CWE-29

Path Traversal: '\..\filename'

Parent: CWE-23 - Relative Path Traversal

The product uses external input to construct a pathname that should be within a restricted directory, but it does not properly neutralize '\..\filename' (leading backslash dot dot) sequences that can resolve to a location that is outside of that directory.

64 vulnerabilities with CWE-29
CVE-2024-7774 CRITICAL
langchain.js < 0.2.19 - Path Traversal via getFullPath Method
CVSS 9.1
CVE-2024-6394 HIGH
parisneo/lollms-webui <9.8 - Path Traversal
CVSS 7.5
CVE-2024-6396 CRITICAL
Aim 3.19.3 - Arbitrary File Overwrite via _backup_run Parameters
CVSS 9.8
CVE-2024-5926 CRITICAL
stitionai devika - Path Traversal and Denial of Service via Project-Name Parameter
CVSS 9.1
CVE-2024-6139 HIGH
parisneo/lollms <9.6 - Path Traversal
CVSS 7.3
CVE-2024-4841 LOW
lollms-webui v9.6-latest - Path Traversal via add_reference_to_local_model Endpoint
CVSS 3.3
CVE-2024-5443 CRITICAL
lollms < 9.5.1 - Path Traversal and Remote Code Execution via ExtensionBuilder Mount Endpoint
CVSS 9.8
CVE-2024-21518 HIGH
OpenCart >= 4.0.0.0 - Path Traversal via Marketplace Installer Zip Slip
CVSS 7.2
CVE-2024-5211 HIGH
AnythingLLM < 1.0.0 - Path Traversal and Arbitrary File Write via Custom Logo Upload
CVSS 7.2
CVE-2024-4320 CRITICAL
lollms_web_ui - Remote Code Execution via Extension Install Name Parameter
CVSS 9.8
CVE-2024-3429 CRITICAL
lollms < 9.6 - Path Traversal via Insufficient Input Sanitization
CVSS 9.8
CVE-2024-2928 HIGH
MLflow < 2.11.3 - Path Traversal
CVSS 7.5
CVE-2024-2624 CRITICAL
parisneo/lollms-webui - Path Traversal
CVSS 9.8
CVE-2024-2360 CRITICAL
lollms_web_ui - Path Traversal and Remote Code Execution via Database and PDF LaTeX Path Settings
CVSS 9.8
CVE-2024-2914 HIGH
deepjavalibrary/djl <0.27.0 - Path Traversal
CVSS 8.8
CVE-2024-2178 HIGH
parisneo/lollms-webui - Path Traversal
CVSS 7.5
CVE-2024-4322 HIGH
lollms_web_ui < 9.8 - Path Traversal via /list_personalities Endpoint Category Parameter
CVSS 7.5
CVE-2024-3848 HIGH
MLflow < 2.12.1 - Path Traversal via URL Fragment Bypass
CVSS 7.5
CVE-2024-3435 HIGH
lollms_web_ui < 9.5 - Path Traversal and Remote Code Execution via Config Parameter in Save Settings Endpoint
CVSS 8.4
CVE-2024-2361 CRITICAL
lollms_web_ui < 9.5 - Path Traversal and Arbitrary File Upload via install_model() Function
CVSS 9.6
CVE-2024-2358 CRITICAL
lollms_web_ui < 9.5 - Path Traversal and Remote Code Execution via Extensions Parameter
CVSS 9.8
CVE-2024-34470 HIGH
HSC Mailinspector <5.2.18 - Path Traversal
CVSS 8.6
CVE-2024-3573 CRITICAL
MLflow < 2.10.0 - Local File Inclusion via URI Scheme Parsing Bypass
CVSS 9.3
CVE-2024-2083 CRITICAL
zenml < 0.55.5 - Path Traversal via /api/v1/steps Logs URI Parameter
CVSS 9.9
CVE-2024-1561 HIGH
gradio-app/gradio - Info Disclosure
CVSS 7.5
Details
Vulnerabilities 64