VYPR

CWE-22

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')

BaseStableLikelihood: High

Description

The product uses external input to construct a pathname that is intended to identify a file or directory that is located underneath a restricted parent directory, but the product does not properly neutralize special elements within the pathname that can cause the pathname to resolve to a location that is outside of the restricted directory.

Hierarchy (View 1000)

Parents

Children

Related attack patterns (CAPEC)

CAPEC-126 · CAPEC-64 · CAPEC-76 · CAPEC-78 · CAPEC-79

CVEs mapped to this weakness (10,395)

page 157 of 520
  • CVE-2023-33510HigJun 7, 2023
    risk 0.49cvss 7.5epss 0.04

    Jeecg P3 Biz Chat 1.0.5 allows remote attackers to read arbitrary files through specific parameters.

  • CVE-2023-34407HigJun 5, 2023
    risk 0.49cvss 7.5epss 0.01

    OfflinePlayerService.exe in Harbinger Offline Player 4.0.6.0.2 allows directory traversal as LocalSystem via ..\ in a URL.

  • CVE-2023-27640HigJun 1, 2023
    risk 0.49cvss 7.5epss 0.04

    An issue was discovered in the tshirtecommerce (aka Custom Product Designer) component 2.1.4 for PrestaShop. An HTTP request can be forged with the POST parameter type in the /tshirtecommerce/fonts.php endpoint, to allow a remote attacker to traverse directories on the system in…

  • CVE-2023-27639HigJun 1, 2023
    risk 0.49cvss 7.5epss 0.04

    An issue was discovered in the tshirtecommerce (aka Custom Product Designer) component 2.1.4 for PrestaShop. An HTTP request can be forged with the POST parameter file_name in the tshirtecommerce/ajax.php?type=svg endpoint, to allow a remote attacker to traverse directories on…

  • CVE-2023-30197HigMay 31, 2023
    risk 0.49cvss 7.5epss 0.01

    Incorrect Access Control in the module "My inventory" (myinventory) <= 1.6.6 from Webbax for PrestaShop, allows a guest to download personal information without restriction by performing a path traversal attack.

  • CVE-2023-30196HigMay 30, 2023
    risk 0.49cvss 7.5epss 0.01

    Prestashop salesbooster <= 1.10.4 is vulnerable to Incorrect Access Control via modules/salesbooster/downloads/download.php.

  • CVE-2023-29380HigMay 29, 2023
    risk 0.49cvss 7.5epss 0.02

    Warpinator before 1.6.0 allows remote file deletion via directory traversal in top_dir_basenames.

  • CVE-2023-31861HigMay 25, 2023
    risk 0.49cvss 7.5epss 0.01

    ZLMediaKit 4.0 is vulnerable to Directory Traversal.

  • CVE-2023-27067HigMay 22, 2023
    risk 0.49cvss 7.5epss 0.02

    Directory Traversal vulnerability in Sitecore Experience Platform through 10.2 allows remote attackers to download arbitrary files via crafted command to download.aspx

  • CVE-2023-30199HigMay 19, 2023
    risk 0.49cvss 7.5epss 0.01

    Prestashop customexporter <= 1.7.20 is vulnerable to Incorrect Access Control via modules/customexporter/downloads/download.php.

  • CVE-2023-32767HigMay 17, 2023
    risk 0.49cvss 7.5epss 0.01

    The web interface of Symcon IP-Symcon before 6.3 (i.e., before 2023-05-12) allows a remote attacker to read sensitive files via .. directory-traversal sequences in the URL.

  • CVE-2023-31904HigMay 17, 2023
    risk 0.49cvss 7.5epss 0.01

    savysoda Wifi HD Wireless Disk Drive 11 is vulnerable to Local File Inclusion.

  • CVE-2023-31477HigMay 11, 2023
    risk 0.49cvss 7.5epss 0.01

    A path traversal issue was discovered on GL.iNet devices before 3.216. Through the file sharing feature, it is possible to share an arbitrary directory, such as /tmp or /etc, because there is no server-side restriction to limit sharing to the USB path.

  • CVE-2023-26126HigMay 10, 2023
    risk 0.49cvss 7.5epss 0.01

    All versions of the package m.static are vulnerable to Directory Traversal due to improper input sanitization of the path being requested via the requestFile function.

  • CVE-2023-31181HigMay 8, 2023
    risk 0.49cvss 7.5epss 0.01

    WJJ Software - InnoKB Server, InnoKB/Console 2.2.1 - CWE-22: Path Traversal

  • CVE-2017-20184HigMay 4, 2023
    risk 0.49cvss 7.5epss 0.03

    Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Carlo Gavazzi Powersoft up to version 2.1.1.1 allows an unauthenticated, remote attacker to download any file from the affected device.

  • CVE-2022-48483HigMay 2, 2023
    risk 0.49cvss 7.5epss 0.02

    3CX before 18 Hotfix 1 build 18.0.3.461 on Windows allows unauthenticated remote attackers to read %WINDIR%\system32 files via /Electron/download directory traversal in conjunction with a path component that has a drive letter and uses backslash characters. NOTE: this issue…

  • CVE-2022-48482HigMay 2, 2023
    risk 0.49cvss 7.5epss 0.02

    3CX before 18 Update 2 Security Hotfix build 18.0.2.315 on Windows allows unauthenticated remote attackers to read certain files via /Electron/download directory traversal. Files may have credentials, full backups, call recordings, and chat logs.

  • CVE-2023-31483HigApr 28, 2023
    risk 0.49cvss 7.5epss 0.01

    tar/TarFileReader.cpp in Cauldron cbang before bastet-v8.1.17 has a directory traversal during extraction that allows the attacker to create or write to files outside the current directory via a crafted tar archive.

  • CVE-2023-30380HigApr 27, 2023
    risk 0.49cvss 7.5epss 0.01

    An issue in the component /dialog/select_media.php of DedeCMS v5.7.107 allows attackers to execute a directory traversal.