CWE-22
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
Description
The product uses external input to construct a pathname that is intended to identify a file or directory that is located underneath a restricted parent directory, but the product does not properly neutralize special elements within the pathname that can cause the pathname to resolve to a location that is outside of the restricted directory.
Hierarchy (View 1000)
Related attack patterns (CAPEC)
CAPEC-126 · CAPEC-64 · CAPEC-76 · CAPEC-78 · CAPEC-79
CVEs mapped to this weakness (10,395)
page 170 of 520| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2020-8983 | Hig | 0.49 | 7.5 | 0.05 | May 7, 2020 | An arbitrary file write issue exists in all versions of Citrix ShareFile StorageZones (aka storage zones) Controller, including the most recent 5.10.x releases as of May 2020, which allows remote code execution. RCE and file access is granted to everything hosted by ShareFile,… | ||
| CVE-2020-6828 | Hig | 0.49 | 7.5 | 0.02 | Apr 24, 2020 | A malicious Android application could craft an Intent that would have been processed by Firefox for Android and potentially result in a file overwrite in the user's profile directory. One exploitation vector for this would be to supply a user.js file providing arbitrary… | ||
| CVE-2020-12128 | Hig | 0.49 | 7.5 | 0.02 | Apr 24, 2020 | DONG JOO CHO File Transfer iFamily 2.1 allows directory traversal related to the ./etc/ path. | ||
| CVE-2020-12112 | Hig | 0.49 | 7.5 | 0.05 | Apr 23, 2020 | BigBlueButton before 2.2.5 allows remote attackers to obtain sensitive files via Local File Inclusion. | ||
| CVE-2020-1699 | Hig | 0.49 | 7.5 | 0.02 | Apr 21, 2020 | A path traversal flaw was found in the Ceph dashboard implemented in upstream versions v14.2.5, v14.2.6, v15.0.0 of Ceph storage and has been fixed in versions 14.2.7 and 15.1.0. An unauthenticated attacker could use this flaw to cause information disclosure on the host machine… | ||
| CVE-2020-3177 | Hig | 0.49 | 7.5 | 0.03 | Apr 15, 2020 | A vulnerability in the Tool for Auto-Registered Phones Support (TAPS) of Cisco Unified Communications Manager (UCM) and Cisco Unified Communications Manager Session Management Edition (SME) could allow an unauthenticated, remote attacker to conduct directory traversal attacks on… | ||
| CVE-2020-10506 | Hig | 0.49 | 7.5 | 0.01 | Apr 15, 2020 | The School Manage System before 2020, developed by ALLE INFORMATION CO., LTD., contains a vulnerability of Path Traversal, allowing attackers to access arbitrary files. | ||
| CVE-2020-10366 | Hig | 0.49 | 7.5 | 0.01 | Apr 8, 2020 | LogicalDoc before 8.3.3 allows /servlet.gupld Directory Traversal, a different vulnerability than CVE-2020-9423 and CVE-2020-10365. | ||
| CVE-2020-11596 | Hig | 0.49 | 7.5 | 0.02 | Apr 6, 2020 | A Directory Traversal issue was discovered in CIPPlanner CIPAce 9.1 Build 2019092801. An unauthenticated attacker can make HTTP GET requests to a certain URL and obtain information about what files and directories reside on the server. | ||
| CVE-2020-7008 | Hig | 0.49 | 7.5 | 0.02 | Apr 3, 2020 | VISAM VBASE Editor version 11.5.0.2 and VBASE Web-Remote Module may allow input passed in the URL that is not properly verified before use, which may allow an attacker to read arbitrary files from local resources. | ||
