VYPR

CWE-22

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')

BaseStableLikelihood: High

Description

The product uses external input to construct a pathname that is intended to identify a file or directory that is located underneath a restricted parent directory, but the product does not properly neutralize special elements within the pathname that can cause the pathname to resolve to a location that is outside of the restricted directory.

Hierarchy (View 1000)

Parents

Children

Related attack patterns (CAPEC)

CAPEC-126 · CAPEC-64 · CAPEC-76 · CAPEC-78 · CAPEC-79

CVEs mapped to this weakness (10,395)

page 159 of 520
  • CVE-2022-39059HigJan 31, 2023
    risk 0.49cvss 7.5epss 0.01

    ChangingTech MegaServiSignAdapter component has a path traversal vulnerability within its file reading function. An unauthenticated remote attacker can exploit this vulnerability to access arbitrary system files.

  • CVE-2022-38451HigJan 30, 2023
    risk 0.49cvss 7.5epss 0.02

    A directory traversal vulnerability exists in the httpd update.cgi functionality of FreshTomato 2022.5. A specially crafted HTTP request can lead to arbitrary file read. An attacker can send an HTTP request to trigger this vulnerability.

  • CVE-2022-39812HigJan 27, 2023
    risk 0.49cvss 7.5epss 0.01

    Italtel NetMatch-S CI 5.2.0-20211008 allows Absolute Path Traversal under NMSCI-WebGui/SaveFileUploader. An unauthenticated user can upload files to an arbitrary path. An attacker can change the uploadDir parameter in a POST request (not possible using the GUI) to an arbitrary…

  • CVE-2019-25053HigJan 27, 2023
    risk 0.49cvss 7.5epss 0.01

    A path traversal vulnerability exists in Sage FRP 1000 before November 2019. This allows remote unauthenticated attackers to access files outside of the web tree via a crafted URL.

  • CVE-2022-43864HigJan 26, 2023
    risk 0.49cvss 7.5epss 0.02

    IBM Business Automation Workflow 22.0.2 could allow a remote attacker to traverse directories on the system. An attacker could send a specially crafted URL request containing "dot dot" sequences (/../) to view arbitrary files on the system. IBM X-Force ID: 239427.

  • CVE-2022-21192HigJan 26, 2023
    risk 0.49cvss 7.5epss 0.01

    All versions of the package serve-lite are vulnerable to Directory Traversal due to missing input sanitization or other checks and protections employed to the req.url passed as-is to path.join().

  • CVE-2022-46639HigJan 23, 2023
    risk 0.49cvss 7.5epss 0.01

    A vulnerability in the descarga_etiqueta.php component of Correos Prestashop 1.7.x allows attackers to execute a directory traversal.

  • CVE-2022-47747HigJan 20, 2023
    risk 0.49cvss 7.5epss 0.01

    kraken <= 0.1.4 has an arbitrary file read vulnerability via the component testfs.

  • CVE-2022-43975HigJan 17, 2023
    risk 0.49cvss 7.5epss 0.01

    An issue was discovered in FC46-WebBridge on GE Grid Solutions MS3000 devices before 3.7.6.25p0_3.2.2.17p0_4.7p0. A vulnerability in the web server allows arbitrary files and configurations to be read via directory traversal over TCP port 8888.

  • CVE-2022-3693HigJan 13, 2023
    risk 0.49cvss 7.5epss 0.01

    Path Traversal vulnerability in Deytek Informatics FileOrbis File Management System allows Path Traversal. This issue affects FileOrbis File Management System: from unspecified before 10.6.3.

  • CVE-2022-4636HigJan 10, 2023
    risk 0.49cvss 7.5epss 0.01

    Black Box KVM Firmware version 3.4.31307 on models ACR1000A-R-R2, ACR1000A-T-R2, ACR1002A-T, ACR1002A-R, and ACR1020A-T is vulnerable to path traversal, which may allow an attacker to steal user credentials and other sensitive information through local file inclusion.

  • CVE-2023-22320HigJan 10, 2023
    risk 0.49cvss 7.5epss 0.01

    OpenAM Web Policy Agent (OpenAM Consortium Edition) provided by OpenAM Consortium parses URLs improperly, leading to a path traversal vulnerability(CWE-22). Furthermore, a crafted URL may be evaluated incorrectly.

  • CVE-2022-39040HigJan 3, 2023
    risk 0.49cvss 7.5epss 0.02

    aEnrich a+HRD log read function has a path traversal vulnerability. An unauthenticated remote attacker can exploit this vulnerability to bypass authentication and download arbitrary system files.

  • CVE-2022-4779HigDec 29, 2022
    risk 0.49cvss 7.5epss 0.01

    StreamX applications from versions 6.02.01 to 6.04.34 are affected by a logic bug that allows to bypass the implemented authentication scheme. StreamX applications using StreamView HTML component with the public web server feature activated are affected.

  • CVE-2022-38202HigDec 28, 2022
    risk 0.49cvss 7.5epss 0.01

    There is a path traversal vulnerability in Esri ArcGIS Server versions 10.9.1 and below. Successful exploitation may allow a remote, unauthenticated attacker traverse the file system to access files outside of the intended directory on ArcGIS Server. This could lead to the…

  • CVE-2022-44016HigDec 25, 2022
    risk 0.49cvss 7.5epss 0.01

    An issue was discovered in Simmeth Lieferantenmanager before 5.6. An attacker can download arbitrary files from the web server by abusing an API call: /DS/LM_API/api/ConfigurationService/GetImages with an '"ImagesPath":"C:\\"' value.

  • CVE-2022-25895HigDec 21, 2022
    risk 0.49cvss 7.5epss 0.01

    All versions of package lite-dev-server are vulnerable to Directory Traversal due to missing input sanitization and sandboxes being employed to the req.url user input that is passed to the server code.

  • CVE-2022-41591HigDec 20, 2022
    risk 0.49cvss 7.5epss 0.01

    The backup module has a path traversal vulnerability. Successful exploitation of this vulnerability causes unauthorized access to other system files.

  • CVE-2021-46856HigDec 20, 2022
    risk 0.49cvss 7.5epss 0.01

    The multi-screen collaboration module has a path traversal vulnerability. Successful exploitation of this vulnerability may affect data confidentiality.

  • CVE-2022-25931HigDec 20, 2022
    risk 0.49cvss 7.5epss 0.01

    All versions of package easy-static-server are vulnerable to Directory Traversal due to missing input sanitization and sandboxes being employed to the req.url user input that is passed to the server code.