VYPR

CWE-22

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')

BaseStableLikelihood: High

Description

The product uses external input to construct a pathname that is intended to identify a file or directory that is located underneath a restricted parent directory, but the product does not properly neutralize special elements within the pathname that can cause the pathname to resolve to a location that is outside of the restricted directory.

Hierarchy (View 1000)

Parents

Children

Related attack patterns (CAPEC)

CAPEC-126 · CAPEC-64 · CAPEC-76 · CAPEC-78 · CAPEC-79

CVEs mapped to this weakness (10,395)

page 169 of 520
  • CVE-2020-24624HigSep 23, 2020
    risk 0.49cvss 7.5epss 0.02

    Unathenticated directory traversal in the DownloadServlet class execute() method can lead to arbitrary file reads in HPE Pay Per Use (PPU) Utility Computing Service (UCS) Meter version 1.9.

  • CVE-2020-25248HigSep 11, 2020
    risk 0.49cvss 7.5epss 0.02

    An issue was discovered in Hyland OnBase through 16.0.2.83 and below, 17.0.2.109 and below, 18.0.0.37 and below, 19.8.16.1000 and below and 20.3.10.1000 and below. Directory traversal exists for reading files, as demonstrated by the FileName parameter.

  • CVE-2020-25247HigSep 11, 2020
    risk 0.49cvss 7.5epss 0.01

    An issue was discovered in Hyland OnBase through 18.0.0.32 and 19.x through 19.8.9.1000. Directory traversal exists for writing to files, as demonstrated by the FileName parameter.

  • CVE-2020-25068HigSep 3, 2020
    risk 0.49cvss 7.5epss 0.04

    Setelsa Conacwin v3.7.1.2 is vulnerable to a local file inclusion vulnerability. This vulnerability allows a remote unauthenticated attacker to read internal files on the server via an http:IP:PORT/../../path/file_to_disclose Directory Traversal URI. NOTE: The manufacturer…

  • CVE-2020-15641HigAug 25, 2020
    risk 0.49cvss 7.5epss 0.03

    This vulnerability allows remote attackers to disclose sensitive information on affected installations of Marvell QConvergeConsole 5.5.0.64. Authentication is not required to exploit this vulnerability. The specific flaw exists within the getFileUploadBytes method of the…

  • CVE-2020-15640HigAug 25, 2020
    risk 0.49cvss 7.5epss 0.03

    This vulnerability allows remote attackers to disclose sensitive information on affected installations of Marvell QConvergeConsole 5.5.0.64. Authentication is not required to exploit this vulnerability. The specific flaw exists within the getFileUploadBytes method of the…

  • CVE-2020-17385HigAug 25, 2020
    risk 0.49cvss 7.5epss 0.02

    Cellopoint CelloOS v4.1.10 Build 20190922 does not validate URL inputted properly, which allows unauthorized user to launch Path Traversal attack and access arbitrate file on the system.

  • CVE-2020-24368HigAug 19, 2020
    risk 0.49cvss 7.5epss 0.03

    Icinga Icinga Web2 2.0.0 through 2.6.4, 2.7.4 and 2.8.2 has a Directory Traversal vulnerability which allows an attacker to access arbitrary files that are readable by the process running Icinga Web 2. This issue is fixed in Icinga Web 2 in v2.6.4, v2.7.4 and v2.8.2.

  • CVE-2020-15592HigJul 27, 2020
    risk 0.49cvss 7.5epss 0.02

    SteelCentral Aternity Agent before 11.0.0.120 on Windows allows Privilege Escalation via a crafted file. It uses an executable running as a high privileged Windows service to perform administrative tasks and collect data from other processes. It distributes functionality among…

  • CVE-2020-7687HigJul 25, 2020
    risk 0.49cvss 7.5epss 0.02

    This affects all versions of package fast-http. There is no path sanitization in the path provided at fs.readFile in index.js.

  • CVE-2020-7686HigJul 25, 2020
    risk 0.49cvss 7.5epss 0.02

    This affects all versions of package rollup-plugin-dev-server. There is no path sanitization in readFile operation inside the readFileFromContentBase function.

  • CVE-2020-7683HigJul 25, 2020
    risk 0.49cvss 7.5epss 0.02

    This affects all versions of package rollup-plugin-server. There is no path sanitization in readFile operation performed inside the readFileFromContentBase function.

  • CVE-2020-7682HigJul 25, 2020
    risk 0.49cvss 7.5epss 0.02

    This affects all versions of package marked-tree. There is no path sanitization in the path provided at fs.readFile in index.js.

  • CVE-2020-7681HigJul 25, 2020
    risk 0.49cvss 7.5epss 0.02

    This affects all versions of package marscode. There is no path sanitization in the path provided at fs.readFile in index.js.

  • CVE-2020-15923HigJul 24, 2020
    risk 0.49cvss 7.5epss 0.03

    Mida eFramework through 2.9.0 allows unauthenticated ../ directory traversal.

  • CVE-2020-8214HigJul 20, 2020
    risk 0.49cvss 7.5epss 0.02

    A path traversal vulnerability in servey version < 3 allows an attacker to read content of any arbitrary file.

  • CVE-2020-15779HigJul 15, 2020
    risk 0.49cvss 7.5epss 0.02

    A Path Traversal issue was discovered in the socket.io-file package through 2.0.31 for Node.js. The socket.io-file::createFile message uses path.join with ../ in the name option, and the uploadDir and rename options determine the path.

  • CVE-2020-8161HigJul 2, 2020
    risk 0.49cvss 8.6epss 0.03

    A directory traversal vulnerability exists in rack < 2.2.0 that allows an attacker perform directory traversal vulnerability in the Rack::Directory app that is bundled with Rack which could result in information disclosure.

  • CVE-2020-12003HigJun 15, 2020
    risk 0.49cvss 7.5epss 0.05

    FactoryTalk Linx versions 6.00, 6.10, and 6.11, RSLinx Classic v4.11.00 and prior,Connected Components Workbench: Version 12 and prior, ControlFLASH: Version 14 and later, ControlFLASH Plus: Version 1 and later, FactoryTalk Asset Centre: Version 9 and later, FactoryTalk Linx…

  • CVE-2020-13836HigJun 4, 2020
    risk 0.49cvss 7.5epss 0.00

    An issue was discovered on Samsung mobile devices with O(8.x), P(9.0), and Q(10.0) software. HWRResProvider allows path traversal for data exposure. The Samsung ID is SVE-2020-16954 (June 2020).