| CVE-2020-11414 | Hig | 0.49 | 7.5 | 0.01 | Mar 31, 2020 | An issue was discovered in Progress Telerik UI for Silverlight before 2020.1.330. The RadUploadHandler class in RadUpload for Silverlight expects a web request that provides the file location of the uploading file along with a few other parameters. The uploading file location… | ||
| CVE-2020-10953 | Hig | 0.49 | 7.5 | 0.02 | Mar 27, 2020 | In GitLab EE 11.7 through 12.9, the NPM feature is vulnerable to a path traversal issue. | ||
| CVE-2020-10875 | Hig | 0.49 | 7.5 | 0.02 | Mar 23, 2020 | Motorola FX9500 devices allow remote attackers to conduct absolute path traversal attacks, as demonstrated by PL/SQL Server Pages files such as /include/viewtagdb.psp. | ||
| CVE-2020-7478 | Hig | 0.49 | 7.5 | 0.04 | Mar 23, 2020 | A CWE-22: Improper Limitation of a Pathname to a Restricted Directory exists in IGSS (Versions 14 and prior using the service: IGSSupdate), which could allow a remote unauthenticated attacker to read arbitrary files from the IGSS server PC on an unrestricted or shared network… | ||
| CVE-2020-9325 | Hig | 0.49 | 7.5 | 0.02 | Mar 18, 2020 | Aquaforest TIFF Server 4.0 allows Unauthenticated Arbitrary File Download. | ||
| CVE-2019-13195 | Hig | 0.49 | 7.5 | 0.03 | Mar 13, 2020 | The web application of some Kyocera printers (such as the ECOSYS M5526cdw 2R7_2000.001.701) was vulnerable to path traversal, allowing an unauthenticated user to retrieve arbitrary files, or check if files or folders existed within the file system. | ||
| CVE-2019-19297 | Hig | 0.49 | 7.5 | 0.03 | Mar 10, 2020 | A vulnerability has been identified in SiNVR/SiVMS Video Server (All versions < V5.0.0). The streaming service (default port 5410/tcp) of the SiVMS/SiNVR Video Server contains a path traversal vulnerability, that could allow an unauthenticated remote attacker to access and… | ||
| CVE-2018-18894 | Hig | 0.49 | 7.5 | 0.02 | Mar 10, 2020 | Certain older Lexmark devices (C, M, X, and 6500e before 2018-12-18) contain a directory traversal vulnerability in the embedded web server. | ||
| CVE-2019-7007 | Hig | 0.49 | 7.5 | 0.02 | Feb 28, 2020 | A directory traversal vulnerability has been found in the Avaya Equinox Management(iView)versions R9.1.9.0 and earlier. Successful exploitation could potentially allow an unauthenticated attacker to access files that are outside the restricted directory on the remote server. | ||
| CVE-2020-9354 | Hig | 0.49 | 7.5 | 0.01 | Feb 23, 2020 | An issue was discovered in SmartClient 12.0. The Remote Procedure Call (RPC) saveFile provided by the console functionality on the /tools/developerConsoleOperations.jsp (or /isomorphic/IDACall) URL allows an unauthenticated attacker to overwrite files via vectors involving an… |
- risk 0.49cvss 7.5epss 0.05
An arbitrary file write issue exists in all versions of Citrix ShareFile StorageZones (aka storage zones) Controller, including the most recent 5.10.x releases as of May 2020, which allows remote code execution. RCE and file access is granted to everything hosted by ShareFile,…
- risk 0.49cvss 7.5epss 0.02
A malicious Android application could craft an Intent that would have been processed by Firefox for Android and potentially result in a file overwrite in the user's profile directory. One exploitation vector for this would be to supply a user.js file providing arbitrary…
- risk 0.49cvss 7.5epss 0.02
DONG JOO CHO File Transfer iFamily 2.1 allows directory traversal related to the ./etc/ path.
- risk 0.49cvss 7.5epss 0.05
BigBlueButton before 2.2.5 allows remote attackers to obtain sensitive files via Local File Inclusion.
