VYPR

CWE-22

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')

BaseStableLikelihood: High

Description

The product uses external input to construct a pathname that is intended to identify a file or directory that is located underneath a restricted parent directory, but the product does not properly neutralize special elements within the pathname that can cause the pathname to resolve to a location that is outside of the restricted directory.

Hierarchy (View 1000)

Parents

Children

Related attack patterns (CAPEC)

CAPEC-126 · CAPEC-64 · CAPEC-76 · CAPEC-78 · CAPEC-79

CVEs mapped to this weakness (10,395)

page 173 of 520
  • CVE-2016-10966HigSep 16, 2019
    risk 0.49cvss 7.5epss 0.03

    The real3d-flipbook-lite plugin 1.0 for WordPress has bookName=../ directory traversal for file upload.

  • CVE-2016-10965HigSep 16, 2019
    risk 0.49cvss 7.5epss 0.02

    The real3d-flipbook-lite plugin 1.0 for WordPress has deleteBook=../ directory traversal for file deletion.

  • CVE-2019-13532HigSep 13, 2019
    risk 0.49cvss 7.5epss 0.03

    CODESYS V3 web server, all versions prior to 3.5.14.10, allows an attacker to send specially crafted http or https requests which may allow access to files outside the restricted working directory of the controller.

  • CVE-2019-12464HigSep 9, 2019
    risk 0.49cvss 7.5epss 0.02

    An issue was discovered in LibreNMS 1.50.1. An authenticated user can perform a directory traversal attack against the /pdf.php file with a partial filename in the report parameter, to cause local file inclusion resulting in code execution.

  • CVE-2019-15839HigAug 30, 2019
    risk 0.49cvss 7.5epss 0.02

    The sina-extension-for-elementor plugin before 2.2.1 for WordPress has local file inclusion.

  • CVE-2019-15630HigAug 30, 2019
    risk 0.49cvss 7.5epss 0.03

    Directory Traversal in APIkit, HTTP connector, and OAuth2 Provider components in MuleSoft Mule Runtime 3.2.0 and higher released before August 1 2019, MuleSoft Mule Runtime 4.1.0 and higher released before August 1 2019, and all versions of MuleSoft API Gateway released before…

  • CVE-2019-6113HigAug 30, 2019
    risk 0.49cvss 7.5epss 0.03

    Directory traversal vulnerability on ONKYO TX-NR686 1030-5000-1040-0010 A/V Receiver devices allows remote attackers to read arbitrary files via a .. (dot dot) and %2f to the default URI.

  • CVE-2019-13408HigAug 29, 2019
    risk 0.49cvss 7.5epss 0.02

    A relative path traversal vulnerability found in Advan VD-1 firmware versions up to 230. It allows attackers to download arbitrary files via url cgibin/ExportSettings.cgi?Download=filepath, without any authentication.

  • CVE-2019-11654HigAug 23, 2019
    risk 0.49cvss 7.5epss 0.03

    Path traversal vulnerability in Micro Focus Verastream Host Integrator (VHI), versions 7.7 SP2 and earlier, The vulnerability allows remote unauthenticated attackers to read arbitrary files.

  • CVE-2019-15326HigAug 22, 2019
    risk 0.49cvss 7.5epss 0.02

    The import-users-from-csv-with-meta plugin before 1.14.2.1 for WordPress has directory traversal.

  • CVE-2019-11029HigAug 22, 2019
    risk 0.49cvss 7.5epss 0.02

    Mirasys VMS before V7.6.1 and 8.x before V8.3.2 mishandles the Download() method of AutoUpdateService in SMServer.exe, leading to Directory Traversal. An attacker could use ..\ with this method to iterate over lists of interesting system files and download them without previous…

  • CVE-2019-15323HigAug 22, 2019
    risk 0.49cvss 7.5epss 0.02

    The ad-inserter plugin before 2.4.20 for WordPress has path traversal.

  • CVE-2019-11603HigAug 21, 2019
    risk 0.49cvss 7.5epss 0.02

    A HTTP Traversal Attack in earlier versions than ProSyst mBS SDK 8.2.6 and Bosch IoT Gateway Software 9.0.2 allows remote attackers to read files outside the http root.

  • CVE-2019-11601HigAug 21, 2019
    risk 0.49cvss 7.5epss 0.03

    A directory traversal vulnerability in remote access to backup & restore in earlier versions than ProSyst mBS SDK 8.2.6 and Bosch IoT Gateway Software 9.2.0 allows remote attackers to write or delete files at any location.

  • CVE-2019-4460HigAug 20, 2019
    risk 0.49cvss 7.5epss 0.03

    IBM API Connect 5.0.0.0 through 5.0.8.6 developer portal could allow a remote attacker to traverse directories on the system. An attacker could send a specially-crafted URL request containing "dot dot" sequences (/../) to view arbitrary files on the system. IBM X-Force ID:…

  • CVE-2019-14701HigAug 6, 2019
    risk 0.49cvss 7.5epss 0.02

    An issue was discovered on MicroDigital N-series cameras with firmware through 6400.0.8.5. An attacker can trigger read operations on an arbitrary file via Path Traversal in the TZ parameter, but cannot retrieve the data that is read. This causes a denial of service if the…

  • CVE-2019-14700HigAug 6, 2019
    risk 0.49cvss 7.5epss 0.02

    An issue was discovered on MicroDigital N-series cameras with firmware through 6400.0.8.5. There is disclosure of the existence of arbitrary files via Path Traversal in HTTPD. This occurs because the filename specified in the TZ parameter is accessed with a substantial delay if…

  • CVE-2019-14521HigAug 5, 2019
    risk 0.49cvss 7.5epss 0.02

    The api/admin/logoupload Logo File upload feature in EMCA Energy Logserver 6.1.2 allows attackers to send any kind of file to any location on the server via path traversal in the filename parameter.

  • CVE-2019-1020001HigJul 29, 2019
    risk 0.49cvss 7.5epss 0.02

    yard before 0.9.20 allows path traversal.

  • CVE-2019-10265HigJul 26, 2019
    risk 0.49cvss 7.5epss 0.03

    An issue was discovered in Ahsay Cloud Backup Suite before 8.1.1.50. On the /cbs/system/ShowAdvanced.do "File Explorer" screen, it is possible to change the directory in the JavaScript code. If changed to (for example) "C:" then one can browse the whole server.