CWE-35

Path Traversal: '.../...//'

Parent: CWE-23 - Relative Path Traversal

The product uses external input to construct a pathname that should be within a restricted directory, but it does not properly neutralize '.../...//' (doubled triple dot slash) sequences that can resolve to a location that is outside of that directory.

169 vulnerabilities with CWE-35
CVE-2024-47171 MEDIUM
agnai < 1.0.330 - Path Traversal and Arbitrary File Write via Image Upload
CVSS 4.3
CVE-2024-47170 MEDIUM
agnai < 1.0.330 - Path Traversal via JSON Storage
CVSS 4.3
CVE-2024-47169 HIGH
agnai < 1.0.330 - Unauthenticated Arbitrary File Write via Path Traversal
CVSS 8.8
CVE-2024-0067 MEDIUM
AXIS OS - Path Traversal via VAPIX API ledlimit.cgi
CVSS 4.3
CVE-2024-7608 MEDIUM
NX-EX-FX-AX-IVX-CMS - Path Traversal
CVSS 5.9
CVE-2024-45190 MEDIUM
Mage AI - Path Traversal via Pipeline Interaction Request
CVSS 6.5
CVE-2024-0113 HIGH
NVIDIA Mellanox OS, ONYX, Skyway, and MetroX-3 XCC - Path Traversal via Web Support CGI URI
CVSS 7.5
CVE-2024-40505 CRITICAL
D-Link DAP-1650 <v.1.03 - Path Traversal
CVSS 9.3
CVE-2024-38706 MEDIUM
HasThemes HT Mega <2.5.7 - Path Traversal
CVSS 6.5
CVE-2024-39171 CRITICAL
phpvibe 11.0.3-11.0.46 - Path Traversal and Remote Code Execution via .htaccess and PNG File Upload
CVSS 9.8
CVE-2024-36991 HIGH
Splunk 9.0.0-9.0.9 - Path Traversal via /modules/messaging/ Endpoint
CVSS 7.5
CVE-2024-5481 MEDIUM
Photo Gallery by 10Web - Mobile-Friendly Image Gallery <= 1.8.23 - Authenticated Path Traversal via esc_dir Function
CVSS 6.8
CVE-2024-34191 MEDIUM
htmly 2.9.6 - Arbitrary File Deletion via delete_post() Function
CVSS 6.5
CVE-2024-2654 MEDIUM
WordPress File Manager <7.2.5 - Path Traversal
CVSS 6.8
CVE-2024-27901 HIGH
SAP Asset Accounting - Path Traversal
CVSS 7.2
CVE-2024-2863 MEDIUM
LG LED Assistant - Thumbnail Path Traversal File Upload
CVSS 5.3
CVE-2024-1886 LOW
LG webOS Signage - Path Traversal
CVSS 3.0
CVE-2023-7263 HIGH
Huawei home music system - Path Traversal
CVSS 7.3
CVE-2023-7300 HIGH
Huawei Home Music System - Path Traversal
CVSS 8.0
CVE-2023-41793 MEDIUM
Pandora FMS 700-775 - Path Traversal and Arbitrary File Write
CVSS 6.7
CVE-2023-5800 MEDIUM
AXIS OS < 11.8.61, 2020 < 9.80.55, 2022 < 10.12.220 - Authenticated RCE via VAPIX API
CVSS 5.4
CVE-2023-46690 HIGH
Delta Electronics InfraSuite Device Master <1.0.7 - Code Injection
CVSS 8.8
CVE-2023-5885 MEDIUM
Franklin Fueling Colibri Firmware - Unauthenticated Path Traversal
CVSS 6.5
CVE-2023-6252 HIGH
Chameleon Power - Path Traversal via getImage Parameter
CVSS 7.5
CVE-2023-21418 HIGH
AXIS OS < 6.50.5.15, < 11.7.57, < 8.40.35, < 9.80.49, < 10.12.213 - Path Traversal & File Deletion via VAPIX API
CVSS 7.1
Details
Vulnerabilities 169