VYPR

CWE-22

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')

BaseStableLikelihood: High

Description

The product uses external input to construct a pathname that is intended to identify a file or directory that is located underneath a restricted parent directory, but the product does not properly neutralize special elements within the pathname that can cause the pathname to resolve to a location that is outside of the restricted directory.

Hierarchy (View 1000)

Parents

Children

Related attack patterns (CAPEC)

CAPEC-126 · CAPEC-64 · CAPEC-76 · CAPEC-78 · CAPEC-79

CVEs mapped to this weakness (10,395)

page 11 of 520
  • CVE-2012-6664CriJun 21, 2024
    risk 0.65cvss 9.1epss 0.30

    Multiple directory traversal vulnerabilities in the TFTP Server in Distinct Intranet Servers 3.10 and earlier allow remote attackers to read or write arbitrary files via a .. (dot dot) in the (1) get or (2) put commands.

  • CVE-2024-34854CriMay 28, 2024
    risk 0.65cvss 9.8epss 0.13

    F-logic DataCube3 v1.0 is vulnerable to File Upload via `/admin/transceiver_schedule.php.`

  • CVE-2024-2227CriMar 22, 2024
    risk 0.65cvss 10.0epss 0.01

    This vulnerability allows access to arbitrary files in the application server file system due to a path traversal vulnerability in JavaServer Faces (JSF) 2.2.20 documented in CVE-2020-6950. The remediation for this vulnerability contained in this security fix provides additional…

  • CVE-2023-6825CriMar 13, 2024
    risk 0.65cvss 9.9epss 0.06

    The File Manager and File Manager Pro plugins for WordPress are vulnerable to Directory Traversal in versions up to, and including version 7.2.1 (free version) and 8.3.4 (Pro version) via the target parameter in the mk_file_folder_manager_action_callback_shortcode function.…

  • CVE-2024-0402CriJan 26, 2024
    risk 0.65cvss 9.9epss 0.04

    An issue has been discovered in GitLab CE/EE affecting all versions from 16.0 prior to 16.6.6, 16.7 prior to 16.7.4, and 16.8 prior to 16.8.1 which allows an authenticated user to write files to arbitrary locations on the GitLab server while creating a workspace.

  • CVE-2023-41373CriOct 10, 2023
    risk 0.65cvss 9.9epss 0.02

    A directory traversal vulnerability exists in the BIG-IP Configuration Utility that may allow an authenticated attacker to execute commands on the BIG-IP system. For BIG-IP system running in Appliance mode, a successful exploit can allow the attacker to cross a security…

  • CVE-2023-32521CriJun 26, 2023
    risk 0.65cvss 9.1epss 0.67

    A path traversal exists in a specific service dll of Trend Micro Mobile Security (Enterprise) 9.8 SP5 which could allow an unauthenticated remote attacker to delete arbitrary files.

  • CVE-2022-2560CriMar 29, 2023
    risk 0.65cvss 9.1epss 0.78

    This vulnerability allows remote attackers to delete arbitrary files on affected installations of EnterpriseDT CompleteFTP 22.1.0 Server. Authentication is not required to exploit this vulnerability. The specific flaw exists within the HttpFile class. The issue results from the…

  • CVE-2022-3184CriDec 21, 2022
    risk 0.65cvss 9.8epss 0.12

    Dataprobe iBoot-PDU FW versions prior to 1.42.06162022 contain a vulnerability where the device’s existing firmware allows unauthenticated users to access an old PHP page vulnerable to directory traversal, which may allow a user to write a file to the webroot directory.

  • CVE-2022-32573CriDec 15, 2022
    risk 0.65cvss 9.9epss 0.04

    A directory traversal vulnerability exists in the AssetActions.aspx addDoc functionality of Lansweeper lansweeper 10.1.1.0. A specially-crafted HTTP request can lead to arbitrary file upload. An attacker can send an HTTP request to trigger this vulnerability.

  • CVE-2022-41657CriOct 31, 2022
    risk 0.65cvss 9.8epss 0.21

    Delta Electronics InfraSuite Device Master Versions 00.00.01a and prior allow attacker provided data already serialized into memory to be used in file operation application programmable interfaces (APIs). This could create arbitrary files, which could be used in API operations…

  • CVE-2022-38129CriAug 10, 2022
    risk 0.65cvss 9.8epss 0.19

    A path traversal vulnerability exists in the com.keysight.tentacle.licensing.LicenseManager.addLicenseFile() method in the Keysight Sensor Management Server (SMS). This allows an unauthenticated remote attacker to upload arbitrary files to the SMS host.

  • CVE-2022-1518CriJun 24, 2022
    risk 0.65cvss 10.0epss 0.02

    LRM contains a directory traversal vulnerability that can allow a malicious actor to upload outside the intended directory structure.

  • CVE-2022-1391CriApr 25, 2022
    risk 0.65cvss 9.8epss 0.15

    The Cab fare calculator WordPress plugin before 1.0.4 does not validate the controller parameter before using it in require statements, which could lead to Local File Inclusion issues.

  • CVE-2022-1390CriApr 25, 2022
    risk 0.65cvss 9.8epss 0.22

    The Admin Word Count Column WordPress plugin through 2.2 does not validate the path parameter given to readfile(), which could allow unauthenticated attackers to read arbitrary files on server running old version of PHP susceptible to the null byte technique. This could also…

  • CVE-2022-25347CriMar 29, 2022
    risk 0.65cvss 9.8epss 0.11

    Delta Electronics DIAEnergie (All versions prior to 1.8.02.004) is vulnerable to path traversal attacks, which may allow an attacker to write arbitrary files to locations on the file system.

  • CVE-2021-45967CriMar 18, 2022
    risk 0.65cvss 9.8epss 0.21

    An issue was discovered in Pascom Cloud Phone System before 7.20.x. A configuration error between NGINX and a backend Tomcat server leads to a path traversal in the Tomcat server, exposing unintended endpoints.

  • CVE-2021-45427CriDec 30, 2021
    risk 0.65cvss 9.8epss 0.19

    Emerson XWEB 300D EVO 3.0.7--3ee403 is affected by: unauthenticated arbitrary file deletion due to path traversal. An attacker can browse and delete files without any authentication due to incorrect access control and directory traversal.

  • CVE-2021-41950CriNov 15, 2021
    risk 0.65cvss 9.1epss 0.75

    A directory traversal issue in ResourceSpace 9.6 before 9.6 rev 18277 allows remote unauthenticated attackers to delete arbitrary files on the ResourceSpace server via the provider and variant parameters in pages/ajax/tiles.php. Attackers can delete configuration or source code…

  • CVE-2021-29212CriNov 1, 2021
    risk 0.65cvss 9.8epss 0.14

    A remote unauthenticated directory traversal security vulnerability has been identified in HPE iLO Amplifier Pack versions 1.80, 1.81, 1.90 and 1.95. The vulnerability could be remotely exploited to allow an unauthenticated user to run arbitrary code leading complete impact to…