3432 vulnerabilities classified as CWE-22 (对路径名的限制不恰当(路径遍历)). AI Chinese analysis included.
CWE-22 represents a critical input validation weakness where software fails to properly sanitize external input before constructing file paths. Attackers typically exploit this vulnerability by injecting directory traversal sequences, such as “../”, into user-supplied parameters. These malicious inputs allow the application to resolve file references outside the intended restricted directory, potentially granting unauthorized access to sensitive system files, configuration data, or source code. To mitigate this risk, developers must implement rigorous input validation techniques, ensuring that all path components are strictly checked against allowed characters and structures. Additionally, employing canonicalization to resolve symbolic links and relative paths before validation, combined with strict chroot jails or sandboxing, effectively confines file operations to designated directories, thereby neutralizing the potential for path traversal attacks and preserving system integrity.
my $dataPath = "/users/cwe/profiles"; my $username = param("user"); my $profilePath = $dataPath . "/" . $username; open(my $fh, "<", $profilePath) || ExitError("profile read error: $profilePath"); print "<ul>\n"; while (<$fh>) { print "<li>$_</li>\n"; } print "</ul>\n";../../../etc/passwdString filename = System.getProperty("com.domain.application.dictionaryFile"); File dictionaryFile = new File(filename);| CVE ID | Title | CVSS | Severity | Published |
|---|---|---|---|---|
| CVE-2018-1048 | Jboss EAP undertow AJP connector 路径遍历漏洞 — undertow as shipped in Jboss EAP 7.1.0.GA | 7.5 | - | 2018-01-24 |
| CVE-2017-16591 | NetGain Enterprise Manager 信息泄露漏洞 — NetGain Systems Enterprise Manager | 6.5 | - | 2018-01-23 |
| CVE-2017-16592 | NetGain Enterprise Manager 信息泄露漏洞 — NetGain Systems Enterprise Manager | 6.5 | - | 2018-01-23 |
| CVE-2017-16593 | NetGain Enterprise Manager 路径遍历漏洞 — NetGain Systems Enterprise Manager | 6.5 | - | 2018-01-23 |
| CVE-2017-16595 | NetGain Enterprise Manager 信息泄露漏洞 — NetGain Systems Enterprise Manager | 6.5 | - | 2018-01-23 |
| CVE-2017-16596 | NetGain Enterprise Manager 信息泄露漏洞 — NetGain Systems Enterprise Manager | 6.5 | - | 2018-01-23 |
| CVE-2017-16597 | NetGain Enterprise Manager 路径遍历漏洞 — NetGain Systems Enterprise Manager | 9.8 | - | 2018-01-23 |
| CVE-2017-16598 | NetGain Enterprise Manager 路径遍历漏洞 — NetGain Systems Enterprise Manager | 8.8 | - | 2018-01-23 |
| CVE-2017-16599 | NetGain Enterprise Manager 路径遍历漏洞 — NetGain Systems Enterprise Manager | 6.5 | - | 2018-01-23 |
| CVE-2017-16600 | NetGain Enterprise Manager 路径遍历漏洞 — NetGain Systems Enterprise Manager | 6.5 | - | 2018-01-23 |
| CVE-2017-16601 | NetGain Enterprise Manager 路径遍历漏洞 — NetGain Systems Enterprise Manager | 6.5 | - | 2018-01-23 |
| CVE-2017-16603 | NetGain Enterprise Manager 路径遍历漏洞 — NetGain Systems Enterprise Manager | 8.8 | - | 2018-01-23 |
| CVE-2017-16604 | NetGain Enterprise Manager 路径遍历漏洞 — NetGain Systems Enterprise Manager | 6.5 | - | 2018-01-23 |
| CVE-2017-16605 | NetGain Enterprise Manager 路径遍历漏洞 — NetGain Systems Enterprise Manager | 6.5 | - | 2018-01-23 |
| CVE-2017-16606 | NetGain Enterprise Manager 路径遍历漏洞 — NetGain Systems Enterprise Manager | 8.8 | - | 2018-01-23 |
| CVE-2017-16610 | Netgain Enterprise Manager 安全漏洞 — NetGain Systems Enterprise Manager | 9.8 | - | 2018-01-23 |
| CVE-2017-16720 | Advantech WebAccess 路径遍历漏洞 — Advantech WebAccess | 5.3 | - | 2018-01-05 |
| CVE-2017-15893 | Synology File Station 路径遍历漏洞 — Synology File Station | 6.5 | - | 2017-12-08 |
| CVE-2017-15894 | Synology DiskStation Manager 路径遍历漏洞 — Synology DiskStation Manager (DSM) | 6.5 | - | 2017-12-08 |
| CVE-2017-15895 | Synology Router Manager 路径遍历漏洞 — Synology Router Manager (SRM) | 6.5 | - | 2017-12-08 |
| CVE-2017-11511 | ZOHO ManageEngine ServiceDesk 安全漏洞 — ManageEngine ServiceDesk | 7.5 | - | 2017-11-08 |
| CVE-2017-11512 | ZOHO ManageEngine ServiceDesk 安全漏洞 — ManageEngine ServiceDesk | 7.5 | - | 2017-11-08 |
| CVE-2017-10940 | Joyent Smart Data Center 安全漏洞 — Joyent Smart Data Center | 8.8 | - | 2017-10-31 |
| CVE-2017-12263 | Cisco License Manager software 路径遍历漏洞 — Cisco License Manager | 7.5 | - | 2017-10-05 |
| CVE-2017-11162 | Synology Photo Station 路径遍历漏洞 — Synology Photo Station | 6.5 | - | 2017-09-08 |
| CVE-2017-0901 | RubyGems 安全漏洞 — RubyGems | 7.5 | - | 2017-08-31 |
| CVE-2017-12694 | iniNet Solutions SpiderControl SCADA Web Server 路径遍历漏洞 — SpiderControl SCADA Web Server | 7.5 | - | 2017-08-25 |
| CVE-2017-9640 | ALC WebCTRL、i-Vu和SiteScan Web 路径遍历漏洞 — Automated Logic Corporation WebCTRL, i-VU, SiteScan | 8.3 | - | 2017-08-25 |
| CVE-2017-12074 | Synology DNS Server 路径遍历漏洞 — Synology DNS Server | 6.5 | - | 2017-08-24 |
| CVE-2017-7424 | Micro Focus Enterprise Developer和Enterprise Server 路径遍历漏洞 — Micro Focus Enterprise Developer, Micro Focus Enterprise Server | 6.5 | - | 2017-08-21 |
Vulnerabilities classified as CWE-22 (对路径名的限制不恰当(路径遍历)) represent 3432 CVEs. The CWE taxonomy describes the weakness; review individual CVEs for product-specific impact.