VYPR

CWE-22

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')

BaseStableLikelihood: High

Description

The product uses external input to construct a pathname that is intended to identify a file or directory that is located underneath a restricted parent directory, but the product does not properly neutralize special elements within the pathname that can cause the pathname to resolve to a location that is outside of the restricted directory.

Hierarchy (View 1000)

Parents

Children

Related attack patterns (CAPEC)

CAPEC-126 · CAPEC-64 · CAPEC-76 · CAPEC-78 · CAPEC-79

CVEs mapped to this weakness (10,395)

page 100 of 520
  • CVE-2020-8209HigAug 17, 2020
    risk 0.53cvss 7.5epss 0.49

    Improper access control in Citrix XenMobile Server 10.12 before RP2, Citrix XenMobile Server 10.11 before RP4, Citrix XenMobile Server 10.10 before RP6 and Citrix XenMobile Server before 10.9 RP5 and leads to the ability to read arbitrary files.

  • CVE-2020-12499HigJul 21, 2020
    risk 0.53cvss 8.2epss 0.00

    In PHOENIX CONTACT PLCnext Engineer version 2020.3.1 and earlier an improper path sanitation vulnerability exists on import of project files.

  • CVE-2020-13158HigJun 22, 2020
    risk 0.53cvss 7.5epss 0.54

    Artica Proxy before 4.30.000000 Community Edition allows Directory Traversal via the fw.progrss.details.php popup parameter.

  • CVE-2020-5590HigJun 19, 2020
    risk 0.53cvss 8.1epss 0.02

    Directory traversal vulnerability in EC-CUBE 3.0.0 to 3.0.18 and 4.0.0 to 4.0.3 allows remote authenticated attackers to delete arbitrary files and/or directories on the server via unspecified vectors.

  • CVE-2020-12851HigJun 4, 2020
    risk 0.53cvss 8.1epss 0.01

    Pydio Cells 2.0.4 allows an authenticated user to write or overwrite existing files in another user’s personal and cells folders (repositories) by uploading a custom generated ZIP file and leveraging the file extraction feature present in the web application. The extracted…

  • CVE-2020-8810HigFeb 25, 2020
    risk 0.53cvss 8.1epss 0.02

    An issue was discovered in Gurux GXDLMS Director through 8.5.1905.1301. When downloading OBIS codes, it does not verify that the downloaded files are actual OBIS codes and doesn't check for path traversal. This allows the attacker exploiting CVE-2020-8809 to send executable…

  • CVE-2013-2474HigJan 27, 2020
    risk 0.53cvss 7.5epss 0.10

    Directory traversal vulnerability in AWS XMS 2.5 allows remote attackers to view arbitrary files via the 'what' parameter.

  • CVE-2019-7751HigDec 31, 2019
    risk 0.53cvss 7.5epss 0.14

    A directory traversal and local file inclusion vulnerability in FPProducerInternetServer.exe in Ricoh MarcomCentral, formerly PTI Marketing, FusionPro VDP before 10.0 allows a remote attacker to list or enumerate sensitive contents of files. Furthermore, this could allow for…

  • CVE-2019-19731HigDec 16, 2019
    risk 0.53cvss 7.5epss 0.12

    Roxy Fileman 1.4.5 for .NET is vulnerable to path traversal. A remote attacker can write uploaded files to arbitrary locations via the RENAMEFILE action. This can be leveraged for code execution by uploading a specially crafted Windows shortcut file and writing the file to the…

  • CVE-2019-16758HigNov 21, 2019
    risk 0.53cvss 7.5epss 0.17

    In Lexmark Services Monitor 2.27.4.0.39 (running on TCP port 2070), a remote attacker can use a directory traversal technique using /../../../ or ..%2F..%2F..%2F to obtain local files on the host operating system.

  • CVE-2019-18951HigNov 13, 2019
    risk 0.53cvss 7.5epss 0.20

    SibSoft Xfilesharing through 2.5.1 allows op=page&tmpl=../ directory traversal to read arbitrary files.

  • CVE-2019-18371HigOct 23, 2019
    risk 0.53cvss 7.5epss 0.56

    An issue was discovered on Xiaomi Mi WiFi R3G devices before 2.28.23-stable. There is a directory traversal vulnerability to read arbitrary files via a misconfigured NGINX alias, as demonstrated by api-third-party/download/extdisks../etc/config/account. With this vulnerability,…

  • CVE-2019-16902HigSep 27, 2019
    risk 0.53cvss 7.5epss 0.10

    In the ARforms plugin 3.7.1 for WordPress, arf_delete_file in arformcontroller.php allows unauthenticated deletion of an arbitrary file by supplying the full pathname.

  • CVE-2017-18585HigAug 22, 2019
    risk 0.53cvss 8.1epss 0.02

    The posts-in-page plugin before 1.3.0 for WordPress has ic_add_posts template='../ directory traversal.

  • CVE-2019-14240HigJul 23, 2019
    risk 0.53cvss 8.1epss 0.01

    WCMS v0.3.2 has a CSRF vulnerability, with resultant directory traversal, to modify index.html via the /wex/html.php?finish=../index.html URI.

  • CVE-2019-12925HigJul 8, 2019
    risk 0.53cvss 8.1epss 0.02

    MailEnable Enterprise Premium 10.23 was vulnerable to multiple directory traversal issues, with which authenticated users could add, remove, or potentially read files in arbitrary folders accessible by the IIS user. This could lead to reading other users' credentials including…

  • CVE-2019-10137HigJul 2, 2019
    risk 0.53cvss 8.1epss 0.03

    A path traversal flaw was found in spacewalk-proxy, all versions through 2.9, in the way the proxy processes cached client tokens. A remote, unauthenticated attacker could use this flaw to test the existence of arbitrary files, if they have access to the proxy's filesystem, or…

  • CVE-2018-16594HigJun 19, 2019
    risk 0.53cvss 8.1epss 0.01

    The Photo Sharing Plus component on Sony Bravia TV through 8.587 devices allows Directory Traversal.

  • CVE-2019-9222HigApr 17, 2019
    risk 0.53cvss 8.1epss 0.01

    An issue was discovered in GitLab Community and Enterprise Edition before 11.6.10, 11.7.x before 11.7.6, and 11.8.x before 11.8.1. It has Insecure Permissions.

  • CVE-2019-3943HigApr 10, 2019
    risk 0.53cvss 8.1epss 0.04

    MikroTik RouterOS versions Stable 6.43.12 and below, Long-term 6.42.12 and below, and Testing 6.44beta75 and below are vulnerable to an authenticated, remote directory traversal via the HTTP or Winbox interfaces. An authenticated, remote attack can use this vulnerability to read…