CWE-23

Relative Path Traversal

Parent: CWE-22 - Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')

The product uses external input to construct a pathname that should be within a restricted directory, but it does not properly neutralize sequences such as ".." that can resolve to a location that is outside of that directory.

462 vulnerabilities with CWE-23
CVE-2022-42476 HIGH
FortiProxy 1.1.0-1.1.5 - Privilege Escalation via CLI Request Path Traversal
CVSS 8.2
CVE-2022-3162 MEDIUM
kubernetes <1.22.15 and 1.25.0-1.25.4 - Unauthorized Custom Resource Access via Path Traversal
CVSS 6.5
CVE-2022-41335 HIGH
Fortinet FortiOS <7.2.2 - Path Traversal
CVSS 8.8
CVE-2022-30300 MEDIUM
FortiWeb 6.3.6-6.3.18, 7.0.0-7.0.1 - Authenticated Path Traversal via HTTP GET Request
CVSS 6.5
CVE-2022-30299 MEDIUM
FortiWeb 6.0.0-6.0.7, 6.1-6.3.19, 6.4, 7.0.0-7.0.1 - Authenticated Path Traversal via API
CVSS 5.3
CVE-2022-29844 MEDIUM
Western Digital My Cloud OS 5 - Path Traversal and Arbitrary File Write via FTP Service
CVSS 6.7
CVE-2022-38205 HIGH
Esri Portal for ArcGIS <10.9.1 - Path Traversal
CVSS 8.6
CVE-2022-38202 HIGH
Esri ArcGIS Server <10.9.1 - Path Traversal
CVSS 7.5
CVE-2022-23854 HIGH
AVEVA InTouch Access Anywhere <2020 R2 - Path Traversal
CVSS 7.5
CVE-2022-23531 MEDIUM
GuardDog < 0.1.5 - Arbitrary File Write via Tarfile Extraction Path Traversal
CVSS 5.8
CVE-2022-4123 LOW
Podman - Path Traversal
CVSS 3.3
CVE-2022-42892 MEDIUM
syngo Dynamics < VA40G HF01 - Unauthenticated Directory Listing via Web Service Operation
CVSS 5.3
CVE-2022-39345 CRITICAL
gin-vue-admin < 2.5.4 - Path Traversal and Arbitrary File Write
CVSS 9.8
CVE-2022-22245 MEDIUM
Juniper Networks Junos OS <19.1R3-S9, <19.2 - Path Traversal
CVSS 4.3
CVE-2022-33937 HIGH
Dell GeoDrive 1.0-2.2 - Path Traversal
CVSS 7.1
CVE-2022-2922 MEDIUM
Dnnsoftware Dotnetnuke < 9.11.0 - Path Traversal
CVSS 4.9
CVE-2022-28814 CRITICAL
Carlo Gavazzi UWP3.0 - Path Traversal
CVSS 9.8
CVE-2022-36081 HIGH
wikmd < 1.7.1 - Path Traversal via /list Endpoint
CVSS 7.5
CVE-2022-34378 MEDIUM
Dell PowerScale OneFS 9.0.0-9.1.0.20, 9.2.1.13, 9.3.0.6, 9.4.0.3 - Denial of Service via Relative Path Traversal
CVSS 5.5
CVE-2022-34836 MEDIUM
ABB Zenon < 8.20 - Path Traversal and Log Flooding
CVSS 5.9
CVE-2022-1373 HIGH
Softing Secure Integration Server v1.22 Remote Code Execution
CVSS 7.2
CVE-2022-1648 MEDIUM
Pandora FMS < 7.0_ng_760 - Authenticated Path Traversal and Remote Code Execution via File Manager
CVSS 5.7
CVE-2022-2139 MEDIUM
Advantech iView < 5.7.04.6469 - Path Traversal and Arbitrary Code Execution
CVSS 6.5
CVE-2022-31163 HIGH
TZInfo <0.36.1, <1.2.10 (with tzinfo-data) - Path Traversal
CVSS 7.5
CVE-2022-20913 MEDIUM
Cisco Nexus Dashboard 2.0-2.2(1e) - Authenticated Arbitrary File Write via Web Management Interface
CVSS 4.9
Details
Vulnerabilities 462