CWE-22

High likelihood

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')

Parent: CWE-706 - Use of Incorrectly-Resolved Name or Reference

The product uses external input to construct a pathname that is intended to identify a file or directory that is located underneath a restricted parent directory, but the product does not properly neutralize special elements within the pathname that can cause the pathname to resolve to a location that is outside of the restricted directory.

9,205 vulnerabilities with CWE-22
CVE-2023-44171 CRITICAL
SeaCMS V12.9 - Arbitrary File Write via admin_smtp.php
CVSS 9.8
CVE-2023-44170 CRITICAL
SeaCMS V12.9 - Arbitrary File Write via admin_ping.php
CVSS 9.8
CVE-2023-44169 CRITICAL
SeaCMS V12.9 - Arbitrary File Write via admin_notify.php
CVSS 9.8
CVE-2023-43825 HIGH
Shihonkanri Plus <9.0.3 - Path Traversal
CVSS 7.8
CVE-2023-43216 CRITICAL
SeaCMS V12.9 - Arbitrary File Write via admin_ip.php
CVSS 9.8
CVE-2023-42819 HIGH
JumpServer 3.0.0-3.6.4 - Authenticated Path Traversal and Arbitrary File Write via Playbook File Endpoint
CVSS 8.9
CVE-2023-42657 CRITICAL
WS_FTP Server < 8.7.4 - Path Traversal and Arbitrary File Operations
CVSS 9.9
CVE-2023-42487 HIGH
soundminer < 2.01 - Path Traversal
CVSS 7.5
CVE-2023-42462 HIGH
GLPI 10.0.0-10.0.9 - Path Traversal and Arbitrary File Deletion via Document Upload Process
CVSS 7.7
CVE-2023-41888 MEDIUM
GLPI 10.0.8-10.0.9 - Path Traversal via Login Page URL
CVSS 5.3
CVE-2023-40532 MEDIUM
Welcart e-Commerce <2.8.21 - Info Disclosure
CVSS 4.3
CVE-2023-2315 HIGH
OpenCart 4.0.0.0-4.0.2.2 - Authenticated Path Traversal via Log Component
CVSS 8.1
CVE-2023-43382 HIGH
ItechYou Dreamer CMS <4.1.3 - Code Injection
CVSS 8.8
CVE-2023-43256 MEDIUM
Gladys Assistant <4.26.1 - Path Traversal
CVSS 6.5
CVE-2023-41302 HIGH
Redirection Permission Verification - Info Disclosure
CVSS 7.5
CVE-2023-39407 CRITICAL
HarmonyOS - Unauthenticated Path Traversal in Watchkit
CVSS 9.1
CVE-2023-5142 LOW
H3C GR and ER Series Firmware < 20230908 - Path Traversal via /userLogin.asp Config File Handler
CVSS 3.7
CVE-2023-38346 HIGH
Wind River VxWorks 6.9-7 - Path Traversal
CVSS 8.8
CVE-2023-42280 HIGH
mee-admin 1.5 - Path Traversal via CommonFileController Download Method
CVSS 7.5
CVE-2023-42456 LOW
sudo-rs < 0.2.1 - Path Traversal via Username with Special Characters
CVSS 3.3
CVE-2023-4760 HIGH
Eclipse RAP 3.0.0-3.25.0 - Remote Code Execution via FileUpload Path Traversal
CVSS 7.6
CVE-2023-4152 HIGH
Frauscher FDS101 < 1.4.24 - Unauthenticated Path Traversal via Crafted URL
CVSS 7.5
CVE-2023-40930 MEDIUM
Skyworth OS v3.0 - Path Traversal via Udisk Mount to /mnt/
CVSS 6.8
CVE-2023-43616 MEDIUM
schollz/croc < 9.6.5 - Path Traversal via ZIP Extraction
CVSS 5.5
CVE-2023-41599 MEDIUM
jfinalcms 5.0.0 - Path Traversal via DownController
CVSS 5.3
Details
Vulnerabilities 9,205
Exploit Likelihood High