VYPR

CWE-22

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')

BaseStableLikelihood: High

Description

The product uses external input to construct a pathname that is intended to identify a file or directory that is located underneath a restricted parent directory, but the product does not properly neutralize special elements within the pathname that can cause the pathname to resolve to a location that is outside of the restricted directory.

Hierarchy (View 1000)

Parents

Children

Related attack patterns (CAPEC)

CAPEC-126 · CAPEC-64 · CAPEC-76 · CAPEC-78 · CAPEC-79

CVEs mapped to this weakness (10,395)

page 154 of 520
  • CVE-2023-6023HigNov 16, 2023
    risk 0.49cvss 7.5epss 0.03

    An attacker can read any file on the filesystem on the server hosting ModelDB through an LFI in the artifact_path URL parameter.

  • CVE-2023-45283HigNov 9, 2023
    risk 0.49cvss 7.5epss 0.03

    The filepath package does not recognize paths with a \??\ prefix as special. On Windows, a path beginning with \??\ is a Root Local Device path equivalent to a path beginning with \\?\. Paths with a \??\ prefix may be used to access arbitrary locations on the system. For…

  • CVE-2023-36667HigNov 8, 2023
    risk 0.49cvss 7.5epss 0.01

    Couchbase Server 7.1.4 before 7.1.5 and 7.2.0 before 7.2.1 allows Directory Traversal.

  • CVE-2023-39299HigNov 3, 2023
    risk 0.49cvss 7.5epss 0.01

    A path traversal vulnerability has been reported to affect Music Station. If exploited, the vulnerability could allow users to read the contents of unexpected files and expose sensitive data via a network. We have already fixed the vulnerability in the following versions: Music…

  • CVE-2023-41344HigNov 3, 2023
    risk 0.49cvss 7.5epss 0.01

    NCSIST ManageEngine Mobile Device Manager(MDM) APP's special function has a path traversal vulnerability. An unauthenticated remote attacker can exploit this vulnerability to bypass authentication and read arbitrary system files.

  • CVE-2023-46863HigOct 30, 2023
    risk 0.49cvss 7.5epss 0.01

    Peppermint Ticket Management before 0.2.4 allows remote attackers to read arbitrary files via a /api/v1/users/file/download?filepath=./../ POST request.

  • CVE-2023-27170HigOct 26, 2023
    risk 0.49cvss 7.5epss 0.01

    Xpand IT Write-back manager v2.3.1 allows attackers to perform a directory traversal via modification of the siteName parameter.

  • CVE-2023-46346HigOct 25, 2023
    risk 0.49cvss 7.5epss 0.01

    In the module "Product Catalog (CSV, Excel, XML) Export PRO" (exportproducts) in versions up to 4.1.1 from MyPrestaModules for PrestaShop, a guest can download personal information without restriction by performing a path traversal attack. Due to a lack of permissions control…

  • CVE-2023-42488HigOct 25, 2023
    risk 0.49cvss 7.5epss 0.01

    EisBaer Scada - CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')

  • CVE-2023-45823HigOct 19, 2023
    risk 0.49cvss 7.5epss 0.01

    Artifact Hub is a web-based application that enables finding, installing, and publishing packages and configurations for CNCF projects. During a security audit of Artifact Hub's code base a security researcher identified a bug in which by using symbolic links in certain kinds of…

  • CVE-2023-45277HigOct 19, 2023
    risk 0.49cvss 7.5epss 0.01

    Yamcs 5.8.6 is vulnerable to directory traversal (issue 1 of 2). The vulnerability is in the storage functionality of the API and allows one to escape the base directory of the buckets, freely navigate system directories, and read arbitrary files.

  • CVE-2023-45383HigOct 18, 2023
    risk 0.49cvss 7.5epss 0.01

    In the module "SoNice etiquetage" (sonice_etiquetage) up to version 2.5.9 from Common-Services for PrestaShop, a guest can download personal information without restriction by performing a path traversal attack. Due to a lack of permissions control and a lack of control in the…

  • CVE-2023-39331HigOct 18, 2023
    risk 0.49cvss 7.5epss 0.01

    A previously disclosed vulnerability (CVE-2023-30584) was patched insufficiently in commit 205f1e6. The new path traversal vulnerability arises because the implementation does not protect itself against the application overwriting built-in utility functions with user-defined…

  • CVE-2023-43121HigOct 16, 2023
    risk 0.49cvss 7.5epss 0.01

    A Directory Traversal vulnerability discovered in Chalet application in Extreme Networks Switch Engine (EXOS) before 32.5.1.5, before 22.7, and before 31.7.2 allows attackers to read arbitrary files.

  • CVE-2023-38312HigOct 15, 2023
    risk 0.49cvss 7.5epss 0.01

    A directory traversal vulnerability in Valve Counter-Strike 8684 allows a client (with remote control access to a game server) to read arbitrary files from the underlying server via the motdfile console variable.

  • CVE-2023-45855HigOct 14, 2023
    risk 0.49cvss 7.5epss 0.03

    qdPM 9.2 allows Directory Traversal to list files and directories by navigating to the /uploads URI.

  • CVE-2023-32974HigOct 13, 2023
    risk 0.49cvss 7.5epss 0.01

    A path traversal vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow users to read the contents of unexpected files and expose sensitive data via a network. We have already fixed the vulnerability in the…

  • CVE-2023-42796HigOct 10, 2023
    risk 0.49cvss 7.5epss 0.01

    A vulnerability has been identified in CP-8031 MASTER MODULE (All versions < CPCI85 V05.11), CP-8050 MASTER MODULE (All versions < CPCI85 V05.11). The web server of affected devices fails to properly sanitize user input for the /sicweb-ajax/tmproot/ endpoint. This could allow…

  • CVE-2023-3512HigOct 4, 2023
    risk 0.49cvss 7.5epss 0.01

    Relative path traversal vulnerability in Setelsa Security's ConacWin CB, in its 3.8.2.2 version and earlier, the exploitation of which could allow an attacker to perform an arbitrary download of files from the system via the "Download file" parameter.

  • CVE-2023-26152HigOct 3, 2023
    risk 0.49cvss 7.5epss 0.01

    All versions of the package static-server are vulnerable to Directory Traversal due to improper input sanitization passed via the validPath function of server.js.