CWE-22
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
Description
The product uses external input to construct a pathname that is intended to identify a file or directory that is located underneath a restricted parent directory, but the product does not properly neutralize special elements within the pathname that can cause the pathname to resolve to a location that is outside of the restricted directory.
Hierarchy (View 1000)
Related attack patterns (CAPEC)
CAPEC-126 · CAPEC-64 · CAPEC-76 · CAPEC-78 · CAPEC-79
CVEs mapped to this weakness (10,395)
page 169 of 520| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2020-24624 | Hig | 0.49 | 7.5 | 0.02 | Sep 23, 2020 | Unathenticated directory traversal in the DownloadServlet class execute() method can lead to arbitrary file reads in HPE Pay Per Use (PPU) Utility Computing Service (UCS) Meter version 1.9. | ||
| CVE-2020-25248 | Hig | 0.49 | 7.5 | 0.02 | Sep 11, 2020 | An issue was discovered in Hyland OnBase through 16.0.2.83 and below, 17.0.2.109 and below, 18.0.0.37 and below, 19.8.16.1000 and below and 20.3.10.1000 and below. Directory traversal exists for reading files, as demonstrated by the FileName parameter. | ||
| CVE-2020-25247 | Hig | 0.49 | 7.5 | 0.01 | Sep 11, 2020 | An issue was discovered in Hyland OnBase through 18.0.0.32 and 19.x through 19.8.9.1000. Directory traversal exists for writing to files, as demonstrated by the FileName parameter. | ||
| CVE-2020-25068 | Hig | 0.49 | 7.5 | 0.04 | Sep 3, 2020 | Setelsa Conacwin v3.7.1.2 is vulnerable to a local file inclusion vulnerability. This vulnerability allows a remote unauthenticated attacker to read internal files on the server via an http:IP:PORT/../../path/file_to_disclose Directory Traversal URI. NOTE: The manufacturer… | ||
| CVE-2020-15641 | Hig | 0.49 | 7.5 | 0.03 | Aug 25, 2020 | This vulnerability allows remote attackers to disclose sensitive information on affected installations of Marvell QConvergeConsole 5.5.0.64. Authentication is not required to exploit this vulnerability. The specific flaw exists within the getFileUploadBytes method of the… | ||
| CVE-2020-15640 | Hig | 0.49 | 7.5 | 0.03 | Aug 25, 2020 | This vulnerability allows remote attackers to disclose sensitive information on affected installations of Marvell QConvergeConsole 5.5.0.64. Authentication is not required to exploit this vulnerability. The specific flaw exists within the getFileUploadBytes method of the… | ||
| CVE-2020-17385 | Hig | 0.49 | 7.5 | 0.02 | Aug 25, 2020 | Cellopoint CelloOS v4.1.10 Build 20190922 does not validate URL inputted properly, which allows unauthorized user to launch Path Traversal attack and access arbitrate file on the system. | ||
| CVE-2020-24368 | Hig | 0.49 | 7.5 | 0.03 | Aug 19, 2020 | Icinga Icinga Web2 2.0.0 through 2.6.4, 2.7.4 and 2.8.2 has a Directory Traversal vulnerability which allows an attacker to access arbitrary files that are readable by the process running Icinga Web 2. This issue is fixed in Icinga Web 2 in v2.6.4, v2.7.4 and v2.8.2. | ||
| CVE-2020-15592 | Hig | 0.49 | 7.5 | 0.02 | Jul 27, 2020 | SteelCentral Aternity Agent before 11.0.0.120 on Windows allows Privilege Escalation via a crafted file. It uses an executable running as a high privileged Windows service to perform administrative tasks and collect data from other processes. It distributes functionality among… | ||
| CVE-2020-7687 | Hig | 0.49 | 7.5 | 0.02 | Jul 25, 2020 | This affects all versions of package fast-http. There is no path sanitization in the path provided at fs.readFile in index.js. | ||
| CVE-2020-7686 | Hig | 0.49 | 7.5 | 0.02 | Jul 25, 2020 | This affects all versions of package rollup-plugin-dev-server. There is no path sanitization in readFile operation inside the readFileFromContentBase function. | ||
| CVE-2020-7683 | Hig | 0.49 | 7.5 | 0.02 | Jul 25, 2020 | This affects all versions of package rollup-plugin-server. There is no path sanitization in readFile operation performed inside the readFileFromContentBase function. | ||
| CVE-2020-7682 | Hig | 0.49 | 7.5 | 0.02 | Jul 25, 2020 | This affects all versions of package marked-tree. There is no path sanitization in the path provided at fs.readFile in index.js. | ||
| CVE-2020-7681 | Hig | 0.49 | 7.5 | 0.02 | Jul 25, 2020 | This affects all versions of package marscode. There is no path sanitization in the path provided at fs.readFile in index.js. | ||
| CVE-2020-15923 | Hig | 0.49 | 7.5 | 0.03 | Jul 24, 2020 | Mida eFramework through 2.9.0 allows unauthenticated ../ directory traversal. | ||
| CVE-2020-8214 | Hig | 0.49 | 7.5 | 0.02 | Jul 20, 2020 | A path traversal vulnerability in servey version < 3 allows an attacker to read content of any arbitrary file. | ||
| CVE-2020-15779 | Hig | 0.49 | 7.5 | 0.02 | Jul 15, 2020 | A Path Traversal issue was discovered in the socket.io-file package through 2.0.31 for Node.js. The socket.io-file::createFile message uses path.join with ../ in the name option, and the uploadDir and rename options determine the path. | ||
| CVE-2020-8161 | Hig | 0.49 | 8.6 | 0.03 | Jul 2, 2020 | A directory traversal vulnerability exists in rack < 2.2.0 that allows an attacker perform directory traversal vulnerability in the Rack::Directory app that is bundled with Rack which could result in information disclosure. | ||
| CVE-2020-12003 | Hig | 0.49 | 7.5 | 0.05 | Jun 15, 2020 | FactoryTalk Linx versions 6.00, 6.10, and 6.11, RSLinx Classic v4.11.00 and prior,Connected Components Workbench: Version 12 and prior, ControlFLASH: Version 14 and later, ControlFLASH Plus: Version 1 and later, FactoryTalk Asset Centre: Version 9 and later, FactoryTalk Linx… | ||
| CVE-2020-13836 | Hig | 0.49 | 7.5 | 0.00 | Jun 4, 2020 | An issue was discovered on Samsung mobile devices with O(8.x), P(9.0), and Q(10.0) software. HWRResProvider allows path traversal for data exposure. The Samsung ID is SVE-2020-16954 (June 2020). |
- risk 0.49cvss 7.5epss 0.02
Unathenticated directory traversal in the DownloadServlet class execute() method can lead to arbitrary file reads in HPE Pay Per Use (PPU) Utility Computing Service (UCS) Meter version 1.9.
