3432 vulnerabilities classified as CWE-22 (对路径名的限制不恰当(路径遍历)). AI Chinese analysis included.
CWE-22 represents a critical input validation weakness where software fails to properly sanitize external input before constructing file paths. Attackers typically exploit this vulnerability by injecting directory traversal sequences, such as “../”, into user-supplied parameters. These malicious inputs allow the application to resolve file references outside the intended restricted directory, potentially granting unauthorized access to sensitive system files, configuration data, or source code. To mitigate this risk, developers must implement rigorous input validation techniques, ensuring that all path components are strictly checked against allowed characters and structures. Additionally, employing canonicalization to resolve symbolic links and relative paths before validation, combined with strict chroot jails or sandboxing, effectively confines file operations to designated directories, thereby neutralizing the potential for path traversal attacks and preserving system integrity.
my $dataPath = "/users/cwe/profiles"; my $username = param("user"); my $profilePath = $dataPath . "/" . $username; open(my $fh, "<", $profilePath) || ExitError("profile read error: $profilePath"); print "<ul>\n"; while (<$fh>) { print "<li>$_</li>\n"; } print "</ul>\n";../../../etc/passwdString filename = System.getProperty("com.domain.application.dictionaryFile"); File dictionaryFile = new File(filename);| CVE ID | Title | CVSS | Severity | Published |
|---|---|---|---|---|
| CVE-2018-3715 | glance 路径遍历漏洞 — glance node module | 6.5 | - | 2018-06-07 |
| CVE-2018-3724 | hekto node模块路径遍历漏洞 — general-file-server node module | 7.5 | - | 2018-06-07 |
| CVE-2018-3725 | hekto node模块路径遍历漏洞 — hekto node module | 7.5 | - | 2018-06-07 |
| CVE-2018-3727 | 626 node module 路径遍历漏洞 — 626 node module | 7.5 | - | 2018-06-07 |
| CVE-2018-3729 | mcstatic node module 路径遍历漏洞 — localhost-now node module | 6.5 | - | 2018-06-07 |
| CVE-2018-3730 | mcstatic node module 路径遍历漏洞 — mcstatic node module | 7.5 | - | 2018-06-07 |
| CVE-2018-3731 | public node模块路径遍历漏洞 — public node module | 7.5 | - | 2018-06-07 |
| CVE-2018-3732 | resolve-path 路径遍历漏洞 — resolve-path node module | 6.5 | - | 2018-06-07 |
| CVE-2017-0930 | augustine 路径遍历漏洞 — augustine node module | 6.5 | - | 2018-06-04 |
| CVE-2017-16029 | hostr 路径遍历漏洞 — hostr node module | 7.5 | - | 2018-06-04 |
| CVE-2017-16036 | badjs-sourcemap-server 路径遍历漏洞 — badjs-sourcemap-server node module | 7.5 | - | 2018-06-04 |
| CVE-2017-16037 | gomeplus-h5-proxy 路径遍历漏洞 — gomeplus-h5-proxy node module | 7.5 | - | 2018-06-04 |
| CVE-2017-16039 | hftp 路径遍历漏洞 — hftp node module | 7.5 | - | 2018-06-04 |
| CVE-2014-10066 | fancy-server 路径遍历漏洞 — fancy-server node module | 7.5 | - | 2018-05-31 |
| CVE-2016-10528 | Restafary 路径遍历漏洞 — restafary node module | 9.1 | - | 2018-05-31 |
| CVE-2016-10538 | node-cli 安全漏洞 — cli node module | 5.7 | - | 2018-05-31 |
| CVE-2016-10561 | Bitty 路径遍历漏洞 — bitty node module | 5.3 | - | 2018-05-31 |
| CVE-2014-10068 | inert node模块inert directory handler 信息泄露漏洞 — inert node module | 7.5 | - | 2018-05-29 |
| CVE-2017-16153 | gaoxuyan 路径遍历漏洞 — gaoxuyan node module | 7.5 | - | 2018-05-29 |
| CVE-2018-3733 | crud-file-server node模块路径遍历漏洞 — crud-file-server node module | 6.5 | - | 2018-05-29 |
| CVE-2018-3734 | stattic node模块路径遍历漏洞 — stattic node module | 7.5 | - | 2018-05-29 |
| CVE-2018-0323 | Cisco Enterprise NFV Infrastructure Software 路径遍历漏洞 — Cisco Enterprise NFV Infrastructure Software | 6.5 | - | 2018-05-17 |
| CVE-2018-10589 | 多款Advantech产品路径遍历漏洞 — WebAccess | 9.8 | - | 2018-05-15 |
| CVE-2018-7503 | 多款Advantech产品路径遍历漏洞 — WebAccess | 7.5 | - | 2018-05-15 |
| CVE-2018-0258 | Cisco Prime Data Center Network Manager和Prime Infrastructure 路径遍历漏洞 — Cisco Prime File Upload Servlet | 9.8 | - | 2018-05-02 |
| CVE-2017-6020 | LCDS LTDA ME LAquis SCADA 路径遍历漏洞 — LAquis SCADA software | 5.3 | - | 2018-04-17 |
| CVE-2018-1271 | Pivotal Spring Framework 路径遍历漏洞 — Spring Framework | 5.9 | - | 2018-04-06 |
| CVE-2018-1162 | Quest NetVault Backup 路径遍历漏洞 — Quest NetVault Backup | 8.1 | - | 2018-02-08 |
| CVE-2018-0123 | Cisco IOS和IOS XE Software 路径遍历漏洞 — Cisco IOS and IOS XE | 7.1 | - | 2018-02-08 |
| CVE-2018-5445 | Advantech WebAccess/SCADA 路径遍历漏洞 — Advantech WebAccess/SCADA | 5.3 | - | 2018-01-25 |
Vulnerabilities classified as CWE-22 (对路径名的限制不恰当(路径遍历)) represent 3432 CVEs. The CWE taxonomy describes the weakness; review individual CVEs for product-specific impact.