VYPR

CWE-22

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')

BaseStableLikelihood: High

Description

The product uses external input to construct a pathname that is intended to identify a file or directory that is located underneath a restricted parent directory, but the product does not properly neutralize special elements within the pathname that can cause the pathname to resolve to a location that is outside of the restricted directory.

Hierarchy (View 1000)

Parents

Children

Related attack patterns (CAPEC)

CAPEC-126 · CAPEC-64 · CAPEC-76 · CAPEC-78 · CAPEC-79

CVEs mapped to this weakness (10,395)

page 113 of 520
  • CVE-2024-23773HigApr 30, 2024
    risk 0.51cvss 7.8epss 0.00

    An issue was discovered in Quest KACE Agent for Windows 12.0.38 and 13.1.23.0. An Arbitrary file delete vulnerability exists in the KSchedulerSvc.exe component. Local attackers can delete any file of their choice with NT Authority\SYSTEM privileges.

  • CVE-2023-52623HigMar 26, 2024
    risk 0.51cvss 7.8epss 0.00

    In the Linux kernel, the following vulnerability has been resolved: SUNRPC: Fix a suspicious RCU usage warning I received the following warning while running cthon against an ontap server running pNFS: [ 57.202521] ============================= [ 57.202522] WARNING:…

  • CVE-2022-45792HigJan 22, 2024
    risk 0.51cvss 7.8epss 0.00

    Project files may contain malicious contents which the software will use to create files on the filesystem. This allows directory traversal and overwriting files with the privileges of the logged-in user.

  • CVE-2023-36123HigOct 7, 2023
    risk 0.51cvss 7.8epss 0.01

    Directory Traversal vulnerability in Hex-Dragon Plain Craft Launcher 2 version Alpha 1.3.9, allows local attackers to execute arbitrary code and gain sensitive information.

  • CVE-2023-43825HigSep 27, 2023
    risk 0.51cvss 7.8epss 0.00

    Relative path traversal vulnerability in Shihonkanri Plus Ver9.0.3 and earlier allows a local attacker to execute an arbitrary code by having a legitimate user import a specially crafted backup file of the product..

  • CVE-2023-35670HigSep 11, 2023
    risk 0.51cvss 7.8epss 0.00

    In computeValuesFromData of FileUtils.java, there is a possible way to insert files to other apps' external private directories due to a path traversal error. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not…

  • CVE-2021-35980HigSep 6, 2023
    risk 0.51cvss 7.8epss 0.00

    Acrobat Reader DC versions 2021.005.20054 (and earlier), 2020.004.30005 (and earlier) and 2017.011.30197 (and earlier) are affected by a Path traversal vulnerability. An unauthenticated attacker could leverage this vulnerability to achieve arbitrary code execution in the context…

  • CVE-2021-28644HigSep 6, 2023
    risk 0.51cvss 7.8epss 0.00

    Acrobat Reader DC versions 2021.005.20054 (and earlier), 2020.004.30005 (and earlier) and 2017.011.30197 (and earlier) are affected by a Path traversal vulnerability. An unauthenticated attacker could leverage this vulnerability to achieve arbitrary code execution in the context…

  • CVE-2023-39138HigAug 30, 2023
    risk 0.51cvss 7.8epss 0.00

    An issue in ZIPFoundation v0.9.16 allows attackers to execute a path traversal via extracting a crafted zip file.

  • CVE-2023-39135HigAug 30, 2023
    risk 0.51cvss 7.8epss 0.00

    An issue in Zip Swift v2.1.2 allows attackers to execute a path traversal attack via a crafted zip entry.

  • CVE-2023-40597HigAug 30, 2023
    risk 0.51cvss 7.8epss 0.00

    In Splunk Enterprise versions lower than 8.2.12, 9.0.6, and 9.1.1, an attacker can exploit an absolute path traversal to execute arbitrary code that is located on a separate disk.

  • CVE-2023-39810HigAug 28, 2023
    risk 0.51cvss 7.8epss 0.01

    An issue in the CPIO command of Busybox v1.33.2 allows attackers to execute a directory traversal.

  • CVE-2023-37646HigAug 8, 2023
    risk 0.51cvss 7.8epss 0.00

    An issue in the CAB file extraction function of Bitberry File Opener v23.0 allows attackers to execute a directory traversal.

  • CVE-2023-31427HigAug 1, 2023
    risk 0.51cvss 7.8epss 0.00

    Brocade Fabric OS versions before Brocade Fabric OS v9.1.1c, and v9.2.0 Could allow an authenticated, local user with knowledge of full path names inside Brocade Fabric OS to execute any command regardless of assigned privilege. Starting with Fabric OS v9.1.0, “root” account…

  • CVE-2023-24256HigJul 6, 2023
    risk 0.51cvss 7.8epss 0.00

    An issue in the com.nextev.datastatistic component of NIO EC6 Aspen before v3.3.0 allows attackers to escalate privileges via path traversal.

  • CVE-2023-33747HigJun 6, 2023
    risk 0.51cvss 7.8epss 0.00

    CloudPanel v2.2.2 allows attackers to execute a path traversal.

  • CVE-2023-26243HigApr 27, 2023
    risk 0.51cvss 7.8epss 0.00

    An issue was discovered in the Hyundai Gen5W_L in-vehicle infotainment system AE_E_PE_EUR.S5W_L001.001.211214. The decryption binary used to decrypt firmware files has an information leak that allows an attacker to read the AES key and initialization vector from memory. An…

  • CVE-2023-21093HigApr 19, 2023
    risk 0.51cvss 7.8epss 0.00

    In extractRelativePath of FileUtils.java, there is a possible way to access files in a directory belonging to other applications due to a path traversal error. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is…

  • CVE-2022-42470HigApr 11, 2023
    risk 0.51cvss 7.8epss 0.00

    A relative path traversal vulnerability in Fortinet FortiClient (Windows) 7.0.0 - 7.0.7, 6.4.0 - 6.4.9, 6.2.0 - 6.2.9 and 6.0.0 - 6.0.10 allows an attacker to execute unauthorized code or commands via sending a crafted request to a specific named pipe.

  • CVE-2023-27981HigMar 21, 2023
    risk 0.51cvss 7.8epss 0.01

    A CWE-22: Improper Limitation of a Pathname to a Restricted Directory vulnerability exists in Custom Reports that could cause a remote code execution when a victim tries to open a malicious report. Affected Products: IGSS Data Server(IGSSdataServer.exe)(V16.0.0.23040 and prior),…