VYPR

CWE-22

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')

BaseStableLikelihood: High

Description

The product uses external input to construct a pathname that is intended to identify a file or directory that is located underneath a restricted parent directory, but the product does not properly neutralize special elements within the pathname that can cause the pathname to resolve to a location that is outside of the restricted directory.

Hierarchy (View 1000)

Parents

Children

Related attack patterns (CAPEC)

CAPEC-126 · CAPEC-64 · CAPEC-76 · CAPEC-78 · CAPEC-79

CVEs mapped to this weakness (10,395)

page 170 of 520
  • CVE-2020-8983HigMay 7, 2020
    risk 0.49cvss 7.5epss 0.05

    An arbitrary file write issue exists in all versions of Citrix ShareFile StorageZones (aka storage zones) Controller, including the most recent 5.10.x releases as of May 2020, which allows remote code execution. RCE and file access is granted to everything hosted by ShareFile,…

  • CVE-2020-6828HigApr 24, 2020
    risk 0.49cvss 7.5epss 0.02

    A malicious Android application could craft an Intent that would have been processed by Firefox for Android and potentially result in a file overwrite in the user's profile directory. One exploitation vector for this would be to supply a user.js file providing arbitrary…

  • CVE-2020-12128HigApr 24, 2020
    risk 0.49cvss 7.5epss 0.02

    DONG JOO CHO File Transfer iFamily 2.1 allows directory traversal related to the ./etc/ path.

  • CVE-2020-12112HigApr 23, 2020
    risk 0.49cvss 7.5epss 0.05

    BigBlueButton before 2.2.5 allows remote attackers to obtain sensitive files via Local File Inclusion.

  • CVE-2020-1699HigApr 21, 2020
    risk 0.49cvss 7.5epss 0.02

    A path traversal flaw was found in the Ceph dashboard implemented in upstream versions v14.2.5, v14.2.6, v15.0.0 of Ceph storage and has been fixed in versions 14.2.7 and 15.1.0. An unauthenticated attacker could use this flaw to cause information disclosure on the host machine…

  • CVE-2020-3177HigApr 15, 2020
    risk 0.49cvss 7.5epss 0.03

    A vulnerability in the Tool for Auto-Registered Phones Support (TAPS) of Cisco Unified Communications Manager (UCM) and Cisco Unified Communications Manager Session Management Edition (SME) could allow an unauthenticated, remote attacker to conduct directory traversal attacks on…

  • CVE-2020-10506HigApr 15, 2020
    risk 0.49cvss 7.5epss 0.01

    The School Manage System before 2020, developed by ALLE INFORMATION CO., LTD., contains a vulnerability of Path Traversal, allowing attackers to access arbitrary files.

  • CVE-2020-10366HigApr 8, 2020
    risk 0.49cvss 7.5epss 0.01

    LogicalDoc before 8.3.3 allows /servlet.gupld Directory Traversal, a different vulnerability than CVE-2020-9423 and CVE-2020-10365.

  • CVE-2020-11596HigApr 6, 2020
    risk 0.49cvss 7.5epss 0.02

    A Directory Traversal issue was discovered in CIPPlanner CIPAce 9.1 Build 2019092801. An unauthenticated attacker can make HTTP GET requests to a certain URL and obtain information about what files and directories reside on the server.

  • CVE-2020-7008HigApr 3, 2020
    risk 0.49cvss 7.5epss 0.02

    VISAM VBASE Editor version 11.5.0.2 and VBASE Web-Remote Module may allow input passed in the URL that is not properly verified before use, which may allow an attacker to read arbitrary files from local resources.

  • CVE-2020-11414HigMar 31, 2020
    risk 0.49cvss 7.5epss 0.01

    An issue was discovered in Progress Telerik UI for Silverlight before 2020.1.330. The RadUploadHandler class in RadUpload for Silverlight expects a web request that provides the file location of the uploading file along with a few other parameters. The uploading file location…

  • CVE-2020-10953HigMar 27, 2020
    risk 0.49cvss 7.5epss 0.02

    In GitLab EE 11.7 through 12.9, the NPM feature is vulnerable to a path traversal issue.

  • CVE-2020-10875HigMar 23, 2020
    risk 0.49cvss 7.5epss 0.02

    Motorola FX9500 devices allow remote attackers to conduct absolute path traversal attacks, as demonstrated by PL/SQL Server Pages files such as /include/viewtagdb.psp.

  • CVE-2020-7478HigMar 23, 2020
    risk 0.49cvss 7.5epss 0.04

    A CWE-22: Improper Limitation of a Pathname to a Restricted Directory exists in IGSS (Versions 14 and prior using the service: IGSSupdate), which could allow a remote unauthenticated attacker to read arbitrary files from the IGSS server PC on an unrestricted or shared network…

  • CVE-2020-9325HigMar 18, 2020
    risk 0.49cvss 7.5epss 0.02

    Aquaforest TIFF Server 4.0 allows Unauthenticated Arbitrary File Download.

  • CVE-2019-13195HigMar 13, 2020
    risk 0.49cvss 7.5epss 0.03

    The web application of some Kyocera printers (such as the ECOSYS M5526cdw 2R7_2000.001.701) was vulnerable to path traversal, allowing an unauthenticated user to retrieve arbitrary files, or check if files or folders existed within the file system.

  • CVE-2019-19297HigMar 10, 2020
    risk 0.49cvss 7.5epss 0.03

    A vulnerability has been identified in SiNVR/SiVMS Video Server (All versions < V5.0.0). The streaming service (default port 5410/tcp) of the SiVMS/SiNVR Video Server contains a path traversal vulnerability, that could allow an unauthenticated remote attacker to access and…

  • CVE-2018-18894HigMar 10, 2020
    risk 0.49cvss 7.5epss 0.02

    Certain older Lexmark devices (C, M, X, and 6500e before 2018-12-18) contain a directory traversal vulnerability in the embedded web server.

  • CVE-2019-7007HigFeb 28, 2020
    risk 0.49cvss 7.5epss 0.02

    A directory traversal vulnerability has been found in the Avaya Equinox Management(iView)versions R9.1.9.0 and earlier. Successful exploitation could potentially allow an unauthenticated attacker to access files that are outside the restricted directory on the remote server.

  • CVE-2020-9354HigFeb 23, 2020
    risk 0.49cvss 7.5epss 0.01

    An issue was discovered in SmartClient 12.0. The Remote Procedure Call (RPC) saveFile provided by the console functionality on the /tools/developerConsoleOperations.jsp (or /isomorphic/IDACall) URL allows an unauthenticated attacker to overwrite files via vectors involving an…