VYPR

CWE-22

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')

BaseStableLikelihood: High

Description

The product uses external input to construct a pathname that is intended to identify a file or directory that is located underneath a restricted parent directory, but the product does not properly neutralize special elements within the pathname that can cause the pathname to resolve to a location that is outside of the restricted directory.

Hierarchy (View 1000)

Parents

Children

Related attack patterns (CAPEC)

CAPEC-126 · CAPEC-64 · CAPEC-76 · CAPEC-78 · CAPEC-79

CVEs mapped to this weakness (10,395)

page 128 of 520
  • CVE-2021-40359HigNov 9, 2021
    risk 0.50cvss 7.7epss 0.01

    A vulnerability has been identified in OpenPCS 7 V8.2 (All versions), OpenPCS 7 V9.0 (All versions < V9.0 Upd4), OpenPCS 7 V9.1 (All versions), SIMATIC BATCH V8.2 (All versions), SIMATIC BATCH V9.0 (All versions), SIMATIC BATCH V9.1 (All versions), SIMATIC NET PC Software V14…

  • CVE-2021-41293HigSep 30, 2021
    risk 0.50cvss 7.5epss 0.20

    ECOA BAS controller suffers from a path traversal vulnerability, causing arbitrary files disclosure. Using the specific POST parameter, unauthenticated attackers can remotely disclose arbitrary files on the affected device and disclose sensitive and system information.

  • CVE-2021-33807HigJul 12, 2021
    risk 0.50cvss 7.5epss 0.16

    Cartadis Gespage through 8.2.1 allows Directory Traversal in gespage/doDownloadData and gespage/webapp/doDownloadData.

  • CVE-2021-32674HigJun 8, 2021
    risk 0.50cvss 8.8epss 0.02

    Zope is an open-source web application server. This advisory extends the previous advisory at https://github.com/zopefoundation/Zope/security/advisories/GHSA-5pr9-v234-jw36 with additional cases of TAL expression traversal vulnerabilities. Most Python modules are not available…

  • CVE-2021-29091HigJun 2, 2021
    risk 0.50cvss 7.7epss 0.01

    Improper limitation of a pathname to a restricted directory ('Path Traversal') vulnerability in file management component in Synology Photo Station before 6.8.14-3500 allows remote authenticated users to write arbitrary files via unspecified vectors.

  • CVE-2020-35580HigMay 20, 2021
    risk 0.50cvss 7.5epss 0.14

    A local file inclusion vulnerability in the FileServlet in all SearchBlox before 9.2.2 allows remote, unauthenticated users to read arbitrary files from the operating system via a /searchblox/servlet/FileServlet?col=url= request. Additionally, this may be used to read the…

  • CVE-2021-26294HigMar 7, 2021
    risk 0.50cvss 7.5epss 0.17

    An issue was discovered in AfterLogic Aurora through 7.7.9 and WebMail Pro through 7.7.9. They allow directory traversal to read files (such as a data/settings/settings.xml file containing admin panel credentials), as demonstrated by dav/server.php/files/personal/%2e%2e when…

  • CVE-2020-13550HigFeb 17, 2021
    risk 0.50cvss 7.7epss 0.03

    A local file inclusion vulnerability exists in the installation functionality of Advantech WebAccess/SCADA 9.0.1. A specially crafted application can lead to information disclosure. An attacker can send an authenticated HTTP request to trigger this vulnerability.

  • CVE-2021-21269HigJan 20, 2021
    risk 0.50cvss 7.7epss 0.01

    Keymaker is a Mastodon Community Finder based Matrix Community serverlist page Server. In Keymaker before version 0.2.0, the assets endpoint did not check for the extension. The rust `join` method without checking user input might have made it abe to do a Path Traversal attack…

  • CVE-2020-19360HigJan 20, 2021
    risk 0.50cvss 7.5epss 0.17

    Local file inclusion in FHEM 6.0 allows in fhem/FileLog_logWrapper file parameter can allow an attacker to include a file, which can lead to sensitive information disclosure.

  • CVE-2021-3019HigJan 5, 2021
    risk 0.50cvss 7.5epss 0.17

    ffay lanproxy 0.1 allows Directory Traversal to read /../conf/config.properties to obtain credentials for a connection to the intranet.

  • CVE-2020-35736HigDec 27, 2020
    risk 0.50cvss 7.5epss 0.15

    GateOne 1.1 allows arbitrary file download without authentication via /downloads/.. directory traversal because os.path.join is misused.

  • CVE-2020-25780HigOct 29, 2020
    risk 0.50cvss 7.5epss 0.10

    In CommCell in Commvault before 14.68, 15.x before 15.58, 16.x before 16.44, 17.x before 17.29, and 18.x before 18.13, Directory Traversal can occur such that an attempt to view a log file can instead view a file outside of the log-files folder.

  • CVE-2020-21527HigSep 30, 2020
    risk 0.50cvss 7.7epss 0.01

    There is an Arbitrary file deletion vulnerability in halo v1.1.3. A backup function in the background allows a user, when deleting their backup files, to delete any files on the system through directory traversal.

  • CVE-2020-24571HigAug 21, 2020
    risk 0.50cvss 7.5epss 0.18

    NexusQA NexusDB before 4.50.23 allows the reading of files via ../ directory traversal.

  • CVE-2020-16136HigJul 31, 2020
    risk 0.50cvss 7.7epss 0.02

    In tgstation-server 4.4.0 and 4.4.1, an authenticated user with permission to download logs can download any file on the server machine (accessible by the owner of the server process) via directory traversal ../ sequences in /Administration/Logs/ requests. The attacker is unable…

  • CVE-2020-7473HigMay 7, 2020
    risk 0.50cvss 7.5epss 0.14

    In certain situations, all versions of Citrix ShareFile StorageZones (aka storage zones) Controller, including the most recent 5.10.x releases as of May 2020, allow unauthenticated attackers to access the documents and folders of ShareFile users. NOTE: unlike most CVEs,…

  • CVE-2020-12447HigApr 29, 2020
    risk 0.50cvss 7.5epss 0.14

    A Local File Inclusion (LFI) issue on Onkyo TX-NR585 1000-0000-000-0008-0000 devices allows remote unauthenticated users on the network to read sensitive files via %2e%2e%2f directory traversal, as demonstrated by reading /etc/shadow.

  • CVE-2020-6767HigFeb 6, 2020
    risk 0.50cvss 7.7epss 0.01

    A path traversal vulnerability in the Bosch Video Management System (BVMS) FileTransferService allows an authenticated remote attacker to read arbitrary files from the Central Server. This affects Bosch BVMS versions 10.0 <= 10.0.0.1225, 9.0 <= 9.0.0.827, 8.0 <= 8.0.329 and 7.5…

  • CVE-2019-18338HigDec 12, 2019
    risk 0.50cvss 7.7epss 0.03

    A vulnerability has been identified in Control Center Server (CCS) (All versions < V1.5.0). The Control Center Server (CCS) contains a directory traversal vulnerability in its XML-based communication protocol as provided by default on ports 5444/tcp and 5440/tcp. An…