CWE-22 对路径名的限制不恰当(路径遍历) 类弱点 3566 条 CVE 漏洞汇总,含 AI 中文分析。
CWE-22 属于路径遍历漏洞,指程序未正确过滤外部输入中的特殊字符,导致构造的文件路径突破受限目录限制。攻击者常利用“../”等序列访问系统敏感文件,窃取数据或执行恶意操作。开发者应严格校验输入,使用白名单机制限制合法字符,并采用绝对路径或规范化处理,确保最终解析路径始终位于预期目录内,从而有效防御此类风险。
my $dataPath = "/users/cwe/profiles"; my $username = param("user"); my $profilePath = $dataPath . "/" . $username; open(my $fh, "<", $profilePath) || ExitError("profile read error: $profilePath"); print "<ul>\n"; while (<$fh>) { print "<li>$_</li>\n"; } print "</ul>\n";../../../etc/passwdString filename = System.getProperty("com.domain.application.dictionaryFile"); File dictionaryFile = new File(filename);| CVE ID | 标题 | CVSS | 风险等级 | Published |
|---|---|---|---|---|
| CVE-2016-10561 | Bitty 路径遍历漏洞 — bitty node module | 5.3 | - | 2018-05-31 |
| CVE-2014-10068 | inert node模块inert directory handler 信息泄露漏洞 — inert node module | 7.5 | - | 2018-05-29 |
| CVE-2017-16153 | gaoxuyan 路径遍历漏洞 — gaoxuyan node module | 7.5 | - | 2018-05-29 |
| CVE-2018-3733 | crud-file-server node模块路径遍历漏洞 — crud-file-server node module | 6.5 | - | 2018-05-29 |
| CVE-2018-3734 | stattic node模块路径遍历漏洞 — stattic node module | 7.5 | - | 2018-05-29 |
| CVE-2018-0323 | Cisco Enterprise NFV Infrastructure Software 路径遍历漏洞 — Cisco Enterprise NFV Infrastructure Software | 6.5 | - | 2018-05-17 |
| CVE-2018-10589 | 多款Advantech产品路径遍历漏洞 — WebAccess | 9.8 | - | 2018-05-15 |
| CVE-2018-7503 | 多款Advantech产品路径遍历漏洞 — WebAccess | 7.5 | - | 2018-05-15 |
| CVE-2018-0258 | Cisco Prime Data Center Network Manager和Prime Infrastructure 路径遍历漏洞 — Cisco Prime File Upload Servlet | 9.8 | - | 2018-05-02 |
| CVE-2017-6020 | LCDS LTDA ME LAquis SCADA 路径遍历漏洞 — LAquis SCADA software | 5.3 | - | 2018-04-17 |
| CVE-2018-1271 | Pivotal Spring Framework 路径遍历漏洞 — Spring Framework | 5.9 | - | 2018-04-06 |
| CVE-2018-1162 | Quest NetVault Backup 路径遍历漏洞 — Quest NetVault Backup | 8.1 | - | 2018-02-08 |
| CVE-2018-0123 | Cisco IOS和IOS XE Software 路径遍历漏洞 — Cisco IOS and IOS XE | 7.1 | - | 2018-02-08 |
| CVE-2018-5445 | Advantech WebAccess/SCADA 路径遍历漏洞 — Advantech WebAccess/SCADA | 5.3 | - | 2018-01-25 |
| CVE-2018-1048 | Jboss EAP undertow AJP connector 路径遍历漏洞 — undertow as shipped in Jboss EAP 7.1.0.GA | 7.5 | - | 2018-01-24 |
| CVE-2017-16591 | NetGain Enterprise Manager 信息泄露漏洞 — NetGain Systems Enterprise Manager | 6.5 | - | 2018-01-23 |
| CVE-2017-16592 | NetGain Enterprise Manager 信息泄露漏洞 — NetGain Systems Enterprise Manager | 6.5 | - | 2018-01-23 |
| CVE-2017-16593 | NetGain Enterprise Manager 路径遍历漏洞 — NetGain Systems Enterprise Manager | 6.5 | - | 2018-01-23 |
| CVE-2017-16595 | NetGain Enterprise Manager 信息泄露漏洞 — NetGain Systems Enterprise Manager | 6.5 | - | 2018-01-23 |
| CVE-2017-16596 | NetGain Enterprise Manager 信息泄露漏洞 — NetGain Systems Enterprise Manager | 6.5 | - | 2018-01-23 |
| CVE-2017-16597 | NetGain Enterprise Manager 路径遍历漏洞 — NetGain Systems Enterprise Manager | 9.8 | - | 2018-01-23 |
| CVE-2017-16598 | NetGain Enterprise Manager 路径遍历漏洞 — NetGain Systems Enterprise Manager | 8.8 | - | 2018-01-23 |
| CVE-2017-16599 | NetGain Enterprise Manager 路径遍历漏洞 — NetGain Systems Enterprise Manager | 6.5 | - | 2018-01-23 |
| CVE-2017-16600 | NetGain Enterprise Manager 路径遍历漏洞 — NetGain Systems Enterprise Manager | 6.5 | - | 2018-01-23 |
| CVE-2017-16601 | NetGain Enterprise Manager 路径遍历漏洞 — NetGain Systems Enterprise Manager | 6.5 | - | 2018-01-23 |
| CVE-2017-16603 | NetGain Enterprise Manager 路径遍历漏洞 — NetGain Systems Enterprise Manager | 8.8 | - | 2018-01-23 |
| CVE-2017-16604 | NetGain Enterprise Manager 路径遍历漏洞 — NetGain Systems Enterprise Manager | 6.5 | - | 2018-01-23 |
| CVE-2017-16605 | NetGain Enterprise Manager 路径遍历漏洞 — NetGain Systems Enterprise Manager | 6.5 | - | 2018-01-23 |
| CVE-2017-16606 | NetGain Enterprise Manager 路径遍历漏洞 — NetGain Systems Enterprise Manager | 8.8 | - | 2018-01-23 |
| CVE-2017-16610 | Netgain Enterprise Manager 安全漏洞 — NetGain Systems Enterprise Manager | 9.8 | - | 2018-01-23 |
CWE-22(对路径名的限制不恰当(路径遍历)) 是常见的弱点类别,本平台收录该类弱点关联的 3566 条 CVE 漏洞。