CWE-22— Path Traversal
The product uses external input to construct a pathname that is intended to identify a file or directory that is located underneath a restricted parent directory, but the product does not properly neutralize special elements within the pathname that can cause the pathname to resolve to a location that is outside of the restricted directory.— MITRE CWE catalog
9,436 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-22page 46 of 189
- CVE-2017-16654HIGHCVSS 7.5EG 7.52018-08-06
An issue was discovered in Symfony before 2.7.38, 2.8.31, 3.2.14, 3.3.13, 3.4-BETA5, and 4.0-BETA5. The Intl component includes various bundle readers that are used to read resource bundles from the local filesystem. The read() methods of …
- CVE-2017-1671HIGHCVSS 7.5EG 7.52018-01-09
IBM Tivoli Key Lifecycle Manager 2.5, 2.6, and 2.7 could allow a remote attacker to traverse directories on the system. An attacker could send a specially-crafted URL request containing "dot dot" sequences (/../) to view arbitrary files on…
- CVE-2017-16720CRITICALCVSS 9.8EG 9.82018-01-05
A Path Traversal issue was discovered in WebAccess versions 8.3.2 and earlier. An attacker has access to files within the directory structure of the target device.
- CVE-2017-16744HIGHCVSS 7.2EG 7.22018-08-20
A path traversal vulnerability in Tridium Niagara AX Versions 3.8 and prior and Niagara 4 systems Versions 4.4 and prior installed on Microsoft Windows Systems can be exploited by leveraging valid platform (administrator) credentials.
- CVE-2017-16759MEDIUMCVSS 5.9EG 5.92017-11-09
The installation process in LibreNMS before 2017-08-18 allows remote attackers to read arbitrary files, related to html/install.php.
- CVE-2017-16762HIGHCVSS 7.5EG 7.52017-11-10
Sanic before 0.5.1 allows reading arbitrary files with directory traversal, as demonstrated by the /static/..%2f substring.
- CVE-2017-16788HIGHCVSS 7.2EG 7.22017-12-15
Directory traversal vulnerability in the "Upload Groupkey" functionality in the Web Configuration Utility in Meinberg LANTIME devices with firmware before 6.24.004 allows remote authenticated users with Admin-User access to write to arbitr…
- CVE-2017-16806CRITICALCVSS 7.5EG 9.02017-11-13
The Process function in RemoteTaskServer/WebServer/HttpServer.cs in Ulterius before 1.9.5.0 allows HTTP server directory traversal.
- CVE-2017-16814MEDIUMCVSS 5.5EG 5.52018-02-26
A Directory Traversal issue was discovered in the Foxit MobilePDF app before 6.1 for iOS. This occurs by abusing the URL + escape character during a Wi-Fi transfer, which could be exploited by attackers to bypass intended restrictions on l…
- CVE-2017-16859MEDIUMCVSS 6.5EG 6.52018-06-28
The review attachment resource in Atlassian Fisheye and Crucible before version 4.3.2, from version 4.4.0 before 4.4.3 and before version 4.5.0 allows remote attackers to read files contained within context path of the running application …
- CVE-2017-16877HIGHCVSS 7.5EG 7.52017-11-17
ZEIT Next.js before 2.4.1 has directory traversal under the /_next and /static request namespace, allowing attackers to obtain sensitive information.
- CVE-2017-16903CRITICALCVSS 9.8EG 9.82017-11-20
LvyeCMS through 3.1 allows remote attackers to upload and execute arbitrary PHP code via directory traversal sequences in the dir parameter, in conjunction with PHP code in the content parameter, within a template Style add request to inde…
- CVE-2017-16922MEDIUMCVSS 5.3EG 5.32018-03-05
In com.wowza.wms.timedtext.http.HTTPProviderCaptionFile in Wowza Streaming Engine before 4.7.1, traversal of the directory structure and retrieval of a file are possible via a remote, specifically crafted HTTP request.
- CVE-2017-16929HIGHCVSS 8.1EG 8.12017-12-05
The remote management interface on the Claymore Dual GPU miner 10.1 is vulnerable to an authenticated directory traversal vulnerability exploited by issuing a specially crafted request, allowing a remote attacker to read/write arbitrary fi…
- CVE-2017-16936MEDIUMCVSS 6.5EG 6.52017-11-24
Directory Traversal vulnerability in app_data_center on Shenzhen Tenda Ac9 US_AC9V1.0BR_V15.03.05.14_multi_TD01, Ac9 ac9_kf_V15.03.05.19(6318_)_cn, Ac15 US_AC15V1.0BR_V15.03.05.18_multi_TD01, Ac15 US_AC15V1.0BR_V15.03.05.19_multi_TD01, Ac1…
- CVE-2017-16959MEDIUMCVSS 6.5EG 6.52017-11-27
The locale feature in cgi-bin/luci on TP-Link TL-WVR, TL-WAR, TL-ER, and TL-R devices allows remote authenticated users to test for the existence of arbitrary files by making an operation=write;locale=%0d request, and then making an operat…
- CVE-2017-17042HIGHCVSS 7.5EG 7.52017-11-28
lib/yard/core_ext/file.rb in the server in YARD before 0.9.11 does not block relative paths with an initial ../ sequence, which allows attackers to conduct directory traversal attacks and read arbitrary files.
