VYPR

CWE-22

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')

BaseStableLikelihood: High

Description

The product uses external input to construct a pathname that is intended to identify a file or directory that is located underneath a restricted parent directory, but the product does not properly neutralize special elements within the pathname that can cause the pathname to resolve to a location that is outside of the restricted directory.

Hierarchy (View 1000)

Parents

Children

Related attack patterns (CAPEC)

CAPEC-126 · CAPEC-64 · CAPEC-76 · CAPEC-78 · CAPEC-79

CVEs mapped to this weakness (10,395)

page 107 of 520
  • CVE-2024-31232HigMay 17, 2024
    risk 0.52cvss 8.0epss 0.01

    Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Sizam Design Rehub allows PHP Local File Inclusion.This issue affects Rehub: from n/a through 19.6.1.

  • CVE-2023-5938HigMay 15, 2024
    risk 0.52cvss 8.0epss 0.01

    Multiple functions use archives without properly validating the filenames therein, rendering the application vulnerable to path traversal via 'zip slip' attacks. An administrator able to provide tampered archives to be processed by the affected versions of Arc may be able to…

  • CVE-2024-4346CriMay 7, 2024
    risk 0.52cvss 9.1epss 0.02

    The Startklar Elementor Addons plugin for WordPress is vulnerable to arbitrary file deletion in all versions up to, and including, 1.7.13. This is due to the plugin not properly validating the path of an uploaded file prior to deleting it. This makes it possible for…

  • CVE-2024-28335CriMar 27, 2024
    risk 0.52cvss 9.1epss 0.01

    Lektor before 3.3.11 does not sanitize DB path traversal. Thus, shell commands might be executed via a file that is added to the templates directory, if the victim's web browser accesses an untrusted website that uses JavaScript to send requests to localhost port 5000, and the…

  • CVE-2023-40279HigMar 19, 2024
    risk 0.52cvss 7.5epss 0.03

    An issue was discovered in OpenClinic GA 5.247.01. An attacker can perform a directory path traversal via the Page parameter in a GET request to main.do.

  • CVE-2024-0818CriMar 7, 2024
    risk 0.52cvss 9.1epss 0.01

    Arbitrary File Overwrite Via Path Traversal in paddlepaddle/paddle before 2.6

  • CVE-2024-23477HigFeb 15, 2024
    risk 0.52cvss 7.9epss 0.08

    The SolarWinds Access Rights Manager (ARM) was found to be susceptible to a Directory Traversal Remote Code Execution Vulnerability. If exploited, this vulnerability allows an unauthenticated user to achieve a Remote Code Execution.

  • CVE-2023-5123HigFeb 14, 2024
    risk 0.52cvss 8.0epss 0.01

    The JSON datasource plugin ( https://grafana.com/grafana/plugins/marcusolsson-json-datasource/ ) is a Grafana Labs maintained plugin for Grafana that allows for retrieving and processing JSON data from a remote endpoint (including a specific sub-path) configured by an…

  • CVE-2024-24591HigFeb 6, 2024
    risk 0.52cvss 8.0epss 0.01

    A path traversal vulnerability in versions 1.4.0 to 1.14.1 of the client SDK of Allegro AI’s ClearML platform enables a maliciously uploaded dataset to write local or remote files to an arbitrary location on an end user’s system when interacted with.

  • CVE-2023-38126HigDec 19, 2023
    risk 0.52cvss 7.2epss 0.71

    Softing edgeAggregator Restore Configuration Directory Traversal Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Softing edgeAggregator. Authentication is required to exploit this…

  • CVE-2023-6021HigNov 16, 2023
    risk 0.52cvss 7.5epss 0.37

    LFI in Ray's log API endpoint allows attackers to read any file on the server without authentication. The issue is fixed in version 2.8.1+. Ray maintainers' response can be found here: https://www.anyscale.com/blog/update-on-ray-cves-cve-2023-6019-cve-2023-6020-cve-2023-6021-cve-…

  • CVE-2023-40055HigNov 9, 2023
    risk 0.52cvss 8.0epss 0.02

    The Network Configuration Manager was susceptible to a Directory Traversal Remote Code Execution Vulnerability. This vulnerability allows a low-level user to perform the actions with SYSTEM privileges. We found this issue was not resolved in CVE-2023-33227

  • CVE-2023-40054HigNov 9, 2023
    risk 0.52cvss 8.0epss 0.03

    The Network Configuration Manager was susceptible to a Directory Traversal Remote Code Execution Vulnerability. This vulnerability allows a low-level user to perform the actions with SYSTEM privileges. We found this issue was not resolved in CVE-2023-33226

  • CVE-2023-33227HigNov 1, 2023
    risk 0.52cvss 8.0epss 0.02

    The Network Configuration Manager was susceptible to a Directory Traversal Remote Code Execution Vulnerability This vulnerability allows a low level user to perform the actions with SYSTEM privileges.

  • CVE-2023-33226HigNov 1, 2023
    risk 0.52cvss 8.0epss 0.02

    The Network Configuration Manager was susceptible to a Directory Traversal Remote Code Execution Vulnerability. This vulnerability allows a low-level user to perform the actions with SYSTEM privileges.

  • CVE-2023-35169CriJun 23, 2023
    risk 0.52cvss 9.0epss 0.03

    PHP-IMAP is a wrapper for common IMAP communication without the need to have the php-imap module installed / enabled. Prior to version 5.3.0, an unsanitized attachment filename allows any unauthenticated user to leverage a directory traversal vulnerability, which results in a…

  • CVE-2023-30198HigJun 12, 2023
    risk 0.52cvss 7.5epss 0.06

    Prestashop winbizpayment <= 1.0.2 is vulnerable to Incorrect Access Control via modules/winbizpayment/downloads/download.php.

  • CVE-2021-27825HigMay 29, 2023
    risk 0.52cvss 7.5epss 0.08

    A directory traversal vulnerability on Mercury MAC1200R devices allows attackers to read arbitrary files via a web-static/ URL.

  • CVE-2023-25289HigMay 4, 2023
    risk 0.52cvss 7.5epss 0.08

    Directory Traversal vulnerability in virtualreception Digital Receptie version win7sp1_rtm.101119-1850 6.1.7601.1.0.65792 in embedded web server, allows attacker to gain sensitive information via a crafted GET request.

  • CVE-2022-34127HigApr 16, 2023
    risk 0.52cvss 7.5epss 0.07

    The Managentities plugin before 4.0.2 for GLPI allows reading local files via directory traversal in the inc/cri.class.php file parameter.