VYPR

CWE-22

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')

BaseStableLikelihood: High

Description

The product uses external input to construct a pathname that is intended to identify a file or directory that is located underneath a restricted parent directory, but the product does not properly neutralize special elements within the pathname that can cause the pathname to resolve to a location that is outside of the restricted directory.

Hierarchy (View 1000)

Parents

Children

Related attack patterns (CAPEC)

CAPEC-126 · CAPEC-64 · CAPEC-76 · CAPEC-78 · CAPEC-79

CVEs mapped to this weakness (10,395)

page 172 of 520
  • CVE-2013-3311HigNov 21, 2019
    risk 0.49cvss 7.5epss 0.04

    Directory traversal vulnerability in the Loftek Nexus 543 IP Camera allows remote attackers to read arbitrary files via a .. (dot dot) in the URL of an HTTP GET request.

  • CVE-2019-15004HigNov 7, 2019
    risk 0.49cvss 7.5epss 0.04

    The Customer Context Filter in Atlassian Jira Service Desk Server and Jira Service Desk Data Center before 3.9.17, from 3.10.0 before 3.16.10, from 4.0.0 before 4.2.6, from 4.3.0 before 4.3.5, from 4.4.0 before 4.4.3, and from 4.5.0 before 4.5.1 allows remote attackers with…

  • CVE-2005-2349HigOct 28, 2019
    risk 0.49cvss 7.5epss 0.02

    Zoo 2.10 has Directory traversal

  • CVE-2019-8238HigOct 23, 2019
    risk 0.49cvss 7.5epss 0.05

    Adobe Acrobat and Reader versions 2019.010.20100 and earlier; 2019.010.20099 and earlier versions; 2017.011.30140 and earlier version; 2017.011.30138 and earlier version; 2015.006.30495 and earlier versions; 2015.006.30493 and earlier versions have a Path Traversal…

  • CVE-2019-17537HigOct 13, 2019
    risk 0.49cvss 7.5epss 0.02

    Jiangnan Online Judge (aka jnoj) 0.8.0 has Directory Traversal for file deletion via the web/polygon/problem/deletefile?id=1&name=../ substring.

  • CVE-2010-5335HigOct 11, 2019
    risk 0.49cvss 7.5epss 0.03

    IceWarp Webclient before 10.2.1 has a directory traversal vulnerability. This can result in loss of confidential data of IceWarp Mailserver and the operating system. Input passed via a certain parameter (script to basic/minimizer/index.php) is not properly sanitised and can…

  • CVE-2010-5334HigOct 11, 2019
    risk 0.49cvss 7.5epss 0.03

    IceWarp Webclient before 10.2.1 has a directory traversal vulnerability. This can result in loss of confidential data of IceWarp Mailserver and the operating system. Input passed via a certain parameter (_c to basic/index.html) is not properly sanitised and can therefore be…

  • CVE-2015-9473HigOct 10, 2019
    risk 0.49cvss 7.5epss 0.04

    The estrutura-basica theme through 2015-09-13 for WordPress has directory traversal via the scripts/download.php arquivo parameter.

  • CVE-2015-9470HigOct 10, 2019
    risk 0.49cvss 7.5epss 0.04

    The history-collection plugin through 1.1.1 for WordPress has directory traversal via the download.php var parameter.

  • CVE-2015-9463HigOct 10, 2019
    risk 0.49cvss 7.5epss 0.04

    The s3bubble-amazon-s3-audio-streaming plugin 2.0 for WordPress has directory traversal via the adverts/assets/plugins/ultimate/content/downloader.php path parameter.

  • CVE-2015-9464HigOct 10, 2019
    risk 0.49cvss 7.5epss 0.04

    The s3bubble-amazon-s3-html-5-video-with-adverts plugin 0.7 for WordPress has directory traversal via the adverts/assets/plugins/ultimate/content/downloader.php path parameter.

  • CVE-2019-17175HigOct 4, 2019
    risk 0.49cvss 7.5epss 0.02

    joyplus-cms 1.6.0 allows manager/admin_pic.php?rootpath= absolute path traversal.

  • CVE-2019-13343HigOct 2, 2019
    risk 0.49cvss 7.5epss 0.02

    Butor Portal before 1.0.27 is affected by a Path Traversal vulnerability leading to a pre-authentication arbitrary file download. Effectively, a remote anonymous user can download any file on servers running Butor Portal. WhiteLabelingServlet is responsible for this…

  • CVE-2019-8291HigOct 1, 2019
    risk 0.49cvss 7.5epss 0.01

    Online Store System v1.0 delete_file.php doesn't check to see if a user has administrative rights nor does it check for path traversal.

  • CVE-2017-18636HigSep 30, 2019
    risk 0.49cvss 7.5epss 0.02

    CDG through 2017-01-01 allows downloadDocument.jsp?command=download&pathAndName= directory traversal.

  • CVE-2019-9281HigSep 27, 2019
    risk 0.49cvss 7.5epss 0.01

    In GoogleContactsSyncAdapter, there is a possible path traversal due to improper input sanitization. This could lead to a bypass of user interaction requirements with no additional execution privileges needed. User interaction is not needed for exploitation. Product:…

  • CVE-2014-10397HigSep 20, 2019
    risk 0.49cvss 7.5epss 0.03

    The Antioch theme through 2014-09-07 for WordPress allows arbitrary file downloads via the file parameter to lib/scripts/download.php.

  • CVE-2014-10396HigSep 20, 2019
    risk 0.49cvss 7.5epss 0.03

    The epic theme through 2014-09-07 for WordPress allows arbitrary file downloads via the file parameter to includes/download.php.

  • CVE-2019-14994HigSep 19, 2019
    risk 0.49cvss 7.5epss 0.06

    The Customer Context Filter in Atlassian Jira Service Desk Server and Jira Service Desk Data Center before version 3.9.16, from version 3.10.0 before version 3.16.8, from version 4.0.0 before version 4.1.3, from version 4.2.0 before version 4.2.5, from version 4.3.0 before…

  • CVE-2019-0207HigSep 16, 2019
    risk 0.49cvss 7.5epss 0.03

    Tapestry processes assets `/assets/ctx` using classes chain `StaticFilesFilter -> AssetDispatcher -> ContextResource`, which doesn't filter the character `\`, so attacker can perform a path traversal attack to read any files on Windows platform.