VYPR

CWE-22

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')

BaseStableLikelihood: High

Description

The product uses external input to construct a pathname that is intended to identify a file or directory that is located underneath a restricted parent directory, but the product does not properly neutralize special elements within the pathname that can cause the pathname to resolve to a location that is outside of the restricted directory.

Hierarchy (View 1000)

Parents

Children

Related attack patterns (CAPEC)

CAPEC-126 · CAPEC-64 · CAPEC-76 · CAPEC-78 · CAPEC-79

CVEs mapped to this weakness (10,395)

page 167 of 520
  • CVE-2021-27461HigMay 20, 2021
    risk 0.49cvss 7.5epss 0.01

    A vulnerability has been found in multiple revisions of Emerson Rosemount X-STREAM Gas Analyzer. The affected webserver applications allow access to stored data that can be obtained by using specially crafted URLs.

  • CVE-2021-32572HigMay 12, 2021
    risk 0.49cvss 7.5epss 0.02

    Speco Web Viewer through 2021-05-12 allows Directory Traversal via GET request for a URI with /.. at the beginning, as demonstrated by reading the /etc/passwd file.

  • CVE-2021-29101HigMay 5, 2021
    risk 0.49cvss 7.5epss 0.02

    ArcGIS GeoEvent Server versions 10.8.1 and below has a read-only directory path traversal vulnerability that could allow an unauthenticated, remote attacker to perform directory traversal attacks and read arbitrary files on the system.

  • CVE-2021-22720HigApr 13, 2021
    risk 0.49cvss 7.2epss 0.31

    A CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability exists in C-Bus Toolkit (V1.15.7 and prior) that could allow a remote code execution when restoring a project.

  • CVE-2021-28172HigApr 6, 2021
    risk 0.49cvss 7.5epss 0.02

    There is a Path Traversal vulnerability in the file download function of Vangene deltaFlow E-platform. Remote attackers can access credential data with this leakage.

  • CVE-2020-10584HigMar 25, 2021
    risk 0.49cvss 7.5epss 0.02

    A directory traversal on the /admin/search_by.php script of Invigo Automatic Device Management (ADM) through 5.0 allows remote attackers to read arbitrary server files accessible to the user running the application.

  • CVE-2020-10579HigMar 25, 2021
    risk 0.49cvss 7.5epss 0.02

    A directory traversal on the /admin/sysmon.php script of Invigo Automatic Device Management (ADM) through 5.0 allows remote attackers to list the content of arbitrary server directories accessible to the user running the application.

  • CVE-2020-13924HigMar 17, 2021
    risk 0.49cvss 7.5epss 0.04

    In Apache Ambari versions 2.6.2.2 and earlier, malicious users can construct file names for directory traversal and traverse to other directories to download files.

  • CVE-2020-9050HigFeb 19, 2021
    risk 0.49cvss 7.5epss 0.04

    Path Traversal vulnerability exists in Metasys Reporting Engine (MRE) Web Services which could allow a remote unauthenticated attacker to access and download arbitrary files from the system.

  • CVE-2021-20354HigFeb 18, 2021
    risk 0.49cvss 7.5epss 0.04

    IBM WebSphere Application Server 8.0, 8.5, and 9.0 could allow a remote attacker to traverse directories. An attacker could send a specially-crafted URL request containing "dot dot" sequences (/../) to view arbitrary files on the system. IBM X-Force ID: 194883.

  • CVE-2021-22857HigFeb 17, 2021
    risk 0.49cvss 7.5epss 0.02

    The CGE page with download function contains a Directory Traversal vulnerability. Attackers can use this loophole to download system files arbitrarily.

  • CVE-2021-22656HigFeb 11, 2021
    risk 0.49cvss 7.5epss 0.03

    Advantech iView versions prior to v5.7.03.6112 are vulnerable to directory traversal, which may allow an attacker to read sensitive files.

  • CVE-2021-21475HigFeb 9, 2021
    risk 0.49cvss 7.5epss 0.02

    Under specific circumstances SAP Master Data Management, versions - 710, 710.750, allows an unauthorized attacker to exploit insufficient validation of path information provided by users, thus characters representing 'traverse to parent directory' are passed through to the file…

  • CVE-2021-1297HigFeb 4, 2021
    risk 0.49cvss 7.5epss 0.04

    Multiple vulnerabilities in the web-based management interface of Cisco Small Business RV160, RV160W, RV260, RV260P, and RV260W VPN Routers could allow an unauthenticated, remote attacker to conduct directory traversal attacks and overwrite certain files that should be…

  • CVE-2021-1296HigFeb 4, 2021
    risk 0.49cvss 7.5epss 0.04

    Multiple vulnerabilities in the web-based management interface of Cisco Small Business RV160, RV160W, RV260, RV260P, and RV260W VPN Routers could allow an unauthenticated, remote attacker to conduct directory traversal attacks and overwrite certain files that should be…

  • CVE-2020-29166HigFeb 3, 2021
    risk 0.49cvss 7.5epss 0.02

    PacsOne Server (PACS Server In One Box) below 7.1.1 is affected by file read/manipulation, which can result in remote information disclosure.

  • CVE-2020-20290HigFeb 1, 2021
    risk 0.49cvss 7.5epss 0.01

    Directory traversal vulnerability in the yccms 3.3 project. The delete, deletesite, and deleteAll functions' improper judgment of the request parameters, triggers a directory traversal vulnerability.

  • CVE-2021-3341HigJan 29, 2021
    risk 0.49cvss 7.5epss 0.01

    A path traversal vulnerability in the DxWebEngine component of DH2i DxEnterprise and DxOdyssey for Windows, version 19.5 through 20.x before 20.0.219.0, allows an attacker to read any file on the host file system via an HTTP request.

  • CVE-2021-25864HigJan 26, 2021
    risk 0.49cvss 7.5epss 0.09

    node-red-contrib-huemagic 3.0.0 is affected by hue/assets/..%2F Directory Traversal.in the res.sendFile API, used in file hue-magic.js, to fetch an arbitrary file.

  • CVE-2020-27859HigJan 20, 2021
    risk 0.49cvss 7.5epss 0.03

    This vulnerability allows remote attackers to disclose sensitive information on affected installations of NEC ESMPRO Manager 6.42. Authentication is not required to exploit this vulnerability. The specific flaw exists within the GetEuaLogDownloadAction class. The issue results…