CWE-22— Path Traversal
The product uses external input to construct a pathname that is intended to identify a file or directory that is located underneath a restricted parent directory, but the product does not properly neutralize special elements within the pathname that can cause the pathname to resolve to a location that is outside of the restricted directory.— MITRE CWE catalog
8,885 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-22page 1 of 178
- CVE-2000-1210MEDIUMCVSS v2 5.0EG 5.02002-03-22
Directory traversal vulnerability in source.jsp of Apache Tomcat before 3.1 allows remote attackers to read arbitrary files via a .. (dot dot) in the argument to source.jsp.
- CVE-2001-0054MEDIUMCVSS v2 5.0EG 5.02001-02-16
Directory traversal vulnerability in FTP Serv-U before 2.5i allows remote attackers to escape the FTP root and read arbitrary files by appending a string such as "/..%20." to a CD command, a variant of a .. (dot dot) attack.
- CVE-2001-0780MEDIUMCVSS v2 5.0EG 5.02001-10-18
Directory traversal vulnerability in cosmicpro.cgi in Cosmicperl Directory Pro 2.0 allows remote attackers to gain sensitive information via a .. (dot dot) in the SHOW parameter.
- CVE-2001-0925MEDIUMCVSS v2 5.0EG 5.02001-03-12
The default installation of Apache before 1.3.19 allows remote attackers to list directories instead of the multiview index.html file via an HTTP request for a path that contains many / (slash) characters, which causes the path to be misha…
- CVE-2001-1205MEDIUMCVSS v2 5.0EG 5.02001-12-30
Directory traversal vulnerability in lastlines.cgi for Last Lines 2.0 allows remote attackers to read arbitrary files via '..' sequences in the $error_log variable.
- CVE-2001-1432HIGHCVSS v2 7.8EG 7.82001-12-29
Directory traversal vulnerability in Cherokee Web Server allows remote attackers to read arbitrary files via a .. (dot dot) in the URL.
- CVE-2001-1586HIGHCVSS v2 10.0EG 10.02010-02-12
Directory traversal vulnerability in SimpleServer:WWW 1.13 and earlier allows remote attackers to execute arbitrary programs via encoded ../ ("%2E%2E%2F%") sequences in a request to the cgi-bin/ directory, a different vulnerability than CV…
- CVE-2002-2154MEDIUMCVSS v2 5.0EG 5.02002-12-31
Directory traversal vulnerability in Monkey HTTP Daemon 0.1.4 allows remote attackers to read arbitrary files via .. (dot dot) sequences.
- CVE-2002-2229MEDIUMCVSS v2 5.0EG 5.02002-12-31
Directory traversal vulnerability in Sapio Design Ltd. WebReflex 1.53 allows remote attackers to read arbitrary files via a .. in an HTTP request.
- CVE-2002-2233HIGHCVSS v2 8.3EG 8.32002-12-31
Directory traversal vulnerability in Enceladus Server Suite 3.9 allows remote attackers to list arbitrary directories and possibly cause a denial of service via "@" (at) characters in a CD (CWD) command, such as (1) "@/....\", (2) "@@@/..c…
- CVE-2002-2238MEDIUMCVSS v2 5.0EG 5.02002-12-31
Directory traversal vulnerability in the Kunani ODBC FTP Server 1.0.10 allows remote attackers to read arbitrary files via a "..\" (dot dot backslash) in a GET request.
- CVE-2002-2240MEDIUMCVSS v2 5.0EG 5.02002-12-31
Directory traversal vulnerability in MyServer 0.11 and 0.2 allows remote attackers to read arbitrary files via a ".." (dot dot) in an HTTP GET request.
- CVE-2002-2256MEDIUMCVSS v2 5.0EG 5.02002-12-31
Directory traversal vulnerability in pWins Webserver 0.2.5 and earlier allows remote attackers to read arbitrary files via Unicode characters.
- CVE-2002-2269HIGHCVSS v2 9.4EG 9.42002-12-31
Directory traversal vulnerability in Webster HTTP Server allows remote attackers to read arbitrary files via a .. (dot dot) in the URL.
- CVE-2002-2292MEDIUMCVSS v2 5.0EG 5.02002-12-31
Directory traversal vulnerability in Remote Console Applet in Halycon Software iASP 1.0.9 allows remote attackers to read arbitrary files via a .. (dot dot) in the HTTP request to port 9095.
- CVE-2002-2351MEDIUMCVSS v2 6.4EG 6.42002-12-31
Eudora 5.1 allows remote attackers to bypass security warnings and possibly execute arbitrary code via attachments with names containing a trailing "." (dot).
