CWE-23

Relative Path Traversal

Parent: CWE-22 - Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')

The product uses external input to construct a pathname that should be within a restricted directory, but it does not properly neutralize sequences such as ".." that can resolve to a location that is outside of that directory.

462 vulnerabilities with CWE-23
CVE-2024-22415 HIGH
jupyter-lsp < 2.2.2 - Unauthenticated Improper Access Control
CVSS 7.3
CVE-2023-35816 LOW
DevExpress <23.1.3 - Code Injection
CVSS 3.5
CVE-2023-40714 CRITICAL
Fortinet FortiSIEM <6.7.2-6.6.3 - Path Traversal
CVSS 9.9
CVE-2023-34990 CRITICAL
Fortinet FortiWLM 8.5.0-8.5.4 and 8.6.0-8.6.5 - Relative Path Traversal and Code Execution via Web Requests
CVSS 9.8
CVE-2023-3941 CRITICAL
ZkTeco-based OEM devices <1.8.25-7354-Ver1.0.0 - Path Traversal
CVSS 10.0
CVE-2023-3940 HIGH
ZkTeco-based OEM devices <1.8.25-7354-Ver1.0.0 - Path Traversal
CVSS 7.5
CVE-2023-6825 CRITICAL
File Manager (Free <=7.2.1, Pro <=8.3.4) - Directory Traversal & Arbitrary File Upload
CVSS 9.9
CVE-2023-42791 HIGH
Fortinet FortiManager Path Traversal via Crafted HTTP Requests
CVSS 8.8
CVE-2023-49801 MEDIUM
lif_auth_server < 1.4.0 - Path Traversal via get_pfp and get_banner Routes
CVSS 4.2
CVE-2023-31036 HIGH
NVIDIA Triton Inference Server - Path Traversal
CVSS 7.5
CVE-2023-50255 CRITICAL
deepin-compressor < 5.12.21 - Path Traversal and Remote Code Execution via Crafted Archive
CVSS 9.3
CVE-2023-6722 HIGH
Repox - Path Traversal and Arbitrary File Read
CVSS 7.5
CVE-2023-6307 MEDIUM
jeecgboot JimuReport <1.6.1 - Path Traversal
CVSS 6.3
CVE-2023-5189 MEDIUM
Ansible Automation Platform - Path Traversal via Malicious Tarball Extraction
CVSS 6.3
CVE-2023-42783 HIGH
Fortinet FortiWLM 8.2.2-8.6.5 - Relative Path Traversal via Crafted HTTP Requests
CVSS 7.5
CVE-2023-47613 MEDIUM
Telit Cinterion BGS5 EHS5/6/8 PDS5/6/8 ELS61/81 PLS62 - Path Traversal
CVSS 4.4
CVE-2023-46119 HIGH
Parse Server <5.5.6,6.3.1 - Info Disclosure
CVSS 7.5
CVE-2023-37913 CRITICAL
XWiki 3.5-14.10.8 - Path Traversal and Arbitrary File Write via Office Converter
CVSS 9.9
CVE-2023-3701 CRITICAL
Aqua Drive 2.4 - Authenticated Path Traversal
CVSS 9.9
CVE-2023-3512 HIGH
Setelsa Security's ConacWin CB <3.8.2.2 - Path Traversal
CVSS 7.5
CVE-2023-42456 LOW
sudo-rs < 0.2.1 - Path Traversal via Username with Special Characters
CVSS 3.3
CVE-2023-4760 HIGH
Eclipse RAP 3.0.0-3.25.0 - Remote Code Execution via FileUpload Path Traversal
CVSS 7.6
CVE-2023-4914 HIGH
cecil < 7.47.1 - Path Traversal
CVSS 7.5
CVE-2023-4897 CRITICAL
mintplex-labs/anything-llm <0.0.1 - Path Traversal
CVSS 9.8
CVE-2023-38185 HIGH
Microsoft Exchange Server - Remote Code Execution
CVSS 8.8
Details
Vulnerabilities 462