- risk 0.49cvss 7.5epss 0.02
An issue was discovered in Hyland OnBase through 16.0.2.83 and below, 17.0.2.109 and below, 18.0.0.37 and below, 19.8.16.1000 and below and 20.3.10.1000 and below. Directory traversal exists for reading files, as demonstrated by the FileName parameter.
- risk 0.49cvss 7.5epss 0.01
An issue was discovered in Hyland OnBase through 18.0.0.32 and 19.x through 19.8.9.1000. Directory traversal exists for writing to files, as demonstrated by the FileName parameter.
- risk 0.49cvss 7.5epss 0.04
Setelsa Conacwin v3.7.1.2 is vulnerable to a local file inclusion vulnerability. This vulnerability allows a remote unauthenticated attacker to read internal files on the server via an http:IP:PORT/../../path/file_to_disclose Directory Traversal URI. NOTE: The manufacturer…
- risk 0.49cvss 7.5epss 0.03
This vulnerability allows remote attackers to disclose sensitive information on affected installations of Marvell QConvergeConsole 5.5.0.64. Authentication is not required to exploit this vulnerability. The specific flaw exists within the getFileUploadBytes method of the…
- risk 0.49cvss 7.5epss 0.03
This vulnerability allows remote attackers to disclose sensitive information on affected installations of Marvell QConvergeConsole 5.5.0.64. Authentication is not required to exploit this vulnerability. The specific flaw exists within the getFileUploadBytes method of the…
- risk 0.49cvss 7.5epss 0.02
Cellopoint CelloOS v4.1.10 Build 20190922 does not validate URL inputted properly, which allows unauthorized user to launch Path Traversal attack and access arbitrate file on the system.
- risk 0.49cvss 7.5epss 0.03
Icinga Icinga Web2 2.0.0 through 2.6.4, 2.7.4 and 2.8.2 has a Directory Traversal vulnerability which allows an attacker to access arbitrary files that are readable by the process running Icinga Web 2. This issue is fixed in Icinga Web 2 in v2.6.4, v2.7.4 and v2.8.2.
- risk 0.49cvss 7.5epss 0.02
SteelCentral Aternity Agent before 11.0.0.120 on Windows allows Privilege Escalation via a crafted file. It uses an executable running as a high privileged Windows service to perform administrative tasks and collect data from other processes. It distributes functionality among…
- risk 0.49cvss 7.5epss 0.02
This affects all versions of package fast-http. There is no path sanitization in the path provided at fs.readFile in index.js.
- risk 0.49cvss 7.5epss 0.02
This affects all versions of package rollup-plugin-dev-server. There is no path sanitization in readFile operation inside the readFileFromContentBase function.
- risk 0.49cvss 7.5epss 0.02
This affects all versions of package rollup-plugin-server. There is no path sanitization in readFile operation performed inside the readFileFromContentBase function.
- risk 0.49cvss 7.5epss 0.02
This affects all versions of package marked-tree. There is no path sanitization in the path provided at fs.readFile in index.js.
- risk 0.49cvss 7.5epss 0.02
This affects all versions of package marscode. There is no path sanitization in the path provided at fs.readFile in index.js.
- risk 0.49cvss 7.5epss 0.03
Mida eFramework through 2.9.0 allows unauthenticated ../ directory traversal.
- risk 0.49cvss 7.5epss 0.02
A path traversal vulnerability in servey version < 3 allows an attacker to read content of any arbitrary file.
- risk 0.49cvss 7.5epss 0.02
A Path Traversal issue was discovered in the socket.io-file package through 2.0.31 for Node.js. The socket.io-file::createFile message uses path.join with ../ in the name option, and the uploadDir and rename options determine the path.
- risk 0.49cvss 8.6epss 0.03
A directory traversal vulnerability exists in rack < 2.2.0 that allows an attacker perform directory traversal vulnerability in the Rack::Directory app that is bundled with Rack which could result in information disclosure.
- risk 0.49cvss 7.5epss 0.05
FactoryTalk Linx versions 6.00, 6.10, and 6.11, RSLinx Classic v4.11.00 and prior,Connected Components Workbench: Version 12 and prior, ControlFLASH: Version 14 and later, ControlFLASH Plus: Version 1 and later, FactoryTalk Asset Centre: Version 9 and later, FactoryTalk Linx…
- risk 0.49cvss 7.5epss 0.00
An issue was discovered on Samsung mobile devices with O(8.x), P(9.0), and Q(10.0) software. HWRResProvider allows path traversal for data exposure. The Samsung ID is SVE-2020-16954 (June 2020).