- CVE-2002-2375MEDIUMCVSS v2 5.0EG 5.02002-12-31
Directory traversal vulnerability in CommuniGate Pro 4.0b4 and possibly earlier versions allows remote attackers to list the contents of the WebUser directory and its parent directory via a (1) .. (dot dot) or (2) . (dot) in a URL. NOTE: …
- CVE-2002-2387MEDIUMCVSS v2 5.0EG 5.02002-12-31
Directory traversal vulnerability in Hyperion FTP server 2.8.1 allows remote attackers to read arbitrary files via a .. (dot dot) in the LS command.
- CVE-2002-2399MEDIUMCVSS v2 6.4EG 6.42002-12-31
Directory traversal vulnerability in viewAttachment.cgi in W3Mail 1.0.6 allows remote attackers to read arbitrary files via a .. (dot dot) in the file parameter.
- CVE-2002-2403MEDIUMCVSS v2 5.0EG 5.02002-12-31
Directory traversal vulnerability in KeyFocus web server 1.0.8 allows remote attackers to read arbitrary files for recognized MIME type files via "...", "....", ".....", and other multiple dot sequences.
- CVE-2002-2416MEDIUMCVSS v2 5.0EG 5.02002-12-31
Directory traversal vulnerability in Zeroo web server 1.5 allows remote attackers to read arbitrary files via a .. (dot dot) in a URL GET request.
- CVE-2003-0593HIGHCVSS v2 7.5EG 7.52004-04-15
Opera allows remote attackers to bypass intended cookie access restrictions on a web application via "%2e%2e" (encoded dot dot) directory traversal sequences in a URL, which causes Opera to send the cookie outside the specified URL subsets…
- CVE-2003-1335MEDIUMCVSS v2 5.0EG 5.02003-12-31
Directory traversal vulnerability in Kai Blankenhorn Bitfolge simple and nice index file (aka snif) before 1.2.5 allows remote attackers to download files from locations above the snif directory.
- CVE-2003-1345MEDIUMCVSS v2 5.0EG 5.02003-12-31
Directory traversal vulnerability in s.dll in WebCollection Plus 5.00 allows remote attackers to view arbitrary files in c:\ via a full pathname in the d parameter.
- CVE-2003-1349MEDIUMCVSS v2 5.0EG 5.02003-12-31
Directory traversal vulnerability in NITE ftp-server (NiteServer) 1.83 allows remote attackers to list arbitrary directories via a "\.." (backslash dot dot) in the CD (CWD) command.
- CVE-2003-1351MEDIUMCVSS v2 5.0EG 5.02003-12-31
Directory traversal vulnerability in edittag.cgi in EditTag 1.1 allows remote attackers to read arbitrary files via a "%2F.." (encoded slash dot dot) in the file parameter.
- CVE-2003-1373MEDIUMCVSS v2 6.8EG 6.82003-12-31
Directory traversal vulnerability in auth.php for PhpBB 1.4.0 through 1.4.4 allows remote attackers to read and include arbitrary files via .. (dot dot) sequences followed by NULL (%00) characters in CGI parameters, as demonstrated using t…
- CVE-2003-1380HIGHCVSS v2 7.5EG 7.52003-12-31
Directory traversal vulnerability in BisonFTP Server 4 release 2 allows remote attackers to (1) list directories above the root via an 'ls @../' command, or (2) list files above the root via a "mget @../FILE" command.
- CVE-2003-1413MEDIUMCVSS v2 4.3EG 4.32003-12-31
parse_xml.cgi in Apple Darwin Streaming Server 4.1.1 allows remote attackers to determine the existence of arbitrary files by using ".." sequences in the filename parameter and comparing the resulting error messages.
- CVE-2003-1414MEDIUMCVSS v2 4.3EG 4.32003-12-31
Directory traversal vulnerability in parse_xml.cg Apple Darwin Streaming Server 4.1.2 and Apple Quicktime Streaming Server 4.1.1 allows remote attackers to read arbitrary files via a ... (triple dot) in the filename parameter.
- CVE-2003-1427MEDIUMCVSS v2 6.4EG 6.42003-12-31
Directory traversal vulnerability in the web configuration interface in Netgear FM114P 1.4 allows remote attackers to read arbitrary files, such as the netgear.cfg configuration file, via a hex-encoded (%2e%2e%2f) ../ (dot dot slash) in th…
- CVE-2003-1430MEDIUMCVSS v2 5.0EG 5.02003-12-31
Directory traversal vulnerability in Unreal Tournament Server 436 and earlier allows remote attackers to access known files via a ".." (dot dot) in an unreal:// URL.
- CVE-2003-1465MEDIUMCVSS v2 5.0EG 5.02003-12-31
Directory traversal vulnerability in download.php in Phorum 3.4 through 3.4.2 allows remote attackers to read arbitrary files.
- CVE-2003-1499MEDIUMCVSS v2 5.0EG 5.02003-12-31
Directory traversal vulnerability in index.php in Bytehoard 0.7 allows remote attackers to read arbitrary files via a .. (dot dot) in the infolder parameter.
