VYPR

CWE-22

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')

BaseStableLikelihood: High

Description

The product uses external input to construct a pathname that is intended to identify a file or directory that is located underneath a restricted parent directory, but the product does not properly neutralize special elements within the pathname that can cause the pathname to resolve to a location that is outside of the restricted directory.

Hierarchy (View 1000)

Parents

Children

Related attack patterns (CAPEC)

CAPEC-126 · CAPEC-64 · CAPEC-76 · CAPEC-78 · CAPEC-79

CVEs mapped to this weakness (10,395)

page 164 of 520
  • CVE-2021-46104HigJan 19, 2022
    risk 0.49cvss 7.5epss 0.05

    An issue was discovered in webp_server_go 0.4.0. There is a directory traversal vulnerability that can read arbitrary file information on the server.

  • CVE-2021-44586HigJan 10, 2022
    risk 0.49cvss 7.5epss 0.01

    An issue was discovered in dst-admin v1.3.0. The product has an unauthorized arbitrary file download vulnerability that can expose sensitive information.

  • CVE-2020-29050HigJan 10, 2022
    risk 0.49cvss 7.5epss 0.02

    SphinxSearch in Sphinx Technologies Sphinx through 3.1.1 allows directory traversal (in conjunction with CVE-2019-14511) because the mysql client can be used for CALL SNIPPETS and load_file operations on a full pathname (e.g., a file in the /etc directory). NOTE: this is…

  • CVE-2021-44351HigJan 6, 2022
    risk 0.49cvss 7.5epss 0.02

    An arbitrary file read vulnerability exists in NavigateCMS 2.9 via /navigate/navigate_download.php id parameter.

  • CVE-2021-39970HigJan 3, 2022
    risk 0.49cvss 7.5epss 0.01

    HwPCAssistant has a Improper Input Validation vulnerability.Successful exploitation of this vulnerability may create any file with the system app permission.

  • CVE-2021-37126HigJan 3, 2022
    risk 0.49cvss 7.5epss 0.01

    Arbitrary file has a Exposure of Sensitive Information to an Unauthorized Actor vulnerability .Successful exploitation of this vulnerability may cause the directory is traversed.

  • CVE-2021-45712HigDec 26, 2021
    risk 0.49cvss 7.5epss 0.02

    An issue was discovered in the rust-embed crate before 6.3.0 for Rust. A ../ directory traversal can sometimes occur in debug mode.

  • CVE-2021-44162HigDec 20, 2021
    risk 0.49cvss 7.5epss 0.02

    Chain Sea ai chatbot system’s specific file download function has path traversal vulnerability. The function has improper filtering of special characters in URL parameters, which allows a remote attacker to download arbitrary system files without authentication.

  • CVE-2021-23797HigDec 17, 2021
    risk 0.49cvss 7.5epss 0.02

    All versions of package http-server-node are vulnerable to Directory Traversal via use of --path-as-is.

  • CVE-2021-44965HigDec 13, 2021
    risk 0.49cvss 7.5epss 0.02

    Directory traversal vulnerability in /admin/includes/* directory for PHPGURUKUL Employee Record Management System 1.2 The attacker can retrieve and download sensitive information from the vulnerable server.

  • CVE-2021-41024HigDec 8, 2021
    risk 0.49cvss 7.5epss 0.02

    A relative path traversal [CWE-23] vulnerabiltiy in FortiOS versions 7.0.0 and 7.0.1 and FortiProxy verison 7.0.0 may allow an unauthenticated, unauthorized attacker to inject path traversal character sequences to disclose sensitive information of the server via the GET request…

  • CVE-2021-44725HigDec 8, 2021
    risk 0.49cvss 7.5epss 0.02

    KNIME Server before 4.13.4 allows directory traversal in a request for a client profile.

  • CVE-2021-43358HigDec 1, 2021
    risk 0.49cvss 7.5epss 0.02

    Sunnet eHRD has inadequate filtering for special characters in URLs, which allows a remote attacker to perform path traversal attacks without authentication, access restricted paths and download system files.

  • CVE-2021-43775HigNov 23, 2021
    risk 0.49cvss 8.6epss 0.02

    Aim is an open-source, self-hosted machine learning experiment tracking tool. Versions of Aim prior to 3.1.0 are vulnerable to a path traversal attack. By manipulating variables that reference files with “dot-dot-slash (../)” sequences and its variations or by using absolute…

  • CVE-2021-24644HigNov 23, 2021
    risk 0.49cvss 7.5epss 0.05

    The Images to WebP WordPress plugin before 1.9 does not validate or sanitise the tab parameter before passing it to the include() function, which could lead to a Local File Inclusion issue

  • CVE-2020-7882HigNov 22, 2021
    risk 0.49cvss 7.5epss 0.01

    Using the parameter of getPFXFolderList function, attackers can see the information of authorization certification and delete the files. It occurs because the parameter contains path traversal characters(ie. '../../../')

  • CVE-2021-40745HigNov 17, 2021
    risk 0.49cvss 7.5epss 0.04

    Adobe Campaign version 21.2.1 (and earlier) is affected by a Path Traversal vulnerability that could lead to reading arbitrary server files. By leveraging an exposed XML file, an unauthenticated attacker can enumerate other files on the server.

  • CVE-2021-43495HigNov 15, 2021
    risk 0.49cvss 7.5epss 0.09

    AlquistManager branch as of commit 280d99f43b11378212652e75f6f3159cde9c1d36 is affected by a directory traversal vulnerability in alquist/IO/input.py. This attack can cause the disclosure of critical secrets stored anywhere on the system and can significantly aid in getting…

  • CVE-2021-43493HigNov 12, 2021
    risk 0.49cvss 7.5epss 0.02

    ServerManagement master branch as of commit 49491cc6f94980e6be7791d17be947c27071eb56 is affected by a directory traversal vulnerability. This vulnerability can be used to extract credentials which can in turn be used to execute code.

  • CVE-2021-43492HigNov 12, 2021
    risk 0.49cvss 7.5epss 0.04

    AlquistManager branch as of commit 280d99f43b11378212652e75f6f3159cde9c1d36 is affected by a directory traversal vulnerability. This attack can cause the disclosure of critical secrets stored anywhere on the system andcan significantly aid in getting remote code access.