- risk 0.49cvss 7.5epss 0.02
A path traversal flaw was found in the Ceph dashboard implemented in upstream versions v14.2.5, v14.2.6, v15.0.0 of Ceph storage and has been fixed in versions 14.2.7 and 15.1.0. An unauthenticated attacker could use this flaw to cause information disclosure on the host machine…
- risk 0.49cvss 7.5epss 0.03
A vulnerability in the Tool for Auto-Registered Phones Support (TAPS) of Cisco Unified Communications Manager (UCM) and Cisco Unified Communications Manager Session Management Edition (SME) could allow an unauthenticated, remote attacker to conduct directory traversal attacks on…
- risk 0.49cvss 7.5epss 0.01
The School Manage System before 2020, developed by ALLE INFORMATION CO., LTD., contains a vulnerability of Path Traversal, allowing attackers to access arbitrary files.
- risk 0.49cvss 7.5epss 0.01
LogicalDoc before 8.3.3 allows /servlet.gupld Directory Traversal, a different vulnerability than CVE-2020-9423 and CVE-2020-10365.
- risk 0.49cvss 7.5epss 0.02
A Directory Traversal issue was discovered in CIPPlanner CIPAce 9.1 Build 2019092801. An unauthenticated attacker can make HTTP GET requests to a certain URL and obtain information about what files and directories reside on the server.
- risk 0.49cvss 7.5epss 0.02
VISAM VBASE Editor version 11.5.0.2 and VBASE Web-Remote Module may allow input passed in the URL that is not properly verified before use, which may allow an attacker to read arbitrary files from local resources.
- risk 0.49cvss 7.5epss 0.01
An issue was discovered in Progress Telerik UI for Silverlight before 2020.1.330. The RadUploadHandler class in RadUpload for Silverlight expects a web request that provides the file location of the uploading file along with a few other parameters. The uploading file location…
- risk 0.49cvss 7.5epss 0.02
In GitLab EE 11.7 through 12.9, the NPM feature is vulnerable to a path traversal issue.
- risk 0.49cvss 7.5epss 0.02
Motorola FX9500 devices allow remote attackers to conduct absolute path traversal attacks, as demonstrated by PL/SQL Server Pages files such as /include/viewtagdb.psp.
- risk 0.49cvss 7.5epss 0.04
A CWE-22: Improper Limitation of a Pathname to a Restricted Directory exists in IGSS (Versions 14 and prior using the service: IGSSupdate), which could allow a remote unauthenticated attacker to read arbitrary files from the IGSS server PC on an unrestricted or shared network…
- risk 0.49cvss 7.5epss 0.02
Aquaforest TIFF Server 4.0 allows Unauthenticated Arbitrary File Download.
- risk 0.49cvss 7.5epss 0.03
The web application of some Kyocera printers (such as the ECOSYS M5526cdw 2R7_2000.001.701) was vulnerable to path traversal, allowing an unauthenticated user to retrieve arbitrary files, or check if files or folders existed within the file system.
- risk 0.49cvss 7.5epss 0.03
A vulnerability has been identified in SiNVR/SiVMS Video Server (All versions < V5.0.0). The streaming service (default port 5410/tcp) of the SiVMS/SiNVR Video Server contains a path traversal vulnerability, that could allow an unauthenticated remote attacker to access and…
- risk 0.49cvss 7.5epss 0.02
Certain older Lexmark devices (C, M, X, and 6500e before 2018-12-18) contain a directory traversal vulnerability in the embedded web server.
- risk 0.49cvss 7.5epss 0.02
A directory traversal vulnerability has been found in the Avaya Equinox Management(iView)versions R9.1.9.0 and earlier. Successful exploitation could potentially allow an unauthenticated attacker to access files that are outside the restricted directory on the remote server.
- risk 0.49cvss 7.5epss 0.01
An issue was discovered in SmartClient 12.0. The Remote Procedure Call (RPC) saveFile provided by the console functionality on the /tools/developerConsoleOperations.jsp (or /isomorphic/IDACall) URL allows an unauthenticated attacker to overwrite files via vectors involving an…