- CVE-2017-17058HIGHCVSS 7.5EG 7.52017-11-29
The WooCommerce plugin through 3.x for WordPress has a Directory Traversal Vulnerability via a /wp-content/plugins/woocommerce/templates/emails/plain/ URI, which accesses a parent directory. NOTE: a software maintainer indicates that Direc…
- CVE-2017-17108CRITICALCVSS 9.8EG 9.82018-02-03
Path traversal vulnerability in the administrative panel in KonaKart eCommerce Platform version 8.7 and earlier could allow an attacker to download system files, as well as upload specially crafted JSP files and in turn gain access to the …
- CVE-2017-17223HIGHCVSS 8.8EG 8.82018-03-09
Huawei eSpace 7910 V200R003C30; eSpace 7950 V200R003C30; eSpace 8950 V200R003C00; V200R003C30 have a directory traversal vulnerability. An authenticated, remote attacker can craft specific URL to the affected products. Due to insufficient …
- CVE-2017-1723MEDIUMCVSS 6.5EG 6.52018-04-26
IBM Security QRadar SIEM 7.2 and 7.3 could allow a remote attacker to traverse directories on the system. An attacker could send a specially-crafted URL request containing "dot dot" sequences (/../) to view arbitrary files on the system. I…
- CVE-2017-17309HIGHCVSS 7.5EG 7.52018-06-14
Huawei HG255s-10 V100R001C163B025SP02 has a path traversal vulnerability due to insufficient validation of the received HTTP requests, a remote attacker may access the local files on the device without authentication.
- CVE-2017-1749MEDIUMCVSS 5.3EG 5.32018-08-13
IBM UrbanCode Deploy 6.1 through 6.9.6.0 could allow a remote attacker to traverse directories on the system. An unauthenticated attacker could alter UCD deployments. IBM X-Force ID: 135522.
- CVE-2017-17662HIGHCVSS 7.5EG 7.52018-01-10
Directory traversal in the HTTP server on Yawcam 0.2.6 through 0.6.0 devices allows attackers to read arbitrary files through a sequence of the form '.x./' or '....\x/' where x is a pattern composed of one or more (zero or more for the sec…
- CVE-2017-17671CRITICALCVSS 9.8EG 9.82017-12-14
vBulletin through 5.3.x on Windows allows remote PHP code execution because a require_once call is reachable with an unauthenticated request that can include directory traversal sequences to specify an arbitrary pathname, and because ../ t…
- CVE-2017-17715HIGHCVSS 8.8EG 8.82017-12-16
The saveFile method in MediaController.java in the Telegram Messenger application before 2017-12-08 for Android allows directory traversal via a pathname obtained in a file-transfer request from a remote peer, as demonstrated by writing to…
- CVE-2017-17739CRITICALCVSS 9.8EG 9.82017-12-18
The BrightSign Digital Signage (4k242) device (Firmware 6.2.63 and below) has directory traversal via the /storage.html rp parameter, allowing an attacker to read or write to files.
- CVE-2017-17924MEDIUMCVSS 5.3EG 5.32017-12-27
PHP Scripts Mall Professional Service Script allows remote attackers to obtain sensitive full-path information via the id parameter to admin/review_userwise.php.
- CVE-2017-17927MEDIUMCVSS 5.3EG 5.32017-12-27
PHP Scripts Mall Professional Service Script allows remote attackers to obtain sensitive full-path information via a crafted PATH_INFO to service-list/category/.
- CVE-2017-17992CRITICALCVSS 9.8EG 9.82017-12-30
Biometric Shift Employee Management System allows Arbitrary File Download via directory traversal sequences in the index.php form_file_name parameter in a download_form action.
- CVE-2017-18037MEDIUMCVSS 6.5EG 6.52018-02-02
The git repository tag rest resource in Atlassian Bitbucket Server from version 3.7.0 before 4.14.11 (the fixed version for 4.14.x), from version 5.0.0 before 5.0.9 (the fixed version for 5.0.x), from version 5.1.0 before 5.1.8 (the fixed …
- CVE-2017-18038MEDIUMCVSS 5.3EG 5.32018-02-02
The repository settings resource in Atlassian Bitbucket Server before version 5.6.0 allows remote attackers to read the first line of arbitrary files via a path traversal vulnerability through the default branch name.
- CVE-2017-18196LOWCVSS 3.3EG 3.32018-02-23
Leptonica 1.74.4 constructs unintended pathnames (containing duplicated path components) when operating on files in /tmp subdirectories, which might allow local users to bypass intended file restrictions by leveraging access to a directory…
- CVE-2017-18263HIGHCVSS 7.5EG 7.52018-04-28
Seagate Media Server in Seagate Personal Cloud before 4.3.18.4 has directory traversal in getPhotoPlaylistPhotos.psp via a parameter named url.
- CVE-2017-18354HIGHCVSS 7.5EG 7.52018-12-17
Rendertron 1.0.0 allows for alternative protocols such as 'file://' introducing a Local File Inclusion (LFI) bug where arbitrary files can be read by a remote attacker.
- CVE-2017-18448MEDIUMCVSS 5.3EG 5.32019-08-02
cPanel before 64.0.21 allows certain file-read operations via a Serverinfo_manpage API call (SEC-252).
- CVE-2017-18585HIGHCVSS 8.1EG 8.12019-08-22
The posts-in-page plugin before 1.3.0 for WordPress has ic_add_posts template='../ directory traversal.
- CVE-2017-18586CRITICALCVSS 9.1EG 9.12019-08-22
The insert-pages plugin before 3.2.4 for WordPress has directory traversal via custom template paths.
- CVE-2017-18636HIGHCVSS 7.5EG 7.52019-09-30
CDG through 2017-01-01 allows downloadDocument.jsp?command=download&pathAndName= directory traversal.
- CVE-2017-18824LOWCVSS 3.3EG 3.32020-04-20
Certain NETGEAR devices are affected by directory traversal. This affects M4300-28G before 12.0.2.15, M4300-52G before 12.0.2.15, M4300-28G-POE+ before 12.0.2.15, M4300-52G-POE+ before 12.0.2.15, M4300-8X8F before 12.0.2.15, M4300-12X12F b…
- CVE-2017-18874MEDIUMCVSS 6.5EG 6.52020-06-19
An issue was discovered in Mattermost Server before 4.3.0, 4.2.1, and 4.1.2 when local storage for files is used. A System Admin can achieve directory traversal.
- CVE-2017-18912CRITICALCVSS 9.8EG 9.82020-06-19
An issue was discovered in Mattermost Server before 3.8.2, 3.7.5, and 3.6.7. It allows an attacker to specify a full pathname of a log file.
- CVE-2017-20102MEDIUMCVSS 4.4EG 5.52022-06-27
A vulnerability was found in Album Lock 4.0 and classified as critical. Affected by this issue is some unknown functionality of the file /getImage. The manipulation of the argument filePaht leads to path traversal. Attacking locally is a r…
- CVE-2017-20105HIGHCVSS 5.4EG 8.12022-06-28
A vulnerability was found in Simplessus 3.7.7. It has been rated as critical. This issue affects some unknown processing. The manipulation of the argument path with the input ..%2f..%2f..%2f..%2f..%2f..%2f..%2f..%2f..%2f..%2f..%2f..%2f..%2…
- CVE-2017-20145CRITICALCVSS 6.3EG 9.82022-07-25
A vulnerability was found in Tecrail Responsive Filemanger up to 9.10.x and classified as critical. The manipulation leads to path traversal. The attack may be launched remotely. The exploit has been disclosed to the public and may be used…
- CVE-2017-20152HIGHCVSS 3.1EG 7.52022-12-30
A vulnerability, which was classified as problematic, was found in aerouk imageserve. Affected is an unknown function of the file public/viewer.php of the component File Handler. The manipulation of the argument filelocation leads to path …
- CVE-2017-20181MEDIUMCVSS 5.3EG 5.52023-03-07
A vulnerability classified as critical was found in hgzojer Vocable Trainer up to 1.3.0 on Android. This vulnerability affects unknown code of the file src/at/hgz/vocabletrainer/VocableTrainerProvider.java. The manipulation leads to path t…
- CVE-2017-20184HIGHCVSS 7.5EG 7.52023-05-04
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Carlo Gavazzi Powersoft up to version 2.1.1.1 allows an unauthenticated, remote attacker to download any file from the affected device.
- CVE-2017-20212MEDIUMCVSS 6.2EG 6.22026-01-08
FLIR Thermal Camera F/FC/PT/D firmware version 8.0.0.64 contains an information disclosure vulnerability that allows unauthenticated attackers to read arbitrary files through unverified input parameters. Attackers can exploit the /var/www/…
- CVE-2017-20248HIGHCVSS 7.5EG 7.52026-06-09
Apptha Slider Gallery 1.0 contains a path traversal vulnerability that allows unauthenticated attackers to download arbitrary files by manipulating the imgname parameter. Attackers can send requests to asgallDownload.php with directory tra…
Map vulnerabilities like CWE-22 to your infrastructure
EchelonGraph correlates every CVE — across CWE-22 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →