CWE-36
Absolute Path Traversal
The product uses external input to construct a pathname that should be within a restricted directory, but it does not properly neutralize absolute path sequences such as "/abs/path" that can resolve to a location that is outside of that directory.
130 vulnerabilities with CWE-36
CVE-2021-30173
MEDIUM
Omni-directional <version> - Local File Inclusion
CVSS 6.5
CVE-2021-1297
HIGH
Cisco RV160/RV260 VPN Router Firmware < 1.0.01.02 - Unauthenticated Path Traversal & Arbitrary File Write
CVSS 7.5
CVE-2021-1296
HIGH
Cisco RV160/RV260 VPN Routers <1.0.01.02 - Unauthenticated Path Traversal & Arbitrary File Write
CVSS 7.5
CVE-2018-20250
HIGH
KEV
WinRAR <= 5.61 - Path Traversal and Remote Code Execution via ACE Filename Field
CVSS 7.8
CVE-2017-7929
HIGH
Advantech WebAccess < 8.1 - Path Traversal
CVSS 7.1
Details
Vulnerabilities
130