CWE-22— Path Traversal
The product uses external input to construct a pathname that is intended to identify a file or directory that is located underneath a restricted parent directory, but the product does not properly neutralize special elements within the pathname that can cause the pathname to resolve to a location that is outside of the restricted directory.— MITRE CWE catalog
9,439 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-22page 17 of 189
- CVE-2009-2116MEDIUMCVSS v2 4.0EG 4.02009-06-18
Directory traversal vulnerability in admin.php in SkyBlueCanvas 1.1 r237 allows remote authenticated administrators to list directory contents via a .. (dot dot) in the dir parameter.
- CVE-2009-2124HIGHCVSS v2 7.5EG 7.52009-06-19
Directory traversal vulnerability in page.php in Elvin 1.2.0 allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the id parameter.
- CVE-2009-2132MEDIUMCVSS v2 6.8EG 6.82009-06-19
Directory traversal vulnerability in global.php in 4images before 1.7.7, when magic_quotes_gpc is disabled, allows remote attackers to include and execute arbitrary local files via directory traversal sequences in the l parameter.
- CVE-2009-2151MEDIUMCVSS v2 5.0EG 5.02009-06-22
Directory traversal vulnerability in index.php in AdaptWeb 0.9.2 allows remote attackers to read arbitrary files via a .. (dot dot) in the newlang parameter.
- CVE-2009-2161MEDIUMCVSS v2 5.1EG 5.12009-06-22
Directory traversal vulnerability in backend/admin-functions.php in TorrentTrader Classic 1.09, when used on a case-insensitive web site, allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the ss_uri…
- CVE-2009-2166MEDIUMCVSS v2 5.0EG 5.02009-06-22
Absolute path traversal vulnerability in cvs.php in OCS Inventory NG before 1.02.1 on Unix allows remote attackers to read arbitrary files via a full pathname in the log parameter.
- CVE-2009-2176HIGHCVSS v2 7.5EG 7.52009-06-23
Multiple directory traversal vulnerabilities in fuzzylime (cms) 3.03a and earlier, when magic_quotes_gpc is disabled, allow remote attackers to include and execute arbitrary local files via directory traversal sequences in the (1) list par…
- CVE-2009-2177MEDIUMCVSS v2 6.8EG 6.82009-06-23
code/display.php in fuzzylime (cms) 3.03a and earlier, when magic_quotes_gpc is disabled, allows remote attackers to conduct directory traversal attacks and overwrite arbitrary files via a "....//" (dot dot) in the s parameter, which is co…
- CVE-2009-2180MEDIUMCVSS v2 5.0EG 5.02009-06-23
Multiple directory traversal vulnerabilities in upfiles/index.php in Pc4 Uploader 10.0 and earlier allow remote attackers to read arbitrary files via (1) a .. (dot dot) or (2) absolute path in the file parameter.
- CVE-2009-2183HIGHCVSS v2 7.5EG 7.52009-06-23
Directory traversal vulnerability in admin-files/ad.php in Campsite 3.3.0 RC1 allows remote attackers to read and possibly execute arbitrary local files via a .. (dot dot) in the GLOBALS[g_campsiteDir] parameter.
- CVE-2009-2184MEDIUMCVSS v2 5.0EG 5.02009-06-23
Absolute path traversal vulnerability in forcedownload.php in Gravy Media Photo Host 1.0.8 allows remote attackers to read arbitrary files via an encoded "/" (slash) in the file parameter.
- CVE-2009-2220MEDIUMCVSS v2 5.1EG 5.12009-06-26
Multiple directory traversal vulnerabilities in Tribiq CMS 5.0.12c, when register_globals is enabled and magic_quotes_gpc is disabled, allow remote attackers to include and possibly execute arbitrary files via directory traversal sequences…
- CVE-2009-2222MEDIUMCVSS v2 5.0EG 5.02009-06-26
Directory traversal vulnerability in PHP-I-BOARD 1.2 and earlier allows remote attackers to read arbitrary files via directory traversal sequences in unspecified vectors, probably related to mail.
- CVE-2009-2223HIGHCVSS v2 9.3EG 9.32009-06-26
Directory traversal vulnerability in locms/smarty.php in LightOpenCMS 0.1 allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the cwd parameter. NOTE: remote file inclusion attacks may be possible.
- CVE-2009-2224MEDIUMCVSS v2 4.3EG 4.32009-06-26
Directory traversal vulnerability in ang/shared/flags.php in AN Guestbook 0.7.8, when register_globals is enabled, allows remote attackers to read arbitrary files via a .. (dot dot) in the g_lang parameter.
