VYPR

CWE-22

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')

BaseStableLikelihood: High

Description

The product uses external input to construct a pathname that is intended to identify a file or directory that is located underneath a restricted parent directory, but the product does not properly neutralize special elements within the pathname that can cause the pathname to resolve to a location that is outside of the restricted directory.

Hierarchy (View 1000)

Parents

Children

Related attack patterns (CAPEC)

CAPEC-126 · CAPEC-64 · CAPEC-76 · CAPEC-78 · CAPEC-79

CVEs mapped to this weakness (10,395)

page 175 of 520
  • CVE-2019-5889HigApr 1, 2019
    risk 0.49cvss 7.5epss 0.02

    An log-management directory traversal issue was discovered in OverIT Geocall 6.3 before build 2:346977.

  • CVE-2018-20144HigMar 28, 2019
    risk 0.49cvss 7.5epss 0.02

    GitLab Community and Enterprise Edition 11.x before 11.3.13, 11.4.x before 11.4.11, and 11.5.x before 11.5.4 has Incorrect Access Control.

  • CVE-2019-5927HigMar 27, 2019
    risk 0.49cvss 7.5epss 0.03

    Directory traversal vulnerability in 'an' App for iOS Version 3.2.0 and earlier allows remote attackers to read arbitrary files via unspecified vectors.

  • CVE-2018-19856HigMar 26, 2019
    risk 0.49cvss 7.5epss 0.02

    GitLab CE/EE before 11.3.12, 11.4.x before 11.4.10, and 11.5.x before 11.5.3 allows Directory Traversal in Templates API.

  • CVE-2019-6240HigMar 25, 2019
    risk 0.49cvss 7.5epss 0.02

    An issue was discovered in GitLab Community and Enterprise Edition before 11.4. It allows Directory Traversal.

  • CVE-2019-5417HigMar 21, 2019
    risk 0.49cvss 7.5epss 0.02

    A path traversal vulnerability in serve npm package version 7.0.1 allows the attackers to read content of arbitrary files on the remote server.

  • CVE-2019-5416HigMar 21, 2019
    risk 0.49cvss 7.5epss 0.02

    A path traversal vulnerability in localhost-now npm package version 1.0.2 allows the attackers to read content of arbitrary files on the remote server.

  • CVE-2018-20628HigMar 21, 2019
    risk 0.49cvss 7.5epss 0.02

    PHP Scripts Mall Charity Foundation Script 1 through 3 allows directory traversal via a direct request for a listing of an uploads directory such as the wp-content/uploads/2018/12 directory.

  • CVE-2018-11789HigMar 21, 2019
    risk 0.49cvss 7.5epss 0.07

    When accessing the heron-ui webpage, people can modify the file paths outside of the current container to access any file on the host. Example woule be modifying the parameter path= to go to the directory you would like to view. i.e. ..%2F..%2F..%2F..%2F..%2F..%2Fetc%2Fpasswd.

  • CVE-2019-5923HigMar 12, 2019
    risk 0.49cvss 7.5epss 0.02

    Directory traversal vulnerability in iChain Insurance Wallet App for iOS Version 1.3.0 and earlier allows remote attackers to read arbitrary files via unspecified vectors.

  • CVE-2019-9662HigMar 11, 2019
    risk 0.49cvss 7.5epss 0.02

    An issue was discovered in JTBC(PHP) 3.0.1.8. Its cache management module is flawed. An arbitrary file ending in "inc.php" can be deleted via a console/cache/manage.php?type=action&action=batch&batch=delete&ids=../ substring.

  • CVE-2018-20795HigFeb 25, 2019
    risk 0.49cvss 7.5epss 0.03

    tecrail Responsive FileManager 9.13.4 allows remote attackers to read arbitrary files via path traversal with the path parameter, through the copy_cut action in ajax_calls.php and the paste_clipboard action in execute.php.

  • CVE-2018-20794HigFeb 25, 2019
    risk 0.49cvss 7.5epss 0.04

    tecrail Responsive FileManager 9.13.4 allows remote attackers to write to an arbitrary image file (jpg/jpeg/png) via path traversal with the path parameter, through the save_img action in ajax_calls.php.

  • CVE-2018-20793HigFeb 25, 2019
    risk 0.49cvss 7.5epss 0.05

    tecrail Responsive FileManager 9.13.4 allows remote attackers to write to an arbitrary file as a consequence of a paths[0] path traversal mitigation bypass, through the create_file action in execute.php.

  • CVE-2018-20792HigFeb 25, 2019
    risk 0.49cvss 7.5epss 0.03

    tecrail Responsive FileManager 9.13.4 allows remote attackers to read arbitrary file via path traversal with the path parameter, through the get_file action in ajax_calls.php.

  • CVE-2018-20790HigFeb 25, 2019
    risk 0.49cvss 7.5epss 0.04

    tecrail Responsive FileManager 9.13.4 allows remote attackers to delete an arbitrary file as a consequence of a paths[0] path traversal mitigation bypass through the delete_file action in execute.php.

  • CVE-2018-20789HigFeb 25, 2019
    risk 0.49cvss 7.5epss 0.04

    tecrail Responsive FileManager 9.13.4 allows remote attackers to delete an arbitrary directory as a consequence of a paths[0] path traversal mitigation bypass through the delete_folder action in execute.php.

  • CVE-2019-1681HigFeb 21, 2019
    risk 0.49cvss 7.5epss 0.06

    A vulnerability in the TFTP service of Cisco Network Convergence System 1000 Series software could allow an unauthenticated, remote attacker to retrieve arbitrary files from the targeted device, possibly resulting in information disclosure. The vulnerability is due to improper…

  • CVE-2019-8411HigFeb 17, 2019
    risk 0.49cvss 7.5epss 0.03

    admin/dl_data.php in zzcms 2018 (2018-10-19) allows remote attackers to delete arbitrary files via action=del&filename=../ directory traversal.

  • CVE-2015-4617HigFeb 15, 2019
    risk 0.49cvss 7.5epss 0.02

    Vulnerability in Easy2map-photos WordPress Plugin v1.09 MapPinImageUpload.php and MapPinIconSave.php allows path traversal when specifying file names creating files outside of the upload directory.