VYPR

CWE-22

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')

BaseStableLikelihood: High

Description

The product uses external input to construct a pathname that is intended to identify a file or directory that is located underneath a restricted parent directory, but the product does not properly neutralize special elements within the pathname that can cause the pathname to resolve to a location that is outside of the restricted directory.

Hierarchy (View 1000)

Parents

Children

Related attack patterns (CAPEC)

CAPEC-126 · CAPEC-64 · CAPEC-76 · CAPEC-78 · CAPEC-79

CVEs mapped to this weakness (10,395)

page 152 of 520
  • CVE-2023-40280HigMar 19, 2024
    risk 0.49cvss 7.5epss 0.01

    An issue was discovered in OpenClinic GA 5.247.01. An attacker can perform a directory path traversal via the Page parameter in a GET request to popup.jsp.

  • CVE-2023-40747HigMar 18, 2024
    risk 0.49cvss 7.5epss 0.01

    Directory traversal vulnerability exists in A.K.I Software's PMailServer/PMailServer2 products' CGIs included in Internal Simple Webserver. If this vulnerability is exploited, a remote attacker may access arbitrary files outside DocumentRoot.

  • CVE-2024-27765HigMar 5, 2024
    risk 0.49cvss 7.5epss 0.01

    Directory Traversal vulnerability in Jeewms v.3.7 and before allows a remote attacker to obtain sensitive information via the cgformTemplateController component.

  • CVE-2024-25164HigMar 5, 2024
    risk 0.49cvss 7.5epss 0.01

    iA Path Traversal vulnerability exists in iDURAR v2.0.0, that allows unauthenticated attackers to expose sensitive files via the download functionality.

  • CVE-2024-24307HigMar 3, 2024
    risk 0.49cvss 7.5epss 0.01

    Path Traversal vulnerability in Tunis Soft "Product Designer" (productdesigner) module for PrestaShop before version 1.178.36, allows a remote attacker to escalate privileges and obtain sensitive information via the ajaxProcessCropImage() method.

  • CVE-2024-25711HigFeb 27, 2024
    risk 0.49cvss 7.5epss 0.01

    diffoscope before 256 allows directory traversal via an embedded filename in a GPG file. Contents of any file, such as ../.ssh/id_rsa, may be disclosed to an attacker. This occurs because the value of the gpg --use-embedded-filenames option is trusted.

  • CVE-2023-49960HigFeb 26, 2024
    risk 0.49cvss 7.5epss 0.01

    In Indo-Sol PROFINET-INspektor NT through 2.4.0, a path traversal vulnerability in the httpuploadd service of the firmware allows remote attackers to write to arbitrary files via a crafted filename parameter in requests to the /upload endpoint.

  • CVE-2024-25461HigFeb 21, 2024
    risk 0.49cvss 7.5epss 0.01

    Directory Traversal vulnerability in Terrasoft, Creatio Terrasoft CRM v.7.18.4.1532 allows a remote attacker to obtain sensitive information via a crafted request to the terrasoft.axd component.

  • CVE-2024-24311HigFeb 7, 2024
    risk 0.49cvss 7.5epss 0.01

    Path Traversal vulnerability in Linea Grafica "Multilingual and Multistore Sitemap Pro - SEO" (lgsitemaps) module for PrestaShop before version 1.6.6, a guest can download personal information without restriction.

  • CVE-2023-39611HigFeb 2, 2024
    risk 0.49cvss 7.5epss 0.01

    An issue in Software FX Chart FX 7 version 7.0.4962.20829 allows attackers to enumerate and read files from the local filesystem by sending crafted web requests.

  • CVE-2024-22851HigFeb 2, 2024
    risk 0.49cvss 7.5epss 0.01

    Directory Traversal Vulnerability in LiveConfig before v.2.5.2 allows a remote attacker to obtain sensitive information via a crafted request to the /static/ endpoint.

  • CVE-2024-22523HigJan 30, 2024
    risk 0.49cvss 7.5epss 0.01

    Directory Traversal vulnerability in Qiyu iFair version 23.8_ad0 and before, allows remote attackers to obtain sensitive information via uploadimage component.

  • CVE-2024-23904HigJan 24, 2024
    risk 0.49cvss 7.5epss 0.01

    Jenkins Log Command Plugin 1.0.2 and earlier does not disable a feature of its command parser that replaces an '@' character followed by a file path in an argument with the file's contents, allowing unauthenticated attackers to read content from arbitrary files on the Jenkins…

  • CVE-2023-48383HigJan 15, 2024
    risk 0.49cvss 7.5epss 0.01

    NetVision Information airPASS has a path traversal vulnerability within its parameter in a specific URL. An unauthenticated remote attacker can exploit this vulnerability to bypass authentication and download arbitrary system files.

  • CVE-2023-52289HigJan 13, 2024
    risk 0.49cvss 7.5epss 0.01

    An issue was discovered in the flaskcode package through 0.0.8 for Python. An unauthenticated directory traversal, exploitable with a POST request to a /update-resource-data/<file_path> URI (from views.py), allows attackers to write to arbitrary files.

  • CVE-2023-52288HigJan 13, 2024
    risk 0.49cvss 7.5epss 0.01

    An issue was discovered in the flaskcode package through 0.0.8 for Python. An unauthenticated directory traversal, exploitable with a GET request to a /resource-data/<file_path>.txt URI (from views.py), allows attackers to read arbitrary files.

  • CVE-2023-48166HigJan 12, 2024
    risk 0.49cvss 7.5epss 0.01

    A directory traversal vulnerability in the SOAP Server integrated in Atos Unify OpenScape Voice V10 before V10R3.26.1 allows a remote attacker to view the contents of arbitrary files in the local file system. An unauthenticated attacker might obtain sensitive files that allow…

  • CVE-2023-31036HigJan 12, 2024
    risk 0.49cvss 7.5epss 0.01

    NVIDIA Triton Inference Server for Linux and Windows contains a vulnerability where, when it is launched with the non-default command line option --model-control explicit, an attacker may use the model load API to cause a relative path traversal. A successful exploit of this…

  • CVE-2023-51127HigJan 10, 2024
    risk 0.49cvss 7.5epss 0.01

    FLIR AX8 thermal sensor cameras up to and including 1.46.16 are vulnerable to Directory Traversal due to improper access restriction. This vulnerability allows an unauthenticated, remote attacker to obtain arbitrary sensitive file contents by uploading a specially crafted…

  • CVE-2023-37607HigJan 3, 2024
    risk 0.49cvss 7.5epss 0.01

    Directory Traversal in Automatic Systems SOC FL9600 FirstLane V06 lego_T04E00 allows a remote attacker to obtain sensitive information via csvServer.php?file= with a .. in the dir parameter.