VYPR

CWE-22

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')

BaseStableLikelihood: High

Description

The product uses external input to construct a pathname that is intended to identify a file or directory that is located underneath a restricted parent directory, but the product does not properly neutralize special elements within the pathname that can cause the pathname to resolve to a location that is outside of the restricted directory.

Hierarchy (View 1000)

Parents

Children

Related attack patterns (CAPEC)

CAPEC-126 · CAPEC-64 · CAPEC-76 · CAPEC-78 · CAPEC-79

CVEs mapped to this weakness (10,395)

page 165 of 520
  • CVE-2021-43494HigNov 12, 2021
    risk 0.49cvss 7.5epss 0.03

    OpenCV-REST-API master branch as of commit 69be158c05d4dd5a4aff38fdc680a162dd6b9e49 is affected by a directory traversal vulnerability. This attack can cause the disclosure of critical secrets stored anywhere on the system and can significantly aid in getting remote code access.

  • CVE-2021-42021HigNov 9, 2021
    risk 0.49cvss 7.5epss 0.02

    A vulnerability has been identified in Siveillance Video DLNA Server (2019 R1), Siveillance Video DLNA Server (2019 R2), Siveillance Video DLNA Server (2019 R3), Siveillance Video DLNA Server (2020 R1), Siveillance Video DLNA Server (2020 R2), Siveillance Video DLNA Server (2020…

  • CVE-2021-33800HigNov 3, 2021
    risk 0.49cvss 7.5epss 0.02

    In Druid 1.2.3, visiting the path with parameter in a certain function can lead to directory traversal.

  • CVE-2020-18438HigNov 2, 2021
    risk 0.49cvss 7.5epss 0.02

    Directory traversal vulnerability in qinggan phpok 5.1, allows attackers to disclose sensitive information, via the title parameter to admin.php.

  • CVE-2021-37130HigOct 27, 2021
    risk 0.49cvss 7.5epss 0.01

    There is a path traversal vulnerability in Huawei FusionCube 6.0.2.The vulnerability is due to that the software uses external input to construct a pathname that is intended to identify a directory that is located underneath a restricted parent directory, but the software does…

  • CVE-2020-23061HigOct 22, 2021
    risk 0.49cvss 7.5epss 0.02

    Dropouts Technologies LLP Super Backup v2.0.5 was discovered to contain an issue in the path parameter of the `list` and `download` module which allows attackers to perform a directory traversal via a change to the path variable to request the local list command.

  • CVE-2020-23040HigOct 22, 2021
    risk 0.49cvss 7.5epss 0.02

    Sky File v2.1.0 contains a directory traversal vulnerability in the FTP server which allows attackers to access sensitive data and files via 'null' path commands.

  • CVE-2020-23038HigOct 22, 2021
    risk 0.49cvss 7.5epss 0.03

    Swift File Transfer Mobile v1.1.2 and below was discovered to contain an information disclosure vulnerability in the path parameter. This vulnerability is exploited via an error caused by including non-existent path environment variables.

  • CVE-2021-42261HigOct 19, 2021
    risk 0.49cvss 7.5epss 0.02

    Revisor Video Management System (VMS) before 2.0.0 has a directory traversal vulnerability. Successful exploitation could allow an attacker to traverse the file system to access files or directories that are outside of restricted directory on the remote server. This could lead…

  • CVE-2021-38460HigOct 12, 2021
    risk 0.49cvss 7.5epss 0.02

    A path traversal vulnerability in the Moxa MXview Network Management software Versions 3.x to 3.2.2 may allow an attacker to create or overwrite critical files used to execute code, such as programs or libraries.

  • CVE-2021-38452HigOct 12, 2021
    risk 0.49cvss 7.5epss 0.02

    A path traversal vulnerability in the Moxa MXview Network Management software Versions 3.x to 3.2.2 may allow an attacker to create or overwrite critical files used to execute code, such as programs or libraries.

  • CVE-2021-33726HigOct 12, 2021
    risk 0.49cvss 7.5epss 0.01

    A vulnerability has been identified in SINEC NMS (All versions < V1.0 SP2 Update 1). The affected system allows to download arbitrary files under a user controlled path and does not correctly check if the relative path is still within the intended target directory.

  • CVE-2021-25485HigOct 6, 2021
    risk 0.49cvss 7.5epss 0.00

    Path traversal vulnerability in FactoryAirCommnadManger prior to SMR Oct-2021 Release 1 allows attackers to write file as system UID via BT remote socket.

  • CVE-2021-35027HigSep 29, 2021
    risk 0.49cvss 7.5epss 0.02

    A directory traversal vulnerability in the web server of the Zyxel VPN2S firmware version 1.12 could allow a remote attacker to gain access to sensitive information.

  • CVE-2021-40103HigSep 27, 2021
    risk 0.49cvss 7.5epss 0.01

    An issue was discovered in Concrete CMS through 8.5.5. Path Traversal can lead to Arbitrary File Reading and SSRF.

  • CVE-2021-22013HigSep 23, 2021
    risk 0.49cvss 7.5epss 0.02

    The vCenter Server contains a file path traversal vulnerability leading to information disclosure in the appliance management API. A malicious actor with network access to port 443 on vCenter Server may exploit this issue to gain access to sensitive information.

  • CVE-2019-9060HigSep 17, 2021
    risk 0.49cvss 7.5epss 0.02

    An issue was discovered in CMS Made Simple 2.2.8. It is possible to achieve unauthenticated path traversal in the CGExtensions module (in the file action.setdefaulttemplate.php) with the m1_filename parameter; and through the action.showmessage.php file, it is possible to read…

  • CVE-2021-33692HigSep 15, 2021
    risk 0.49cvss 7.5epss 0.01

    SAP Cloud Connector, version - 2.0, allows the upload of zip files as backup. This backup file can be tricked to inject special elements such as '..' and '/' separators, for attackers to escape outside of the restricted location to access files or directories.

  • CVE-2021-39500HigSep 7, 2021
    risk 0.49cvss 7.5epss 0.01

    Eyoucms 1.5.4 is vulnerable to Directory Traversal. Due to a lack of input data sanitizaton in param tpldir, filename, type, nid an attacker can inject "../" to escape and write file to writeable directories.

  • CVE-2021-39109HigSep 1, 2021
    risk 0.49cvss 7.5epss 0.02

    The renderWidgetResource resource in Atlasian Atlasboard before version 1.1.9 allows remote attackers to read arbitrary files via a path traversal vulnerability.