VYPR

CWE-22

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')

BaseStableLikelihood: High

Description

The product uses external input to construct a pathname that is intended to identify a file or directory that is located underneath a restricted parent directory, but the product does not properly neutralize special elements within the pathname that can cause the pathname to resolve to a location that is outside of the restricted directory.

Hierarchy (View 1000)

Parents

Children

Related attack patterns (CAPEC)

CAPEC-126 · CAPEC-64 · CAPEC-76 · CAPEC-78 · CAPEC-79

CVEs mapped to this weakness (10,395)

page 177 of 520
  • CVE-2018-13812HigDec 13, 2018
    risk 0.49cvss 7.5epss 0.04

    A vulnerability has been identified in SIMATIC HMI Comfort Panels 4" - 22" (All versions < V15 Update 4), SIMATIC HMI Comfort Outdoor Panels 7" & 15" (All versions < V15 Update 4), SIMATIC HMI KTP Mobile Panels KTP400F, KTP700, KTP700F, KTP900 and KTP900F (All versions < V15…

  • CVE-2018-20128HigDec 13, 2018
    risk 0.49cvss 7.5epss 0.02

    An issue was discovered in UsualToolCMS v8.0. cmsadmin\a_sqlback.php allows remote attackers to delete arbitrary files via a backname[] directory-traversal pathname followed by a crafted substring.

  • CVE-2018-20094HigDec 12, 2018
    risk 0.49cvss 7.5epss 0.02

    An issue was discovered in XXL-CONF 1.6.0. There is a path traversal vulnerability via ../ in the keys parameter that can download any configuration file, related to ConfController.java and PropUtil.java.

  • CVE-2018-20064HigDec 11, 2018
    risk 0.49cvss 7.5epss 0.03

    doorGets 7.0 allows remote attackers to write to arbitrary files via directory traversal, as demonstrated by a dg-user/?controller=theme&action=edit&name=doorgets&file=../../1.txt%00 URI with content in the theme_content_nofi parameter.

  • CVE-2018-20058HigDec 11, 2018
    risk 0.49cvss 7.5epss 0.01

    In Evernote before 7.6 on macOS, there is a local file path traversal issue in attachment previewing, aka MACOSNOTE-28634.

  • CVE-2018-12314HigDec 4, 2018
    risk 0.49cvss 7.5epss 0.02

    Directory Traversal in downloadwallpaper.cgi in ASUSTOR ADM version 3.1.1 allows attackers to download arbitrary files by manipulating the "file" and "folder" URL parameters.

  • CVE-2018-12309HigDec 4, 2018
    risk 0.49cvss 7.5epss 0.01

    Directory Traversal in upload.cgi in ASUSTOR ADM version 3.1.1 allows attackers to upload files to arbitrary locations by modifying the "path" URL parameter. NOTE: the "filename" POST parameter is covered by CVE-2018-11345.

  • CVE-2018-12306HigDec 4, 2018
    risk 0.49cvss 7.5epss 0.02

    Directory Traversal in File Explorer in ASUSTOR ADM version 3.1.1 allows attackers to view arbitrary files by modifying the "file1" URL parameter, a similar issue to CVE-2018-11344.

  • CVE-2018-19748HigNov 29, 2018
    risk 0.49cvss 7.5epss 0.02

    app/plug/attachment/controller/admincontroller.php in SDCMS 1.6 allows reading arbitrary files via a /?m=plug&c=admin&a=index&p=attachment&root= directory traversal. The value of the root parameter must be base64 encoded (note that base64 encoding, instead of URL encoding, is…

  • CVE-2018-13332HigNov 27, 2018
    risk 0.49cvss 7.5epss 0.02

    Directory Traversal in the explorer application in TerraMaster TOS version 3.1.03 allows attackers to upload files to arbitrary locations via the "path" URL parameter.

  • CVE-2018-0693HigNov 15, 2018
    risk 0.49cvss 7.5epss 0.02

    Directory traversal vulnerability in FileZen V3.0.0 to V4.2.1 allows remote attackers to upload an arbitrary file in the specific directory in FileZen via unspecified vectors.

  • CVE-2018-19228HigNov 12, 2018
    risk 0.49cvss 7.5epss 0.02

    An issue was discovered in LAOBANCMS 2.0. It allows arbitrary file deletion via ../ directory traversal in the admin/pic.php del parameter, as demonstrated by deleting install/install.txt to permit a reinstallation.

  • CVE-2018-19181HigNov 11, 2018
    risk 0.49cvss 7.5epss 0.01

    statics/ueditor/php/vendor/Local.class.php in YUNUCMS 1.1.5 allows arbitrary file deletion via the statics/ueditor/php/controller.php?action=remove key parameter, as demonstrated by using directory traversal to delete the install.lock file.

  • CVE-2018-16475HigNov 6, 2018
    risk 0.49cvss 7.5epss 0.02

    A Path Traversal in Knightjs versions <= 0.0.1 allows an attacker to read content of arbitrary files on a remote server.

  • CVE-2018-18950HigNov 5, 2018
    risk 0.49cvss 7.5epss 0.02

    KindEditor through 4.1.11 has a path traversal vulnerability in php/upload_json.php. Anyone can browse a file or directory in the kindeditor/attached/ folder via the path parameter without authentication.

  • CVE-2018-18936HigNov 5, 2018
    risk 0.49cvss 7.5epss 0.03

    An issue was discovered in PopojiCMS v2.0.1. admin_library.php allows remote attackers to delete arbitrary files via directory traversal in the po-admin/route.php?mod=library&act=delete id parameter.

  • CVE-2018-18831HigOct 30, 2018
    risk 0.49cvss 7.5epss 0.02

    An issue was discovered in com\mingsoft\cms\action\GeneraterAction.java in MCMS 4.6.5. An attacker can write a .jsp file (in the position parameter) to an arbitrary directory via a ../ Directory Traversal in the url parameter.

  • CVE-2018-18713HigOct 29, 2018
    risk 0.49cvss 7.5epss 0.02

    The function down_sql_action() in /admin/model/database.class.php in PHPYun 4.6 allows remote attackers to read arbitrary files via directory traversal in an m=database&c=down_sql&name=../ URI.

  • CVE-2018-18703HigOct 29, 2018
    risk 0.49cvss 7.5epss 0.04

    PhpTpoint Mailing Server Using File Handling 1.0 suffers from multiple Arbitrary File Read vulnerabilities in different sections that allow an attacker to read sensitive files on the system via directory traversal, bypassing the login page, as demonstrated by the…

  • CVE-2018-17444HigOct 23, 2018
    risk 0.49cvss 7.5epss 0.04

    A Directory Traversal issue was discovered in Citrix SD-WAN 10.1.0 and NetScaler SD-WAN 9.3.x before 9.3.6 and 10.0.x before 10.0.4.