3485 vulnerabilities classified as CWE-22 (对路径名的限制不恰当(路径遍历)). AI Chinese analysis included.
CWE-22 represents a critical input validation weakness where software fails to properly sanitize external input before constructing file paths. Attackers typically exploit this vulnerability by injecting directory traversal sequences, such as “../”, into user-supplied parameters. These malicious inputs allow the application to resolve file references outside the intended restricted directory, potentially granting unauthorized access to sensitive system files, configuration data, or source code. To mitigate this risk, developers must implement rigorous input validation techniques, ensuring that all path components are strictly checked against allowed characters and structures. Additionally, employing canonicalization to resolve symbolic links and relative paths before validation, combined with strict chroot jails or sandboxing, effectively confines file operations to designated directories, thereby neutralizing the potential for path traversal attacks and preserving system integrity.
my $dataPath = "/users/cwe/profiles"; my $username = param("user"); my $profilePath = $dataPath . "/" . $username; open(my $fh, "<", $profilePath) || ExitError("profile read error: $profilePath"); print "<ul>\n"; while (<$fh>) { print "<li>$_</li>\n"; } print "</ul>\n";../../../etc/passwdString filename = System.getProperty("com.domain.application.dictionaryFile"); File dictionaryFile = new File(filename);| CVE ID | Title | CVSS | Severity | Published |
|---|---|---|---|---|
| CVE-2020-15641 | Marvell QConvergeConsole 路径遍历漏洞 — QConvergeConsole | 7.5 | - | 2020-08-25 |
| CVE-2020-15643 | Marvell QConvergeConsole 路径遍历漏洞 — QConvergeConsole | 8.8 | - | 2020-08-25 |
| CVE-2020-15639 | Marvell QConvergeConsole 路径遍历漏洞 — QConvergeConsole | 9.8 | - | 2020-08-25 |
| CVE-2020-15640 | Marvell QConvergeConsole 路径遍历漏洞 — QConvergeConsole | 7.5 | - | 2020-08-25 |
| CVE-2020-16245 | Advantech iView 路径遍历漏洞 — Advantech iView | 9.8 | - | 2020-08-25 |
| CVE-2020-8227 | Nextcloud 路径遍历漏洞 — Desktop Client | 6.5 | - | 2020-08-21 |
| CVE-2020-8209 | Citrix Systems XenMobile Server 路径遍历漏洞 — Citrix XenMobile Server | 7.5 | - | 2020-08-17 |
| CVE-2020-15141 | Path Traversal in openapi-python-client — openapi-python-client | 3.0 | Low | 2020-08-14 |
| CVE-2020-8221 | Pulse Secure Pulse Connect Secure 路径遍历漏洞 — Pulse Connect Secure | 4.9 | - | 2020-07-30 |
| CVE-2020-8222 | Pulse Secure Pulse Connect Secure 路径遍历漏洞 — Pulse Connect Secure | 6.8 | - | 2020-07-30 |
| CVE-2020-14490 | OpenClinic GA — OpenClinic GA | 8.8 | High | 2020-07-29 |
| CVE-2020-5377 | Dell EMC OpenManage Server Administrator 路径遍历漏洞 — Dell Open Manage Server Administrator | 9.1 | Critical | 2020-07-28 |
| CVE-2020-15124 | Path traversal in Goobi viewer Core — goobi-viewer-core | 9.6 | Critical | 2020-07-22 |
| CVE-2016-7063 | Pritunl-client 路径遍历漏洞 — pritunl-client-electron | 8.8 | - | 2020-07-21 |
| CVE-2020-12499 | PHOENIX CONTACT PLCnext Engineer version 2020.3.1 and earlier: Improper path sanitation vulnerability. — PLCnext Engineer | 8.2 | High | 2020-07-21 |
| CVE-2020-8214 | servey 路径遍历漏洞 — servey | 7.5 | - | 2020-07-20 |
| CVE-2020-3401 | Cisco SD-WAN vManage Software Path Traversal Vulnerability — Cisco SD-WAN vManage | 6.5 | - | 2020-07-16 |
| CVE-2020-3381 | Cisco SD-WAN vManage Software Directory Traversal Vulnerability — Cisco SD-WAN vManage | 8.1 | - | 2020-07-16 |
| CVE-2020-14507 | Advantech iView 路径遍历漏洞 — Advantech iView | 9.8 | - | 2020-07-15 |
| CVE-2020-5366 | Dell EMC iDRAC9 路径遍历漏洞 — Integrated Dell Remote Access Controller (iDRAC) | 7.1 | High | 2020-07-09 |
| CVE-2020-3241 | Cisco UCS Director Path Traversal Vulnerability — Cisco Unified Computing System (Management Software) | 6.5 | - | 2020-06-18 |
| CVE-2020-3236 | Cisco Enterprise NFV Infrastructure Software Path Traversal Vulnerability — Cisco Enterprise NFV Infrastructure Software | 6.7 | - | 2020-06-18 |
| CVE-2020-4053 | Path Traversal in Helm Plugin Archive — Helm | 3.7 | Low | 2020-06-16 |
| CVE-2020-7497 | Schneider Electric EcoStruxure Operator Terminal Expert 路径遍历漏洞 — EcoStruxure Operator Terminal Expert 3.1 Service Pack 1 and prior (formerly known as Vijeo XD) | 9.8 | - | 2020-06-16 |
| CVE-2020-7495 | Schneider Electric EcoStruxure Operator Terminal Expert 路径遍历漏洞 — EcoStruxure Operator Terminal Expert 3.1 Service Pack 1 and prior (formerly known as Vijeo XD) | 5.5 | - | 2020-06-16 |
| CVE-2020-7494 | Schneider Electric EcoStruxure Operator Terminal Expert 路径遍历漏洞 — EcoStruxure Operator Terminal Expert 3.1 Service Pack 1 and prior (formerly known as Vijeo XD) | 7.8 | - | 2020-06-16 |
| CVE-2020-12003 | 多款Rockwell Automation产品路径遍历漏洞 — FactoryTalk Linx, RSLinx Classic, Connected Components Workbench, ControlFLASH Plus, FactoryTalk Asset Centre, FactoryTalk Linx CommDTM, Studio 5000 Launcher, Studio 5000 Logix Designer software | 7.5 | - | 2020-06-15 |
| CVE-2020-6110 | Zoom Client 路径遍历漏洞 — Zoom | 8.8 | - | 2020-06-08 |
| CVE-2020-6109 | Zoom Client 路径遍历漏洞 — Zoom | 9.8 | - | 2020-06-08 |
| CVE-2020-8159 | actionpack_page-caching gem 路径遍历漏洞 — https://github.com/rails/actionpack-page_caching | 9.8 | - | 2020-05-12 |
Vulnerabilities classified as CWE-22 (对路径名的限制不恰当(路径遍历)) represent 3485 CVEs. The CWE taxonomy describes the weakness; review individual CVEs for product-specific impact.