- CVE-2009-2229MEDIUMCVSS v2 5.0EG 5.02009-06-26
Directory traversal vulnerability in engine.php in Kasseler CMS 1.3.5 lite allows remote attackers to read arbitrary files via a .. (dot dot) in the file parameter during a download action, a different vector than CVE-2008-3087. NOTE: som…
- CVE-2009-2258HIGHCVSS v2 7.8EG 7.82009-06-30
Directory traversal vulnerability in cgi-bin/webcm in the administrative web interface on the Netgear DG632 with firmware 3.4.0_ap allows remote attackers to list arbitrary directories via a .. (dot dot) in the nextpage parameter.
- CVE-2009-2263HIGHCVSS v2 7.5EG 7.52009-06-30
Directory traversal vulnerability in index.php in Awesome PHP Mega File Manager 1.0 allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the page parameter. NOTE: in some environments, this can be lev…
- CVE-2009-2265HIGHCVSS v2 7.5EG 7.52009-07-05
Multiple directory traversal vulnerabilities in FCKeditor before 2.6.4.1 allow remote attackers to create executable files in arbitrary directories via directory traversal sequences in the input to unspecified connector modules, as exploit…
- CVE-2009-2275MEDIUMCVSS v2 5.0EG 5.02009-07-01
Directory traversal vulnerability in frontend/x3/stats/lastvisit.html in cPanel allows remote attackers to read arbitrary files via a .. (dot dot) in the domain parameter.
- CVE-2009-2313HIGHCVSS v2 7.5EG 7.52009-07-02
Directory traversal vulnerability in index.php in Jinzora Media Jukebox 2.8 and earlier allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the name parameter.
- CVE-2009-2325MEDIUMCVSS v2 5.0EG 5.02009-07-05
Directory traversal vulnerability in index.php in Clicknet CMS 2.1 allows remote attackers to read arbitrary files via a .. (dot dot) in the side parameter.
- CVE-2009-2333HIGHCVSS v2 7.5EG 7.52009-07-05
Multiple directory traversal vulnerabilities in CMS Chainuk 1.2 and earlier allow remote attackers to include and execute arbitrary local files via a .. (dot dot) in (1) the menu parameter to admin/admin_menu.php, and the id parameter to (…
- CVE-2009-2338MEDIUMCVSS v2 6.8EG 6.82009-07-07
Directory traversal vulnerability in includes/startmodules.inc.php in FreeWebshop.org 2.2.9 R2, when register_globals is enabled, allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the lang_file para…
- CVE-2009-2379MEDIUMCVSS v2 6.8EG 6.82009-07-08
Directory traversal vulnerability in public/index.php in BIGACE Web CMS 2.6 allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the cmd parameter.
- CVE-2009-2397MEDIUMCVSS v2 5.0EG 5.02009-07-09
Directory traversal vulnerability in download.php in Audio Article Directory allows remote attackers to read arbitrary files via directory traversal sequences in the file parameter.
- CVE-2009-2398MEDIUMCVSS v2 5.0EG 5.02009-07-09
Directory traversal vulnerability in test/index.php in PHP-Sugar 0.80 allows remote attackers to read arbitrary files via a ..// (dot dot slash slash) in the t parameter.
- CVE-2009-2444HIGHCVSS v2 7.5EG 7.52009-07-13
Directory traversal vulnerability in maillinglist/setup/step1.php.inc in ADbNewsSender before 1.5.6, and 2.0 before RC2, allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the path_to_lang parameter …
- CVE-2009-2449HIGHCVSS v2 7.5EG 7.52009-07-13
Directory traversal vulnerability in maillinglist/admin/change_config.php in ADbNewsSender before 1.5.6 allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the path_to_lang parameter.
- CVE-2009-2544MEDIUMCVSS v2 6.8EG 6.82009-07-20
Directory traversal vulnerability in the Marcelo Costa FileServer component 1.0 for Microsoft Windows Live Messenger and Messenger Plus! Live (MPL) allows remote authenticated users to list arbitrary directories and read arbitrary files vi…
- CVE-2009-2546MEDIUMCVSS v2 4.3EG 4.32009-07-20
Directory traversal vulnerability in Advanced Electron Forum (AEF) 1.x allows remote attackers to determine the existence of arbitrary files via the avatargalfile parameter when changing an avatar, which leaks the existence of the file in …
- CVE-2009-2552MEDIUMCVSS v2 6.8EG 6.82009-07-20
Multiple directory traversal vulnerabilities in comments.php in Super Simple Blog Script 2.5.4 allow remote attackers to overwrite, include, and execute arbitrary local files via the entry parameter.
- CVE-2009-2557MEDIUMCVSS v2 5.0EG 5.02009-07-21
Directory traversal vulnerability in system/download.php in Admin News Tools 2.5 allows remote attackers to read arbitrary files via a .. (dot dot) in the fichier parameter.
- CVE-2009-2600MEDIUMCVSS v2 5.0EG 5.02009-07-27
Multiple directory traversal vulnerabilities in view.php in Webboard 2.90 beta and earlier allow remote attackers to read arbitrary files via a .. (dot dot) in the topic parameter.
- CVE-2009-2611MEDIUMCVSS v2 6.8EG 6.82009-07-27
Directory traversal vulnerability in infusions/last_seen_users_panel/last_seen_users_panel.php in MyFusion (aka MyF) 6 Beta, when register_globals is enabled, allows remote attackers to include and execute arbitrary local files via a .. (d…
- CVE-2009-2658HIGHCVSS v2 7.5EG 7.52009-08-04
Directory traversal vulnerability in ZNC before 0.072 allows remote attackers to overwrite arbitrary files via a crafted DCC SEND request.
- CVE-2009-2784HIGHCVSS v2 9.3EG 9.32009-08-17
Multiple directory traversal vulnerabilities in dit.cms 1.3, when register_globals is enabled, allow remote attackers to include and execute arbitrary local files via a .. (dot dot) in the path parameter to index.php in (1) install/, (2) m…
- CVE-2009-2787MEDIUMCVSS v2 6.8EG 6.82009-08-17
Directory traversal vulnerability in include/reputation/rep_profile.php in the Reputation plugin 2.2.4, 2.2.3, 2.0.4, and earlier for PunBB, when register_globals is enabled and magic_quotes_gpc is disabled, allows remote attackers to incl…
- CVE-2009-2792HIGHCVSS v2 7.5EG 7.52009-08-17
Directory traversal vulnerability in plugings/pagecontent.php in Really Simple CMS (RSCMS) 0.3a allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the PT parameter.
- CVE-2009-2922HIGHCVSS v2 7.8EG 7.82009-08-21
Absolute path traversal vulnerability in pixaria.image.php in Pixaria Gallery 2.0.0 through 2.3.5 allows remote attackers to read arbitrary files via a base64-encoded file parameter.
- CVE-2009-2923MEDIUMCVSS v2 5.0EG 5.02009-08-21
Multiple directory traversal vulnerabilities in BitmixSoft PHP-Lance 1.52 allow remote attackers to read arbitrary files via a .. (dot dot) in the (1) language parameter to show.php and (2) in parameter to advanced_search.php.
- CVE-2009-2925HIGHCVSS v2 7.8EG 7.82009-08-21
Directory traversal vulnerability in DJcalendar.cgi in DJCalendar allows remote attackers to read arbitrary files via a .. (dot dot) in the TEMPLATE parameter.
- CVE-2009-2931HIGHCVSS v2 7.8EG 7.82009-08-21
Directory traversal vulnerability in p.php in SlideShowPro Director 1.1 through 1.3.8 allows remote attackers to read arbitrary files via directory traversal sequences in the a parameter.
- CVE-2009-2968MEDIUMCVSS v2 5.0EG 5.02009-09-02
Directory traversal vulnerability in a support component in the web interface in VMware Studio 2.0 public beta before build 1017-185256 allows remote attackers to upload files to arbitrary locations via unspecified vectors.
- CVE-2009-3053MEDIUMCVSS v2 6.8EG 6.82009-09-03
Directory traversal vulnerability in the Agora (com_agora) component 3.0.0b for Joomla! allows remote attackers to include and execute arbitrary local files via directory traversal sequences in the action parameter to the avatars page, rea…
- CVE-2009-3064HIGHCVSS v2 7.5EG 7.52009-09-03
Directory traversal vulnerability in debugger/debug_php.php in Ve-EDIT 0.1.4 allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the _GET[filename] parameter.
- CVE-2009-3123MEDIUMCVSS v2 5.0EG 5.02009-09-09
Directory traversal vulnerability in gallery/gallery.php in Wap-Motor before 18.1 allows remote attackers to read arbitrary files via a .. (dot dot) in the image parameter.
- CVE-2009-3124MEDIUMCVSS v2 5.0EG 5.02009-09-09
Directory traversal vulnerability in get_message.cgi in QuarkMail allows remote attackers to read arbitrary files via a .. (dot dot) in the tf parameter.
- CVE-2009-3149MEDIUMCVSS v2 4.3EG 4.32009-09-10
Directory traversal vulnerability in _css/js.php in Elgg 1.5, when magic_quotes_gpc is disabled, allows remote attackers to read arbitrary files via a .. (dot dot) in the js parameter. NOTE: some of these details are obtained from third p…
- CVE-2009-3151MEDIUMCVSS v2 5.0EG 5.02009-09-10
Directory traversal vulnerability in actions/downloadFile.php in Ultrize TimeSheet 1.2.2 allows remote attackers to read arbitrary files via a .. (dot dot) in the fileName parameter.
Map vulnerabilities like CWE-22 to your infrastructure
EchelonGraph correlates every CVE — across CWE-22 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →