VYPR

CWE-22

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')

BaseStableLikelihood: High

Description

The product uses external input to construct a pathname that is intended to identify a file or directory that is located underneath a restricted parent directory, but the product does not properly neutralize special elements within the pathname that can cause the pathname to resolve to a location that is outside of the restricted directory.

Hierarchy (View 1000)

Parents

Children

Related attack patterns (CAPEC)

CAPEC-126 · CAPEC-64 · CAPEC-76 · CAPEC-78 · CAPEC-79

CVEs mapped to this weakness (10,395)

page 171 of 520
  • CVE-2020-9353HigFeb 23, 2020
    risk 0.49cvss 7.5epss 0.02

    An issue was discovered in SmartClient 12.0. The Remote Procedure Call (RPC) loadFile provided by the console functionality on the /tools/developerConsoleOperations.jsp (or /isomorphic/IDACall) URL is affected by unauthenticated Local File Inclusion via directory-traversal…

  • CVE-2020-7966HigFeb 5, 2020
    risk 0.49cvss 7.5epss 0.02

    GitLab EE 11.11 and later through 12.7.2 allows Directory Traversal.

  • CVE-2014-5236HigJan 31, 2020
    risk 0.49cvss 7.5epss 0.04

    Multiple absolute path traversal vulnerabilities in documentconverter in Open-Xchange (OX) AppSuite before 7.4.2-rev10 and 7.6.x before 7.6.0-rev10 allow remote attackers to read application files via a full pathname in a crafted (1) OLE Object or (2) image in an OpenDocument…

  • CVE-2012-6609HigJan 28, 2020
    risk 0.49cvss 7.5epss 0.02

    Directory traversal vulnerability in a_getlog.cgi in Polycom HDX Video End Points before 3.0.4 and UC APL before 2.7.1.J allows remote attackers to read arbitrary files via a .. (dot dot) in the name parameter.

  • CVE-2014-8742HigJan 27, 2020
    risk 0.49cvss 7.5epss 0.04

    Directory traversal vulnerability in the ReportDownloadServlet servlet in Lexmark MarkVision Enterprise before 2.1 allows remote attackers to read arbitrary files via unspecified vectors.

  • CVE-2013-6056HigJan 27, 2020
    risk 0.49cvss 7.5epss 0.02

    OSSIM before 4.3.3.1 has tele_compress.php path traversal vulnerability

  • CVE-2020-8009HigJan 27, 2020
    risk 0.49cvss 7.5epss 0.02

    AVB MOTU devices through 2020-01-22 allow /.. Directory Traversal, as demonstrated by reading the /etc/passwd file.

  • CVE-2014-1923HigJan 24, 2020
    risk 0.49cvss 7.5epss 0.03

    Multiple directory traversal vulnerabilities in the (1) staff interface help editor (edithelp.pl) or (2) member-picupload.pl in Koha before 3.8.23, 3.10.x before 3.10.13, 3.12.x before 3.12.10, and 3.14.x before 3.14.3 allow remote attackers to write to arbitrary files via…

  • CVE-2014-1922HigJan 24, 2020
    risk 0.49cvss 7.5epss 0.02

    Absolute path traversal vulnerability in tools/pdfViewer.pl in Koha before 3.8.23, 3.10.x before 3.10.13, 3.12.x before 3.12.10, and 3.14.x before 3.14.3 allows remote attackers to read arbitrary files via unspecified vectors.

  • CVE-2019-19893HigJan 23, 2020
    risk 0.49cvss 7.5epss 0.03

    In IXP EasyInstall 6.2.13723, there is Directory Traversal on TCP port 8000 via the Engine Service by an unauthenticated attacker, who can access the server's filesystem with the access rights of NT AUTHORITY\SYSTEM.

  • CVE-2020-7211HigJan 21, 2020
    risk 0.49cvss 7.5epss 0.04

    tftp.c in libslirp 4.1.0, as used in QEMU 4.2.0, does not prevent ..\ directory traversal on Windows.

  • CVE-2019-14767HigJan 21, 2020
    risk 0.49cvss 7.5epss 0.01

    In DIMO YellowBox CRM before 6.3.4, Path Traversal in images/Apparence (dossier=../) and servletrecuperefichier (document=../) allows an unauthenticated user to download arbitrary files from the server.

  • CVE-2019-15600HigDec 18, 2019
    risk 0.49cvss 7.5epss 0.03

    A Path traversal exists in http_server which allows an attacker to read arbitrary system files.

  • CVE-2019-15596HigDec 18, 2019
    risk 0.49cvss 7.5epss 0.02

    A path traversal in statics-server exists in all version that allows an attacker to perform a path traversal when a symlink is used within the working directory.

  • CVE-2019-19264HigDec 17, 2019
    risk 0.49cvss 7.5epss 0.02

    In Simplifile RecordFusion through 2019-11-25, the logs and hist parameters allow remote attackers to access local files via a logger/logs?/../ or logger/hist?/../ URI.

  • CVE-2019-14251HigDec 9, 2019
    risk 0.49cvss 7.5epss 0.08

    An issue was discovered in T24 in TEMENOS Channels R15.01. The login page presents JavaScript functions to access a document on the server once successfully authenticated. However, an attacker can leverage downloadDocServer() to traverse the file system and access files or…

  • CVE-2014-9356HigDec 2, 2019
    risk 0.49cvss 8.6epss 0.05

    Path traversal vulnerability in Docker before 1.3.3 allows remote attackers to write to arbitrary files and bypass a container protection mechanism via a full pathname in a symlink in an (1) image or (2) build in a Dockerfile.

  • CVE-2019-19372HigNov 28, 2019
    risk 0.49cvss 7.5epss 0.01

    A downloadFile.php download_file path traversal vulnerability in rConfig through 3.9.3 allows attackers to list files in arbitrary folders and potentially download files. NOTE: the discoverer later reported that there was not a "fully working exploit.

  • CVE-2015-1396HigNov 25, 2019
    risk 0.49cvss 7.5epss 0.03

    A Directory Traversal vulnerability exists in the GNU patch before 2.7.4. A remote attacker can write to arbitrary files via a symlink attack in a patch file. NOTE: this issue exists because of an incomplete fix for CVE-2015-1196.

  • CVE-2019-13157HigNov 22, 2019
    risk 0.49cvss 7.5epss 0.02

    nsGreen.dll in Naver Vaccine 2.1.4 allows remote attackers to overwrite arbitary files via directory traversal sequences in a filename within nsz archive.