CWE-36

Absolute Path Traversal

Parent: CWE-22 - Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')

The product uses external input to construct a pathname that should be within a restricted directory, but it does not properly neutralize absolute path sequences such as "/abs/path" that can resolve to a location that is outside of that directory.

130 vulnerabilities with CWE-36
CVE-2021-30173 MEDIUM
Omni-directional <version> - Local File Inclusion
CVSS 6.5
CVE-2021-1297 HIGH
Cisco RV160/RV260 VPN Router Firmware < 1.0.01.02 - Unauthenticated Path Traversal & Arbitrary File Write
CVSS 7.5
CVE-2021-1296 HIGH
Cisco RV160/RV260 VPN Routers <1.0.01.02 - Unauthenticated Path Traversal & Arbitrary File Write
CVSS 7.5
CVE-2018-20250 HIGH KEV
WinRAR <= 5.61 - Path Traversal and Remote Code Execution via ACE Filename Field
CVSS 7.8
CVE-2017-7929 HIGH
Advantech WebAccess < 8.1 - Path Traversal
CVSS 7.1
Details
Vulnerabilities 130