VYPR

CWE-22

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')

BaseStableLikelihood: High

Description

The product uses external input to construct a pathname that is intended to identify a file or directory that is located underneath a restricted parent directory, but the product does not properly neutralize special elements within the pathname that can cause the pathname to resolve to a location that is outside of the restricted directory.

Hierarchy (View 1000)

Parents

Children

Related attack patterns (CAPEC)

CAPEC-126 · CAPEC-64 · CAPEC-76 · CAPEC-78 · CAPEC-79

CVEs mapped to this weakness (10,395)

page 178 of 520
  • CVE-2018-18485HigOct 18, 2018
    risk 0.49cvss 7.5epss 0.02

    An issue was discovered in PHPSHE 1.7. admin.php?mod=db&act=del allows remote attackers to delete arbitrary files via directory traversal sequences in the dbname parameter. This can be leveraged to reload the product by deleting install.lock.

  • CVE-2018-18257HigOct 11, 2018
    risk 0.49cvss 7.5epss 0.02

    An issue was discovered in BageCMS 3.1.3. An attacker can delete any files and folders on the web server via an index.php?r=admini/template/batch&command=deleteFile&fileName= or index.php?r=admini/template/batch&command=deleteFolder&folderName=../ directory traversal URI.

  • CVE-2018-0405HigOct 5, 2018
    risk 0.49cvss 7.5epss 0.03

    A vulnerability in the web framework code for Cisco RV180W Wireless-N Multifunction VPN Router and Small Business RV Series RV220W Wireless Network Security Firewall could allow an unauthenticated, remote attacker to conduct a directory path traversal attack on a targeted…

  • CVE-2018-17838HigOct 1, 2018
    risk 0.49cvss 7.5epss 0.02

    An issue was discovered in JTBC(PHP) 3.0.1.6. Arbitrary file read operations are possible via a /console/#/console/file/manage.php?type=list&path=c:/ substring.

  • CVE-2018-17837HigOct 1, 2018
    risk 0.49cvss 7.5epss 0.01

    An issue was discovered in JTBC(PHP) 3.0.1.6. Arbitrary file deletion is possible via a /console/file/manage.php?type=action&action=delete&path=c%3A%2F substring.

  • CVE-2018-17785HigSep 30, 2018
    risk 0.49cvss 7.5epss 0.02

    In blynk-server in Blynk before 0.39.7, Directory Traversal exists via a ../ in a URI that has /static or /static/js at the beginning, as demonstrated by reading the /etc/passwd file.

  • CVE-2018-7102HigSep 27, 2018
    risk 0.49cvss 7.5epss 0.03

    A security vulnerability in HPE Intelligent Management Center (iMC) PLAT E0506P09, createFabricAutoCfgFile could be remotely exploited via directory traversal to allow remote arbitrary file modification.

  • CVE-2018-17365HigSep 26, 2018
    risk 0.49cvss 7.5epss 0.02

    SeaCMS 6.64 and 7.2 allows remote attackers to delete arbitrary files via the filedir parameter.

  • CVE-2018-17297HigSep 21, 2018
    risk 0.49cvss 7.5epss 0.03

    The unzip function in ZipUtil.java in Hutool before 4.1.12 allows remote attackers to overwrite arbitrary files via directory traversal sequences in a filename within a ZIP archive.

  • CVE-2018-6500HigSep 20, 2018
    risk 0.49cvss 7.5epss 0.04

    A potential Directory Traversal Security vulnerability has been identified in ArcSight Management Center (ArcMC) in all versions prior to 2.81. This vulnerability could be remotely exploited to allow Directory Traversal.

  • CVE-2018-16820HigSep 18, 2018
    risk 0.49cvss 7.5epss 0.02

    admin/index.php in Monstra CMS 3.0.4 allows arbitrary directory listing via id=filesmanager&path=uploads/.......//./.......//./ requests.

  • CVE-2018-17125HigSep 17, 2018
    risk 0.49cvss 7.5epss 0.01

    CScms 4.1 allows arbitrary directory deletion via a dir=..\\ substring to plugins\sys\admin\Plugins.php.

  • CVE-2018-16774HigSep 10, 2018
    risk 0.49cvss 7.5epss 0.02

    HongCMS 3.0.0 allows arbitrary file deletion via a ../ in the file parameter to admin/index.php/language/ajax?action=delete.

  • CVE-2018-16446HigSep 4, 2018
    risk 0.49cvss 7.5epss 0.02

    An issue was discovered in SeaCMS through 6.61. adm1n/admin_database.php allows remote attackers to delete arbitrary files via directory traversal sequences in the bakfiles parameter. This can allow the product to be reinstalled by deleting install_lock.txt.

  • CVE-2018-16344HigSep 2, 2018
    risk 0.49cvss 7.5epss 0.02

    An issue was discovered in zzcms 8.3. It allows remote attackers to delete arbitrary files via directory traversal sequences in the flv parameter. This can be leveraged for database access by deleting install.lock.

  • CVE-2018-3787HigAug 31, 2018
    risk 0.49cvss 7.5epss 0.02

    Path traversal in simplehttpserver <v0.2.1 allows listing any file on the server.

  • CVE-2018-11720HigAug 30, 2018
    risk 0.49cvss 7.5epss 0.02

    Xovis PC2, PC2R, and PC3 devices through 3.6.0 allow Directory Traversal.

  • CVE-2018-15810HigAug 27, 2018
    risk 0.49cvss 7.5epss 0.02

    Visiology Flipbox Software Suite before 2.7.0 allows directory traversal via %5c%2e%2e%2f because it does not sanitize filename parameters.

  • CVE-2018-15694HigAug 27, 2018
    risk 0.49cvss 7.5epss 0.02

    ASUSTOR Data Master 3.1.5 and below allows authenticated remote non-administrative users to upload files to arbitrary locations due to a path traversal vulnerability. This could lead to code execution if the "Web Server" feature is enabled.

  • CVE-2018-14429HigAug 14, 2018
    risk 0.49cvss 7.5epss 0.04

    man-cgi before 1.16 allows Local File Inclusion via absolute path traversal, as demonstrated by a cgi-bin/man-cgi?/etc/passwd URI.