VYPR

CWE-22

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')

BaseStableLikelihood: High

Description

The product uses external input to construct a pathname that is intended to identify a file or directory that is located underneath a restricted parent directory, but the product does not properly neutralize special elements within the pathname that can cause the pathname to resolve to a location that is outside of the restricted directory.

Hierarchy (View 1000)

Parents

Children

Related attack patterns (CAPEC)

CAPEC-126 · CAPEC-64 · CAPEC-76 · CAPEC-78 · CAPEC-79

CVEs mapped to this weakness (10,395)

page 166 of 520
  • CVE-2021-33555HigAug 31, 2021
    risk 0.49cvss 7.5epss 0.01

    In PEPPERL+FUCHS WirelessHART-Gateway <= 3.0.7 the filename parameter is vulnerable to unauthenticated path traversal attacks, enabling read access to arbitrary files on the server.

  • CVE-2021-38612HigAug 24, 2021
    risk 0.49cvss 7.5epss 0.02

    In NASCENT RemKon Device Manager 4.0.0.0, a Directory Traversal vulnerability in a log-reading function in maintenance/readLog.php allows an attacker to read any file via a specialized URL.

  • CVE-2021-23430HigAug 24, 2021
    risk 0.49cvss 7.5epss 0.02

    All versions of package startserver are vulnerable to Directory Traversal due to missing sanitization.

  • CVE-2021-38758HigAug 16, 2021
    risk 0.49cvss 7.5epss 0.02

    Directory traversal vulnerability in Online Catering Reservation System 1.0 exists due to lack of validation in index.php.

  • CVE-2015-2074HigAug 9, 2021
    risk 0.49cvss 7.5epss 0.04

    The File Repository Server (FRS) CORBA listener in SAP BussinessObjects Edge 4.0 allows remote attackers to write to arbitrary files via a full pathname, aka SAP Note 2018681.

  • CVE-2015-2073HigAug 9, 2021
    risk 0.49cvss 7.5epss 0.04

    The File RepositoRy Server (FRS) CORBA listener in SAP BussinessObjects Edge 4.0 allows remote attackers to read arbitrary files via a full pathname, aka SAP Note 2018682.

  • CVE-2021-35397HigAug 4, 2021
    risk 0.49cvss 7.5epss 0.04

    A path traversal vulnerability in the static router for Drogon from 1.0.0-beta14 to 1.6.0 could allow an unauthenticated, remote attacker to arbitrarily read files. The vulnerability is due to lack of proper input validation for requested path. An attacker could exploit this…

  • CVE-2020-19304HigAug 3, 2021
    risk 0.49cvss 7.5epss 0.02

    An issue in /admin/index.php?n=system&c=filept&a=doGetFileList of Metinfo v7.0.0 allows attackers to perform a directory traversal and access sensitive information.

  • CVE-2021-35054HigJul 20, 2021
    risk 0.49cvss 7.5epss 0.01

    Minecraft before 1.17.1, when online-mode=false is configured, allows path traversal for deletion of arbitrary JSON files.

  • CVE-2021-34820HigJul 19, 2021
    risk 0.49cvss 7.5epss 0.04

    Web Path Directory Traversal in the Novus HTTP Server. The Novus HTTP Server is affected by the Directory Traversal for Arbitrary File Access vulnerability. A remote, unauthenticated attacker using an HTTP GET request may be able to exploit this issue to access sensitive data.…

  • CVE-2021-35962HigJul 16, 2021
    risk 0.49cvss 7.5epss 0.02

    Specific page parameters in Dr. ID Door Access Control and Personnel Attendance Management system does not filter special characters. Remote attackers can apply Path Traversal means to download credential files from the system without permission.

  • CVE-2021-32532HigJul 7, 2021
    risk 0.49cvss 7.5epss 0.02

    Path traversal vulnerability in back-end analysis function in QSAN XEVO allows remote attackers to download arbitrary files without permissions. The referred vulnerability has been solved with the updated version of QSAN XEVO v2.1.0.

  • CVE-2021-32527HigJul 7, 2021
    risk 0.49cvss 7.5epss 0.02

    Path traversal vulnerability in QSAN Storage Manager allows remote unauthenticated attackers to download arbitrary files thru injecting file path in download function. Suggest contacting with QSAN and refer to recommendations in QSAN Document.

  • CVE-2021-32516HigJul 7, 2021
    risk 0.49cvss 7.5epss 0.02

    Path traversal vulnerability in share_link in QSAN Storage Manager allows remote attackers to download arbitrary files. The referred vulnerability has been solved with the updated version of QSAN Storage Manager v3.3.3.

  • CVE-2020-24143HigJul 7, 2021
    risk 0.49cvss 7.5epss 0.02

    Directory traversal in the Video Downloader for TikTok (aka downloader-tiktok) plugin 1.3 for WordPress lets an attacker get access to files that are stored outside the web root folder via the njt-tk-download-video parameter.

  • CVE-2021-29157HigJun 28, 2021
    risk 0.49cvss 7.5epss 0.00

    Dovecot before 2.3.15 allows ../ Path Traversal. An attacker with access to the local filesystem can trick OAuth2 authentication into using an HS256 validation key from an attacker-controlled location. This occurs during use of local JWT validation with the posix fs driver.

  • CVE-2021-29087HigJun 23, 2021
    risk 0.49cvss 7.5epss 0.01

    Improper limitation of a pathname to a restricted directory ('Path Traversal') vulnerability in webapi component in Synology DiskStation Manager (DSM) before 6.2.3-25426-3 allows remote attackers to write arbitrary files via unspecified vectors.

  • CVE-2021-31538HigJun 10, 2021
    risk 0.49cvss 7.5epss 0.01

    LANCOM R&S Unified Firewall (UF) devices running LCOS FX 10.5 allow Relative Path Traversal.

  • CVE-2021-30465HigMay 27, 2021
    risk 0.49cvss 8.5epss 0.07

    runc before 1.0.0-rc95 allows a Container Filesystem Breakout via Directory Traversal. To exploit the vulnerability, an attacker must be able to create multiple containers with a fairly specific mount configuration. The problem occurs via a symlink-exchange attack that relies on…

  • CVE-2021-22736HigMay 26, 2021
    risk 0.49cvss 7.5epss 0.01

    Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability exists in homeLYnk (Wiser For KNX) and spaceLYnk V2.60 and prior which could cause a denial of service when an unauthorized file is uploaded.