VYPR

CWE-22

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')

BaseStableLikelihood: High

Description

The product uses external input to construct a pathname that is intended to identify a file or directory that is located underneath a restricted parent directory, but the product does not properly neutralize special elements within the pathname that can cause the pathname to resolve to a location that is outside of the restricted directory.

Hierarchy (View 1000)

Parents

Children

Related attack patterns (CAPEC)

CAPEC-126 · CAPEC-64 · CAPEC-76 · CAPEC-78 · CAPEC-79

CVEs mapped to this weakness (10,395)

page 148 of 520
  • CVE-2024-47559HigOct 7, 2024
    risk 0.49cvss 7.6epss 0.01

    Authenticated RCE via Path Traversal

  • CVE-2024-47558HigOct 7, 2024
    risk 0.49cvss 7.6epss 0.01

    Authenticated RCE via Path Traversal

  • CVE-2024-44034HigOct 5, 2024
    risk 0.49cvss 7.5epss 0.01

    Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Martin Greenwood WPSPX wpspx allows PHP Local File Inclusion.This issue affects WPSPX: from n/a through <= 1.0.2.

  • CVE-2024-44018HigOct 5, 2024
    risk 0.49cvss 7.5epss 0.01

    Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in istmoplugins Instant Chat Floating Button for WordPress Websites instant-chat-wp allows PHP Local File Inclusion.This issue affects Instant Chat Floating Button for WordPress…

  • CVE-2024-44016HigOct 5, 2024
    risk 0.49cvss 7.5epss 0.01

    Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in amarksteadman Podiant podiant allows PHP Local File Inclusion.This issue affects Podiant: from n/a through <= 1.1.

  • CVE-2024-44015HigOct 5, 2024
    risk 0.49cvss 7.5epss 0.01

    Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in istmoplugins Users Control users-control allows PHP Local File Inclusion.This issue affects Users Control: from n/a through <= 1.0.16.

  • CVE-2024-44013HigOct 5, 2024
    risk 0.49cvss 7.5epss 0.01

    Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Innate Images LLC VR Calendar vr-calendar-sync allows PHP Local File Inclusion.This issue affects VR Calendar: from n/a through <= 2.4.0.

  • CVE-2024-44012HigOct 5, 2024
    risk 0.49cvss 7.5epss 0.01

    Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in wpdev33 WP Newsletter Subscription wp-newsletter-subscription allows PHP Local File Inclusion.This issue affects WP Newsletter Subscription: from n/a through <= 1.1.

  • CVE-2024-44011HigOct 5, 2024
    risk 0.49cvss 7.5epss 0.01

    Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in ExpressTech Systems WP Ticket Ultra Help Desk & Support Plugin wp-ticket-ultra allows PHP Local File Inclusion.This issue affects WP Ticket Ultra Help Desk & Support Plugin: from n/a…

  • CVE-2024-41922HigOct 3, 2024
    risk 0.49cvss 7.5epss 0.08

    A directory traversal vulnerability exists in the log files download functionality of Veertu Anka Build 1.42.0. A specially crafted HTTP request can lead to a disclosure of sensitive information. An attacker can make an unauthenticated HTTP request to trigger this vulnerability.

  • CVE-2024-8352HigOct 3, 2024
    risk 0.49cvss 7.5epss 0.01

    The Social Web Suite – Social Media Auto Post, Social Media Auto Publish plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 4.1.11 via the download_log function. This makes it possible for unauthenticated attackers to read the…

  • CVE-2024-44017HigOct 2, 2024
    risk 0.49cvss 7.5epss 0.01

    Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in MinHyeong Lim MH Board mh-board allows PHP Local File Inclusion.This issue affects MH Board: from n/a through <= 1.3.2.1.

  • CVE-2024-9301HigSep 27, 2024
    risk 0.49cvss 7.5epss 0.01

    A path traversal issue in E2Nest prior to commit 8a41948e553c89c56b14410c6ed395e9cfb9250a

  • CVE-2024-44825HigSep 25, 2024
    risk 0.49cvss 7.5epss 0.01

    Directory Traversal vulnerability in Centro de Tecnologia da Informaco Renato Archer InVesalius3 v3.1.99995 allows attackers to write arbitrary files unto the system via a crafted .inv3 file.

  • CVE-2024-8941HigSep 25, 2024
    risk 0.49cvss 7.5epss 0.01

    Path traversal vulnerability in Scriptcase version 9.4.019, in /scriptcase/devel/compat/nm_edit_php_edit.php (in the “subpage” parameter), which allows unauthenticated remote users to bypass SecurityManager's intended restrictions and list and/or read a parent directory via…

  • CVE-2024-46649HigSep 20, 2024
    risk 0.49cvss 7.5epss 0.01

    eNMS up to 4.7.1 is vulnerable to Directory Traversal via download/folder.

  • CVE-2024-46648HigSep 20, 2024
    risk 0.49cvss 7.5epss 0.01

    eNMS 4.4.0 to 4.7.1 is vulnerable to Directory Traversal via scan_folder.

  • CVE-2024-46645HigSep 20, 2024
    risk 0.49cvss 7.5epss 0.01

    eNMS 4.0.0 is vulnerable to Directory Traversal via get_tree_files.

  • CVE-2024-7609HigSep 11, 2024
    risk 0.49cvss 7.5epss 0.01

    Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Vidco Software VOC TESTER allows Path Traversal. This issue affects VOC TESTER: before 12.34.8.

  • CVE-2024-44867HigSep 10, 2024
    risk 0.49cvss 7.5epss 0.01

    phpok v3.0 was discovered to contain an arbitrary file read vulnerability via the component /autoload/file.php.