CWE-23

Relative Path Traversal

Parent: CWE-22 - Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')

The product uses external input to construct a pathname that should be within a restricted directory, but it does not properly neutralize sequences such as ".." that can resolve to a location that is outside of that directory.

417 vulnerabilities with CWE-23
CVE-2023-42456 LOW
sudo-rs < 0.2.1 - Path Traversal via Username with Special Characters
CVSS 3.3
CVE-2023-4760 HIGH
Eclipse RAP 3.0.0-3.25.0 - Remote Code Execution via FileUpload Path Traversal
CVSS 7.6
CVE-2023-4914 HIGH
cecil < 7.47.1 - Path Traversal
CVSS 7.5
CVE-2023-4897 CRITICAL
mintplex-labs/anything-llm <0.0.1 - Path Traversal
CVSS 9.8
CVE-2023-38185 HIGH
Microsoft Exchange Server - Remote Code Execution
CVSS 8.8
CVE-2023-35359 HIGH
Windows Kernel - Elevation of Privilege via Relative Path Traversal
CVSS 7.8
CVE-2023-34394 HIGH
Keysight Geolocation Server < 2.4.2 - Unauthenticated Arbitrary File Upload and Deletion via Improper Path Validation
CVSS 7.8
CVE-2023-2913 HIGH
Rockwell Automation ThinManager 13.0.0-13.0.1 - Path Traversal via API Feature
CVSS 7.5
CVE-2023-34117 LOW
Zoom Client SDK <5.15.0 - Info Disclosure
CVSS 3.3
CVE-2023-37288 MEDIUM
SmartBPM.NET - Unauthenticated Path Traversal via File Download Function
CVSS 6.5
CVE-2023-33144 MEDIUM
Visual Studio Code < 1.79 - Spoofing via Relative Path Traversal
CVSS 6.6
CVE-2023-27993 MEDIUM
FortiADC 7.2.0 and before 7.1.1 - Authenticated Path Traversal via CLI Commands
CVSS 6.0
CVE-2023-2356 HIGH
mlflow/mlflow <2.3.1 - Path Traversal
CVSS 7.5
CVE-2023-30630 HIGH
dmidecode < 3.5 - Arbitrary File Write via -dump-bin Option
CVSS 7.1
CVE-2023-29189 MEDIUM
SAP CRM (WebClient UI) - Auth Bypass
CVSS 5.4
CVE-2023-20066 MEDIUM
Cisco IOS XE - Authenticated Path Traversal in Web UI
CVSS 6.5
CVE-2023-23391 MEDIUM
Office for Android - Spoofing via Relative Path Traversal
CVSS 5.5
CVE-2023-1112 MEDIUM
Drag and Drop Multiple File Upload Contact Form 7 < 5.0.6.3 - Path Traversal via upload_name Parameter
CVSS 4.7
CVE-2023-0511 CRITICAL
ForgeRock Java Policy Agent < 5.10.1 - Authentication Bypass via Relative Path Traversal
CVSS 9.1
CVE-2023-0339 CRITICAL
ForgeRock Access Management Web Policy Agent < 5.10.1 - Authentication Bypass via Relative Path Traversal
CVSS 9.1
CVE-2023-1045 LOW
MuYuCMS 2.2 - Path Traversal via /admin.php/accessory/filesdel.html filedelur Parameter
CVSS 3.8
CVE-2023-1044 MEDIUM
MuYuCMS 2.2 - Path Traversal via /editor/index.php file_path Parameter
CVSS 4.3
CVE-2023-1043 MEDIUM
MuYuCMS 2.2 - Path Traversal via dir_path Parameter in Editor
CVSS 4.3
CVE-2023-23784 MEDIUM
FortiWeb 6.3.6-6.3.20 and 7.0.0-7.0.2 - Path Traversal via Crafted Web Requests
CVSS 5.7
CVE-2023-23778 MEDIUM
FortiWeb 6.2.3-6.2.6, 6.3, 6.4, 7.0-7.0.1 - Authenticated Path Traversal via Crafted Web Requests
CVSS 4.9
Details
Vulnerabilities 417