VYPR

CWE-22

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')

BaseStableLikelihood: High

Description

The product uses external input to construct a pathname that is intended to identify a file or directory that is located underneath a restricted parent directory, but the product does not properly neutralize special elements within the pathname that can cause the pathname to resolve to a location that is outside of the restricted directory.

Hierarchy (View 1000)

Parents

Children

Related attack patterns (CAPEC)

CAPEC-126 · CAPEC-64 · CAPEC-76 · CAPEC-78 · CAPEC-79

CVEs mapped to this weakness (10,395)

page 129 of 520
  • CVE-2019-18665HigNov 2, 2019
    risk 0.50cvss 7.5epss 0.15

    The Log module in SECUDOS DOMOS before 5.6 allows local file inclusion.

  • CVE-2019-16279HigOct 14, 2019
    risk 0.50cvss 7.5epss 0.20

    A memory error in the function SSL_accept in nostromo nhttpd through 1.9.6 allows an attacker to trigger a denial of service via a crafted HTTP request.

  • CVE-2019-17538HigOct 13, 2019
    risk 0.50cvss 7.5epss 0.11

    Jiangnan Online Judge (aka jnoj) 0.8.0 has Directory Traversal for file reading via the web/polygon/problem/viewfile?id=1&name=../ substring.

  • CVE-2015-9480HigOct 10, 2019
    risk 0.50cvss 7.5epss 0.13

    The RobotCPA plugin 5 for WordPress has directory traversal via the f.php l parameter.

  • CVE-2019-17187HigOct 8, 2019
    risk 0.50cvss 7.5epss 0.11

    /var/WEB-GUI/cgi-bin/downloadfile.cgi on FiberHome HG2201T 1.00.M5007_JS_201804 devices allows pre-authentication Directory Traversal for reading arbitrary files.

  • CVE-2019-16123HigSep 9, 2019
    risk 0.50cvss 7.5epss 0.17

    In Kartatopia PilusCart 1.4.1, the parameter filename in the file catalog.php is mishandled, leading to ../ Local File Disclosure.

  • CVE-2016-10924HigAug 22, 2019
    risk 0.50cvss 7.5epss 0.12

    The ebook-download plugin before 1.2 for WordPress has directory traversal.

  • CVE-2018-14918HigJun 28, 2019
    risk 0.50cvss 7.5epss 0.19

    LOYTEC LGATE-902 6.3.2 devices allow Directory Traversal.

  • CVE-2019-7315HigJun 17, 2019
    risk 0.50cvss 7.5epss 0.11

    Genie Access WIP3BVAF WISH IP 3MP IR Auto Focus Bullet Camera devices through 3.x are vulnerable to directory traversal via the web interface, as demonstrated by reading /etc/shadow. NOTE: this product is discontinued, and its final firmware version has this vulnerability (4.x…

  • CVE-2019-1717HigMay 15, 2019
    risk 0.50cvss 7.5epss 0.10

    A vulnerability in the web-based management interface of Cisco Video Surveillance Manager could allow an unauthenticated, remote attacker to access sensitive information. The vulnerability is due to improper validation of parameters handled by the web-based management interface.…

  • CVE-2019-9726HigMay 13, 2019
    risk 0.50cvss 7.5epss 0.16

    Directory Traversal / Arbitrary File Read in eQ-3 AG Homematic CCU3 3.43.15 and earlier allows remote attackers to read arbitrary files of the device's filesystem. This vulnerability can be exploited by unauthenticated attackers with access to the web interface.

  • CVE-2018-1618HigApr 2, 2019
    risk 0.50cvss 7.7epss 0.03

    IBM Security Privileged Identity Manager Virtual Appliance 2.2.1 could allow a remote attacker to traverse directories on the system. An attacker could send a specially-crafted URL request containing "dot dot" sequences (/../) to view arbitrary files on the system. IBM X-Force…

  • CVE-2019-9922HigMar 29, 2019
    risk 0.50cvss 7.5epss 0.11

    An issue was discovered in the Harmis JE Messenger component 1.2.2 for Joomla!. Directory Traversal allows read access to arbitrary files.

  • CVE-2019-3816HigMar 14, 2019
    risk 0.50cvss 7.5epss 0.15

    Openwsman, versions up to and including 2.6.9, are vulnerable to arbitrary file disclosure because the working directory of openwsmand daemon was set to root directory. A remote, unauthenticated attacker can exploit this vulnerability by sending a specially crafted HTTP request…

  • CVE-2018-15782HigJan 16, 2019
    risk 0.50cvss 7.7epss 0.00

    The Quick Setup component of RSA Authentication Manager versions prior to 8.4 is vulnerable to a relative path traversal vulnerability. A local attacker could potentially provide an administrator with a crafted license that if used during the quick setup deployment of the…

  • CVE-2018-20463HigDec 25, 2018
    risk 0.50cvss 7.5epss 0.13

    An issue was discovered in the JSmol2WP plugin 1.07 for WordPress. There is an arbitrary file read vulnerability via ../ directory traversal in query=php://filter/resource= in the jsmol.php query string. This can also be used for SSRF.

  • CVE-2018-19753HigDec 5, 2018
    risk 0.50cvss 7.5epss 0.17

    Tarantella Enterprise before 3.11 allows Directory Traversal.

  • CVE-2018-19326HigNov 17, 2018
    risk 0.50cvss 7.5epss 0.10

    Zyxel VMG1312-B10D devices before 5.13(AAXA.8)C0 allow ../ Directory Traversal, as demonstrated by reading /etc/passwd.

  • CVE-2018-1744HigOct 15, 2018
    risk 0.50cvss 7.7epss 0.03

    IBM Security Key Lifecycle Manager 2.5, 2.6, 2.7, and 3.0 could allow a remote attacker to traverse directories on the system. An attacker could send a specially-crafted URL request containing "dot dot" sequences (/../) to view arbitrary files on the system. IBM X-Force ID:…

  • CVE-2018-1649HigOct 5, 2018
    risk 0.50cvss 7.7epss 0.03

    IBM QRadar Incident Forensics 7.2 and 7.3 could allow a remote attacker to traverse directories on the system. An attacker could send a specially-crafted URL request containing "dot dot" sequences (/../) to view arbitrary files on the system. IBM X-Force ID: 144655.