- CVE-2003-1501MEDIUMCVSS v2 6.4EG 6.42003-12-31
Directory traversal vulnerability in the file upload CGI of Gast Arbeiter 1.3 allows remote attackers to write arbitrary files via a .. (dot dot) in the req_file parameter.
- CVE-2003-1529MEDIUMCVSS v2 5.0EG 5.02003-12-31
Directory traversal vulnerability in Seagull Software Systems J Walk application server 3.2C9, and other versions before 3.3c4, allows remote attackers to read arbitrary files via a ".%252e" (encoded dot dot) in the URL.
- CVE-2003-1537MEDIUMCVSS v2 5.0EG 5.02003-12-31
Directory traversal vulnerability in PostNuke 0.723 and earlier allows remote attackers to include arbitrary files named theme.php via the theme parameter to index.php.
- CVE-2003-1542MEDIUMCVSS v2 5.0EG 5.02003-12-31
Directory traversal vulnerability in plugins/file.php in phpWebFileManager before 0.4.4 allows remote attackers to read arbitrary files via a .. (dot dot) in the fm_path parameter.
- CVE-2003-1545MEDIUMCVSS v2 5.0EG 5.02003-12-31
Absolute path traversal vulnerability in nukestyles.com viewpage.php addon for PHP-Nuke allows remote attackers to read arbitrary files via a full pathname in the file parameter. NOTE: This was originally reported as an issue in PHP-Nuke …
- CVE-2004-0175MEDIUMCVSS v2 4.3EG 4.32004-08-18
Directory traversal vulnerability in scp for OpenSSH before 3.4p1 allows remote malicious servers to overwrite arbitrary files. NOTE: this may be a rediscovery of CVE-2000-0992.
- CVE-2004-0273HIGHCVSS v2 9.3EG 9.32004-11-23
Directory traversal vulnerability in RealOne Player, RealOne Player 2.0, and RealOne Enterprise Desktop allows remote attackers to upload arbitrary files via an RMP file that contains .. (dot dot) sequences in a .rjs skin file.
- CVE-2004-0847CRITICALCVSS 9.8EG 9.82004-11-03
The Microsoft .NET forms authentication capability for ASP.NET allows remote attackers to bypass authentication for .aspx files in restricted directories via a request containing a (1) "\" (backslash) or (2) "%5C" (encoded backslash), aka …
- CVE-2004-1354MEDIUMCVSS v2 5.0EG 5.02004-05-14
The Solaris Management Console (SMC) in Sun Solaris 8 and 9 generates different 404 error messages when a file does not exist versus when a file exists but is otherwise inaccessible, which could allow remote attackers to obtain sensitive i…
- CVE-2004-1364HIGHCVSS v2 8.5EG 8.52004-08-04
Directory traversal vulnerability in extproc in Oracle 9i and 10g allows remote attackers to access arbitrary libraries outside of the $ORACLE_HOME\bin directory.
- CVE-2004-1444MEDIUMCVSS v2 5.0EG 5.02004-12-31
Directory traversal vulnerability in Roundup 0.6.4 and earlier allows remote attackers to view arbitrary files via .. (dot dot) sequences in an @@ command in an HTTP GET request.
- CVE-2004-1927MEDIUMCVSS v2 5.0EG 5.02004-04-11
Directory traversal vulnerability in the map feature (tiki-map.phtml) in Tiki CMS/Groupware (TikiWiki) 1.8.1 and earlier allows remote attackers to determine the existence of arbitrary files via .. (dot dot) sequences in the mapfile parame…
- CVE-2004-1991MEDIUMCVSS v2 5.0EG 5.02004-05-03
Directory traversal vulnerability in Aldo's Web Server (aweb) 1.5 allows remote attackers to view arbitrary files via a .. (dot dot) in an HTTP GET request.
- CVE-2004-2686HIGHCVSS v2 7.2EG 7.22004-12-31
Directory traversal vulnerability in the vfs_getvfssw function in Solaris 2.6, 7, 8, and 9 allows local users to load arbitrary kernel modules via crafted (1) mount or (2) sysfs system calls. NOTE: this might be the same issue as CVE-2004…
- CVE-2004-2717LOWCVSS v2 2.6EG 2.62004-12-31
Multiple directory traversal vulnerabilities in admin.php3 in PHPMyChat 0.14.5 allow remote attackers with administrative privileges to read arbitrary files via a .. (dot dot) in the (1) sheet and (2) What parameters.
- CVE-2004-2745HIGHCVSS v2 7.8EG 7.82004-12-31
Directory traversal vulnerability in Anteco Visual Technologies OwnServer 1.0 and earlier allows remote attackers to read arbitrary files via a .. (dot dot) in a URL.
Map vulnerabilities like CWE-22 to your infrastructure
EchelonGraph correlates every CVE — across CWE-22 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →