a directory traversal issue, giving an attacker access to the filesystem by placing "../" in the url.
- CVE-2017-16107HIGHCVSS 7.5EG 7.52018-06-07
pooledwebsocket is vulnerable to a directory traversal issue, giving an attacker access to the filesystem by placing "../" in the url.
- CVE-2017-16108HIGHCVSS 7.5EG 7.52018-06-07
gaoxiaotingtingting is an HTTP server. gaoxiaotingtingting is vulnerable to a directory traversal issue, giving an attacker access to the filesystem by placing "../" in the url.
- CVE-2017-16109MEDIUMCVSS 5.3EG 5.32018-06-07
easyquick is a simple web server. easyquick is vulnerable to a directory traversal issue, giving an attacker access to the filesystem by placing "../" in the url. Access is constrained, however, to supported file types. Requesting a file s…
- CVE-2017-16110HIGHCVSS 7.5EG 7.52018-06-07
weather.swlyons is a simple web server for weather updates. weather.swlyons is vulnerable to a directory traversal issue, giving an attacker access to the filesystem by placing "../" in the url.
- CVE-2017-16120HIGHCVSS 7.5EG 7.52018-06-07
liyujing is a static file server. liyujing is vulnerable to a directory traversal issue, giving an attacker access to the filesystem by placing "../" in the url.
- CVE-2017-16121HIGHCVSS 7.5EG 7.52018-06-07
datachannel-client is a signaling implementation for DataChannel.js. datachannel-client is vulnerable to a directory traversal issue, giving an attacker access to the filesystem by placing "../" in the url.
- CVE-2017-16122HIGHCVSS 7.5EG 7.52018-06-07
cuciuci is a simple fileserver. cuciuci is vulnerable to a directory traversal issue, giving an attacker access to the filesystem by placing "../" in the url.
- CVE-2017-16123HIGHCVSS 7.5EG 7.52018-06-07
welcomyzt is a simple file server. welcomyzt is vulnerable to a directory traversal issue, giving an attacker access to the filesystem by placing "../" in the url.
- CVE-2017-16124HIGHCVSS 7.5EG 7.52018-06-07
node-server-forfront is a simple static file server. node-server-forfront is vulnerable to a directory traversal issue, giving an attacker access to the filesystem by placing "../" in the url.
Map vulnerabilities like CWE-22 to your infrastructure
EchelonGraph correlates every CVE — across CWE-22 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →