CWE-22— Path Traversal
The product uses external input to construct a pathname that is intended to identify a file or directory that is located underneath a restricted parent directory, but the product does not properly neutralize special elements within the pathname that can cause the pathname to resolve to a location that is outside of the restricted directory.— MITRE CWE catalog
9,439 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-22page 19 of 189
- CVE-2009-4261HIGHCVSS v2 7.5EG 7.52009-12-21
Multiple directory traversal vulnerabilities in the iallocator framework in Ganeti 1.2.4 through 1.2.8, 2.0.0 through 2.0.4, and 2.1.0 before 2.1.0~rc2 allow (1) remote attackers to execute arbitrary programs via a crafted external script …
- CVE-2009-4315MEDIUMCVSS v2 6.8EG 6.82009-12-14
Directory traversal vulnerability in admin/ajaxsave.php in Nuggetz CMS 1.0, when magic_quotes_gpc is disabled, allows remote attackers to create or modify arbitrary files via a .. (dot dot) in the nugget parameter and a modified pagevalue …
- CVE-2009-4374HIGHCVSS v2 7.5EG 7.52009-12-21
Directory traversal vulnerability in repository/repository_attachment.php in AlienVault Open Source Security Information Management (OSSIM) 2.1.5, and possibly other versions before 2.1.5-4, allows remote attackers to upload files into arb…
- CVE-2009-4383MEDIUMCVSS v2 5.0EG 5.02009-12-22
Directory traversal vulnerability in Pforum.php in Rocomotion P forum before 1.28 allows remote attackers to read arbitrary files via directory traversal sequences in unspecified vectors.
- CVE-2009-4415HIGHCVSS v2 7.5EG 7.52009-12-24
Multiple directory traversal vulnerabilities in phpGroupWare 0.9.16.12, and possibly other versions before 0.9.16.014, allow remote attackers to (1) read arbitrary files via the csvfile parameter to addressbook/csv_import.php, or (2) inclu…
- CVE-2009-4421MEDIUMCVSS v2 6.5EG 6.52009-12-24
Directory traversal vulnerability in languages_cgi.php in Simple PHP Blog 0.5.1 and earlier allows remote authenticated users to include and execute arbitrary local files via a .. (dot dot) in the blog_language1 parameter.
- CVE-2009-4426MEDIUMCVSS v2 6.8EG 6.82009-12-28
Multiple directory traversal vulnerabilities in Ignition 1.2, when magic_quotes_gpc is disabled, allow remote attackers to include and execute arbitrary local files via a .. (dot dot) in the blog parameter to (1) comment.php and (2) view.p…
- CVE-2009-4427HIGHCVSS v2 7.5EG 7.52009-12-28
Directory traversal vulnerability in cmd.php in phpLDAPadmin 1.1.0.5 allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the cmd parameter.
- CVE-2009-4434MEDIUMCVSS v2 5.0EG 5.02009-12-28
Directory traversal vulnerability in index.php in IDevSpot iSupport 1.8 and earlier allows remote attackers to read arbitrary files via a .. (dot dot) in the include_file parameter.
- CVE-2009-4435MEDIUMCVSS v2 6.8EG 6.82009-12-28
Multiple directory traversal vulnerabilities in F3Site 2009 allow remote attackers to include and execute arbitrary local files via directory traversal sequences in the GLOBALS[nlang] parameter to (1) mod/poll.php and (2) mod/new.php.
- CVE-2009-4449MEDIUMCVSS 6.5EG 6.52009-12-29
Directory traversal vulnerability in MyBB (aka MyBulletinBoard) 1.4.10, and possibly earlier versions, when changing the user avatar from the gallery, allows remote authenticated users to determine the existence of files via directory trav…
- CVE-2009-4512MEDIUMCVSS v2 5.1EG 5.12009-12-31
Directory traversal vulnerability in index.php in Oscailt 3.3, when Use Friendly URL's is disabled, allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the obj_id parameter.
- CVE-2009-4626HIGHCVSS v2 7.5EG 7.52010-01-18
Directory traversal vulnerability in menu.php in phpNagios 1.2.0 allows remote attackers to include and execute arbitrary local files via directory traversal sequences in the conf[lang] parameter.
- CVE-2009-4627MEDIUMCVSS v2 5.0EG 5.02010-01-18
Directory traversal vulnerability in sources/_template_parser.php in Moa Gallery 1.2.0 and earlier allows remote attackers to read arbitrary files via a .. (dot dot) in the p_filename parameter, a different issue than CVE-2009-4614.
- CVE-2009-4645HIGHCVSS v2 7.8EG 7.82010-02-19
Directory traversal vulnerability in web_client_user_guide.html in Accellion Secure File Transfer Appliance before 8_0_105 allows remote attackers to read arbitrary files via a .. (dot dot) in the lang parameter.
- CVE-2009-4672HIGHCVSS v2 7.5EG 7.52010-03-05
Directory traversal vulnerability in main.php in the WP-Lytebox plugin 1.3 for WordPress allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the pg parameter.
- CVE-2009-4679HIGHCVSS v2 7.5EG 7.52010-03-08
Directory traversal vulnerability in the inertialFATE iF Portfolio Nexus (com_if_nexus) component 1.5 for Joomla! allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the controller parameter to index.…
- CVE-2009-4683HIGHCVSS v2 7.5EG 7.52010-03-10
Directory traversal vulnerability in vote.php in Good/Bad Vote allows remote attackers to include and execute arbitrary local files via directory traversal sequences in the id parameter in a dovote action. NOTE: some of these details are o…
- CVE-2009-4700MEDIUMCVSS v2 5.0EG 5.02010-03-15
Directory traversal vulnerability in index.php in SkaDate Dating allows remote attackers to read arbitrary files via a .. (dot dot) in the layout parameter.
- CVE-2009-4723HIGHCVSS v2 7.5EG 7.52010-03-18
Directory traversal vulnerability in confirm.php in Netpet CMS 1.9 allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the language parameter.
- CVE-2009-4725MEDIUMCVSS v2 5.1EG 5.12010-03-18
Directory traversal vulnerability in modules/aljazeera/admin/setup.php in Arab Portal 2.2 and earlier, when register_globals is enabled and magic_quotes_gpc is disabled, allows remote attackers to include and execute arbitrary local files …
- CVE-2009-4726MEDIUMCVSS v2 5.0EG 5.02010-03-18
Directory traversal vulnerability in download.php in Quickdev 4 PHP allows remote attackers to read arbitrary files via a .. (dot dot) in the file parameter.
- CVE-2009-4740HIGHCVSS v2 7.5EG 7.52010-03-26
Directory traversal vulnerability in the Webesse E-Card (ws_ecard) extension 1.0.2 and earlier for TYPO3 has unspecified impact and remote attack vectors.
- CVE-2009-4790HIGHCVSS v2 9.0EG 9.02010-04-22
Multiple directory traversal vulnerabilities in Sysax Multi Server 4.5 allow remote authenticated users to read or modify arbitrary files via crafted FTP commands. NOTE: the provenance of this information is unknown; the details are obtai…
- CVE-2009-4800MEDIUMCVSS v2 4.0EG 4.02010-04-22
Directory traversal vulnerability in Sysax Multi Server 4.3 and 4.5 allows remote authenticated users to delete arbitrary files via a ..// (dot dot slash slash) in a DELE command.
- CVE-2009-4809MEDIUMCVSS v2 5.0EG 5.02010-04-23
Directory traversal vulnerability in thumbnail.ghp in Easy File Sharing (EFS) Web Server 4.8 allows remote attackers to read arbitrary files via a .. (dot dot) in the vfolder parameter.
- CVE-2009-4815MEDIUMCVSS v2 4.0EG 4.02010-04-27
Directory traversal vulnerability in Serv-U before 9.2.0.1 allows remote authenticated users to read arbitrary files via unspecified vectors.
- CVE-2009-4816MEDIUMCVSS v2 5.0EG 5.02010-04-27
Directory traversal vulnerability in api/download_checker.php in MegaLab The Uploader 2.0 allows remote attackers to read arbitrary files via a .. (dot dot) in the filename parameter.
- CVE-2009-4886MEDIUMCVSS v2 5.0EG 5.02010-06-11
Multiple directory traversal vulnerabilities in phpCommunity 2 2.1.8 allow remote attackers to read arbitrary files via a .. (dot dot) in the (1) file parameter to module/admin/files/show_file.php and the (2) path parameter to module/admin…
- CVE-2009-4896MEDIUMCVSS v2 6.5EG 6.52010-08-02
Multiple directory traversal vulnerabilities in the mlmmj-php-admin web interface for Mailing List Managing Made Joyful (mlmmj) 1.2.15 through 1.2.17 allow remote authenticated users to overwrite, create, or delete arbitrary files, or dete…
- CVE-2009-4946MEDIUMCVSS v2 6.8EG 6.82010-07-22
Directory traversal vulnerability in the Messaging (com_messaging) component before 1.5.1 for Joomla! allows remote attackers to include and execute arbitrary local files via directory traversal sequences in the controller parameter in a m…
- CVE-2009-4952HIGHCVSS v2 10.0EG 10.02010-07-22
Directory traversal vulnerability in the Directory Listing (dir_listing) extension 1.1.0 and earlier for TYPO3 allows remote attackers to have an unspecified impact via unknown vectors.
- CVE-2009-4957HIGHCVSS v2 7.5EG 7.52010-07-22
Directory traversal vulnerability in loadpanel.php in Interspire ActiveKB allows remote attackers to read arbitrary files and possibly have unspecified other impact via directory traversal sequences in the Panel parameter.
- CVE-2009-4960MEDIUMCVSS v2 5.0EG 5.02010-07-28
Directory traversal vulnerability in modules/backup/download.php in Lanai Core 0.6 allows remote attackers to read arbitrary files via a .. (dot dot) in the f parameter.
- CVE-2009-4974HIGHCVSS v2 7.5EG 7.52010-07-28
Directory traversal vulnerability in box_display.php in TotalCalendar 2.4 allows remote attackers to read arbitrary files and possibly have unspecified other impact via a .. (dot dot) in the box parameter.
- CVE-2009-4978MEDIUMCVSS v2 5.0EG 5.02010-08-25
Directory traversal vulnerability in down.php in MyBackup 1.4.0 allows remote attackers to read arbitrary files via a .. (dot dot) in the filename parameter.
- CVE-2009-4986MEDIUMCVSS v2 6.8EG 6.82010-08-25
Directory traversal vulnerability in index.php in In-Portal 4.3.1, when magic_quotes_gpc is disabled, allows remote attackers to read arbitrary files via a .. (dot dot) in the env parameter.
- CVE-2009-5067MEDIUMCVSS v2 4.3EG 4.32012-10-10
Directory traversal vulnerability in html2ps before 1.0b6 allows remote attackers to read arbitrary files via a .. (dot dot) in the "include file" SSI directive. NOTE: this issue only might be a vulnerability in limited scenarios, such as…
- CVE-2009-5087MEDIUMCVSS v2 5.0EG 5.02011-09-12
Directory traversal vulnerability in geohttpserver in Geovision Digital Video Surveillance System 8.2 allows remote attackers to read arbitrary files via a .. (dot dot) in a GET request.
- CVE-2009-5089MEDIUMCVSS v2 4.3EG 4.32011-09-12
Directory traversal vulnerability in index.php in IdeaCart 0.02 and 0.02a allows remote attackers to read arbitrary files via a .. (dot dot) in the page parameter.
- CVE-2009-5093MEDIUMCVSS v2 5.0EG 5.02011-09-12
Directory traversal vulnerability in gastbuch.php in Gästebuch (Gastebuch) 1.6 allows remote attackers to read arbitrary files via a .. (dot dot) in the start parameter.
- CVE-2009-5114MEDIUMCVSS v2 5.0EG 5.02012-03-19
Directory traversal vulnerability in wgarcmin.cgi in WebGlimpse 2.18.7 and earlier allows remote attackers to read arbitrary files via a .. (dot dot) in the DOC parameter.
- CVE-2010-0012HIGHCVSS 8.8EG 8.82010-01-08
Directory traversal vulnerability in libtransmission/metainfo.c in Transmission 1.22, 1.34, 1.75, and 1.76 allows remote attackers to overwrite arbitrary files via a .. (dot dot) in a pathname within a .torrent file.
- CVE-2010-0013HIGHCVSS 7.5EG 7.52010-01-09
Directory traversal vulnerability in slp.c in the MSN protocol plugin in libpurple in Pidgin 2.6.4 and Adium 1.3.8 allows remote attackers to read arbitrary files via a .. (dot dot) in an application/x-msnmsgrp2p MSN emoticon (aka custom s…
- CVE-2010-0146MEDIUMCVSS v2 6.8EG 6.82010-02-23
Directory traversal vulnerability in the Management Center for Cisco Security Agents 6.0 allows remote authenticated users to read arbitrary files via unspecified vectors.
- CVE-2010-0154MEDIUMCVSS v2 4.0EG 4.02010-09-14
Directory traversal vulnerability in sla/index.php in the Local Management Interface (LMI) on the IBM Proventia Network Mail Security System (PNMSS) appliance with firmware before 2.5 allows remote authenticated users to read arbitrary fil…
- CVE-2010-0157HIGHCVSS v2 7.5EG 7.52010-01-06
Directory traversal vulnerability in the Bible Study (com_biblestudy) component 6.1 for Joomla! allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the controller parameter in a studieslist action to …
- CVE-2010-0284HIGHCVSS v2 10.0EG 10.02010-06-18
Directory traversal vulnerability in the getEntry method in the PortalModuleInstallManager component in a servlet in nps.jar in the Administration Console (aka Access Management Console) in Novell Access Manager 3.1 before 3.1.2-281 on Win…
- CVE-2010-0287MEDIUMCVSS v2 5.0EG 5.02010-02-15
Directory traversal vulnerability in the ACL Manager plugin (plugins/acl/ajax.php) in DokuWiki before 2009-12-25b allows remote attackers to list the contents of arbitrary directories via a .. (dot dot) in the ns parameter.
- CVE-2010-0348MEDIUMCVSS v2 5.0EG 5.02010-01-15
Directory traversal vulnerability in C3 Corp. WebCalenderC3 0.32 and earlier allows remote attackers to read arbitrary files via unknown vectors.
Map vulnerabilities like CWE-22 to your infrastructure
EchelonGraph correlates every CVE — across CWE-22 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →