CWE-36

Absolute Path Traversal

Parent: CWE-22 - Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')

The product uses external input to construct a pathname that should be within a restricted directory, but it does not properly neutralize absolute path sequences such as "/abs/path" that can resolve to a location that is outside of that directory.

126 vulnerabilities with CWE-36
CVE-2024-51549 CRITICAL
ABB ASPECT <3.08.02, NEXUS Series <3.08.02, MATRIX Series <3.08.02 ...
CVSS 10.0
CVE-2024-11978 HIGH
Interinfo DreamMaker < 2024/09/26 - Unauthenticated Path Traversal
CVSS 7.5
CVE-2024-10651 MEDIUM
IDExpert 2.5-2.8 - Authenticated Absolute Path Traversal
CVSS 4.9
CVE-2024-47883 CRITICAL
OpenRefine Butterfly < 1.2.6 - Path Traversal and Server-Side Request Forgery via file:/ URL
CVSS 9.1
CVE-2024-20379 MEDIUM
Cisco Secure Firewall Management Center - Info Disclosure
CVSS 6.5
CVE-2024-9924 CRITICAL
Hgiga OAKlouds < 1162 - Unauthenticated Absolute Path Traversal
CVSS 9.8
CVE-2024-45291 MEDIUM
PhpSpreadsheet Image Embedding - File Read and Server-Side Request Forgery
CVSS 6.3
CVE-2024-45290 HIGH
PHPSpreadsheet <1.29.2, >=2.2.0 <2.3.0 - Absolute Path Traversal via Crafted XLSX File
CVSS 7.7
CVE-2024-8497 HIGH
Franklin Fueling Systems TS-550 EVO <2.26.4.8967 - Info Disclosure
CVSS 7.5
CVE-2024-8778 MEDIUM
OMFLOW 1.1.6.0-1.2.1.2 - Path Traversal via Download Functionality
CVSS 6.5
CVE-2024-7323 MEDIUM
Digiwin EasyFlow .NET < 6.6.17 - Path Traversal and Arbitrary File Read
CVSS 6.5
CVE-2024-28806 HIGH
Italtel i-MCS NFV 12.1.0-20211215 - Unauthenticated Path Traversal and Arbitrary File Write
CVSS 7.5
CVE-2024-20401 CRITICAL
Cisco Secure Email Gateway - File Overwrite
CVSS 9.8
CVE-2024-6250 HIGH
parisneo/lollms-webui <9.6 - Path Traversal
CVSS 7.5
CVE-2024-33620 HIGH
ID Link Manager/FUJITSU Software TIME CREATOR - Path Traversal
CVSS 8.6
CVE-2024-4881 HIGH
lollms < 5.9.0 - Path Traversal via Backslash Handling in /user_infos Endpoint
CVSS 7.5
CVE-2024-2548 HIGH
lollms_web_ui < 9.5 - Path Traversal via User Infos Endpoint
CVSS 7.5
CVE-2024-2362 CRITICAL
lollms_web_ui 9.3 - Path Traversal and Arbitrary File Deletion via del_preset Endpoint
CVSS 9.1
CVE-2024-29053 HIGH
Microsoft Defender for IoT < 24.1.3 - Remote Code Execution
CVSS 8.8
CVE-2024-21323 HIGH
Microsoft Defender for IoT < 24.1.3 - Remote Code Execution
CVSS 8.8
CVE-2024-1703 LOW
CRMEB 5.2.2 - Path Traversal via /adminapi/system/file/openfile
CVSS 3.5
CVE-2023-41830 MEDIUM
Motorola Phones < 2023-12-01 - Unauthenticated Absolute Path Traversal
CVSS 6.5
CVE-2023-50955 LOW
IBM InfoSphere Information Server 11.7 - Authenticated Path Traversal
CVSS 2.4
CVE-2023-5390 MEDIUM
Honeywell ControlEdge Unit Operations Controller Firmware - Path Traversal
CVSS 5.3
CVE-2023-30970 MEDIUM
Gotham Table service & Forward App - Path Traversal
CVSS 6.5
Details
Vulnerabilities 126