VYPR

CWE-22

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')

BaseStableLikelihood: High

Description

The product uses external input to construct a pathname that is intended to identify a file or directory that is located underneath a restricted parent directory, but the product does not properly neutralize special elements within the pathname that can cause the pathname to resolve to a location that is outside of the restricted directory.

Hierarchy (View 1000)

Parents

Children

Related attack patterns (CAPEC)

CAPEC-126 · CAPEC-64 · CAPEC-76 · CAPEC-78 · CAPEC-79

CVEs mapped to this weakness (10,395)

page 168 of 520
  • CVE-2020-13449HigJan 7, 2021
    risk 0.49cvss 7.5epss 0.05

    A directory traversal vulnerability in the Markdown engine of Gotenberg through 6.2.1 allows an attacker to read any container files.

  • CVE-2020-36051HigJan 5, 2021
    risk 0.49cvss 7.5epss 0.02

    Directory traversal vulnerability in page_edit.php in MiniCMS V1.10 allows remote attackers to read arbitrary files via the state parameter.

  • CVE-2020-22550HigJan 4, 2021
    risk 0.49cvss 7.5epss 0.02

    Veno File Manager 3.5.6 is affected by a directory traversal vulnerability. Using the traversal allows an attacker to download sensitive files from the server.

  • CVE-2020-35612HigDec 28, 2020
    risk 0.49cvss 7.5epss 0.02

    An issue was discovered in Joomla! 2.5.0 through 3.9.22. The folder parameter of mod_random_image lacked input validation, leading to a path traversal vulnerability.

  • CVE-2020-35362HigDec 26, 2020
    risk 0.49cvss 7.5epss 0.02

    DEXT5Upload 2.7.1262310 and earlier is affected by Directory Traversal in handler/dext5handler.jsp. This could allow remote files to be downloaded via a dext5CMD=downloadRequest action with traversal in the fileVirtualPath parameter (the attacker must provide the correct…

  • CVE-2020-35284HigDec 26, 2020
    risk 0.49cvss 7.5epss 0.02

    Flamingo (aka FlamingoIM) through 2020-09-29 allows ../ directory traversal because the only ostensibly unpredictable part of a file-transfer request is an MD5 computation; however, this computation occurs on the client side, and the computation details can be easily determined…

  • CVE-2020-8463HigDec 17, 2020
    risk 0.49cvss 7.5epss 0.06

    A vulnerability in Trend Micro InterScan Web Security Virtual Appliance 6.5 SP2 could allow an attacker to bypass a global authorization check for anonymous users by manipulating request paths.

  • CVE-2020-7535HigDec 11, 2020
    risk 0.49cvss 7.5epss 0.01

    A CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal' Vulnerability Type) vulnerability exists in the Web Server on Modicon M340, Legacy Offers Modicon Quantum and Modicon Premium and associated Communication Modules (see security notification…

  • CVE-2020-28993HigDec 1, 2020
    risk 0.49cvss 7.5epss 0.03

    A Directory Traversal vulnerability exists in ATX miniCMTS200a Broadband Gateway through 2.0 and Pico CMTS through 2.0. Successful exploitation of this vulnerability would allow an unauthenticated attacker to retrieve administrator credentials by sending a malicious POST request.

  • CVE-2017-15684HigNov 27, 2020
    risk 0.49cvss 7.5epss 0.02

    Crafter CMS Crafter Studio 3.0.1 has a directory traversal vulnerability which allows unauthenticated attackers to view files from the operating system.

  • CVE-2020-13355HigNov 19, 2020
    risk 0.49cvss 7.5epss 0.02

    An issue has been discovered in GitLab CE/EE affecting all versions starting from 8.14. A path traversal is found in LFS Upload that allows attacker to overwrite certain specific paths on the server. Affected versions are: >=8.14, <13.3.9,>=13.4, <13.4.5,>=13.5, <13.5.2.

  • CVE-2020-28574HigNov 18, 2020
    risk 0.49cvss 7.5epss 0.03

    A unauthenticated path traversal arbitrary remote file deletion vulnerability in Trend Micro Worry-Free Business Security 10 SP1 could allow an unauthenticated attacker to exploit the vulnerability and modify or delete arbitrary files on the product's management console.

  • CVE-2020-27553HigNov 17, 2020
    risk 0.49cvss 7.5epss 0.02

    In BASETech GE-131 BT-1837836 firmware 20180921, the web-server on the system is configured with the option “DocumentRoot /etc“. This allows an attacker with network access to the web-server to download any files from the “/etc” folder without authentication. No path…

  • CVE-2020-9368HigNov 2, 2020
    risk 0.49cvss 7.5epss 0.02

    The Module Olea Gift On Order module through 5.0.8 for PrestaShop enables an unauthenticated user to read arbitrary files on the server via getfile.php?file=/.. directory traversal.

  • CVE-2020-24990HigOct 28, 2020
    risk 0.49cvss 7.5epss 0.04

    An issue was discovered in QSC Q-SYS Core Manager 8.2.1. By utilizing the TFTP service running on UDP port 69, a remote attacker can perform a directory traversal and obtain operating system files via a TFTP GET request, as demonstrated by reading /etc/passwd or /proc/version.

  • CVE-2020-9782HigOct 27, 2020
    risk 0.49cvss 7.5epss 0.01

    A parsing issue in the handling of directory paths was addressed with improved path validation. This issue is fixed in macOS Catalina 10.15.2, Security Update 2019-002 Mojave, and Security Update 2019-007 High Sierra. A remote attacker may be able to overwrite existing files.

  • CVE-2020-4776HigOct 12, 2020
    risk 0.49cvss 7.5epss 0.02

    A path traversal vulnerability may impact IBM Curam Social Program Management 7.0.9 and 7.0.10, which could allow a remote attacker to traverse directories on the system. An attacker could send a specially-crafted file path in URL request to view arbitrary files on the system.…

  • CVE-2020-25623HigOct 2, 2020
    risk 0.49cvss 7.5epss 0.03

    Erlang/OTP 22.3.x before 22.3.4.6 and 23.x before 23.1 allows Directory Traversal. An attacker can send a crafted HTTP request to read arbitrary files, if httpd in the inets application is used.

  • CVE-2020-21525HigSep 30, 2020
    risk 0.49cvss 7.5epss 0.02

    Halo V1.1.3 is affected by: Arbitrary File reading. In an interface that reads files in halo v1.1.3, a directory traversal check is performed on the input path parameter, but the startsWith function can be used to bypass it.

  • CVE-2020-24625HigSep 23, 2020
    risk 0.49cvss 7.5epss 0.02

    Unathenticated directory traversal in the ReceiverServlet class doGet() method can lead to arbitrary file reads in HPE Pay Per Use (PPU) Utility Computing Service (UCS) Meter version 1.9.