VYPR

CWE-22

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')

BaseStableLikelihood: High

Description

The product uses external input to construct a pathname that is intended to identify a file or directory that is located underneath a restricted parent directory, but the product does not properly neutralize special elements within the pathname that can cause the pathname to resolve to a location that is outside of the restricted directory.

Hierarchy (View 1000)

Parents

Children

Related attack patterns (CAPEC)

CAPEC-126 · CAPEC-64 · CAPEC-76 · CAPEC-78 · CAPEC-79

CVEs mapped to this weakness (10,395)

page 18 of 520
  • CVE-2024-11314CriNov 18, 2024
    risk 0.64cvss 9.8epss 0.01

    The DVC from TRCore has a Path Traversal vulnerability and does not restrict the types of uploaded files. This allows unauthenticated remote attackers to upload arbitrary files to any directory, leading to arbitrary code execution by uploading webshells.

  • CVE-2024-11313CriNov 18, 2024
    risk 0.64cvss 9.8epss 0.01

    The DVC from TRCore has a Path Traversal vulnerability and does not restrict the types of uploaded files. This allows unauthenticated remote attackers to upload arbitrary files to any directory, leading to arbitrary code execution by uploading webshells.

  • CVE-2024-11312CriNov 18, 2024
    risk 0.64cvss 9.8epss 0.01

    The DVC from TRCore has a Path Traversal vulnerability and does not restrict the types of uploaded files. This allows unauthenticated remote attackers to upload arbitrary files to any directory, leading to arbitrary code execution by uploading webshells.

  • CVE-2024-11311CriNov 18, 2024
    risk 0.64cvss 9.8epss 0.01

    The DVC from TRCore has a Path Traversal vulnerability and does not restrict the types of uploaded files. This allows unauthenticated remote attackers to upload arbitrary files to any directory, leading to arbitrary code execution by uploading webshells.

  • CVE-2024-50649CriNov 15, 2024
    risk 0.64cvss 9.8epss 0.01

    The user avatar upload function in python_book V1.0 has an arbitrary file upload vulnerability.

  • CVE-2024-50648CriNov 15, 2024
    risk 0.64cvss 9.8epss 0.01

    yshopmall V1.0 has an arbitrary file upload vulnerability, which can enable RCE or even take over the server when improperly configured to parse JSP files.

  • CVE-2024-11150CriNov 13, 2024
    risk 0.64cvss 9.8epss 0.01

    The WordPress User Extra Fields plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the delete_tmp_uploaded_file() function in all versions up to, and including, 16.6. This makes it possible for unauthenticated attackers to…

  • CVE-2024-46888CriNov 12, 2024
    risk 0.64cvss 9.9epss 0.01

    A vulnerability has been identified in SINEC INS (All versions < V1.0 SP2 Update 3). The affected application does not properly sanitize user provided paths for SFTP-based file up- and downloads. This could allow an authenticated remote attacker to manipulate arbitrary files on…

  • CVE-2024-10625CriNov 9, 2024
    risk 0.64cvss 9.8epss 0.01

    The WooCommerce Support Ticket System plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the delete_tmp_uploaded_file() function in all versions up to, and including, 17.7. This makes it possible for unauthenticated…

  • CVE-2024-39332CriOct 31, 2024
    risk 0.64cvss 9.8epss 0.01

    Webswing 23.2.2 allows remote attackers to modify client-side JavaScript code to achieve path traversal, likely leading to remote code execution via modification of shell scripts on the server.

  • CVE-2024-41717CriOct 22, 2024
    risk 0.64cvss 9.8epss 0.01

    Kieback & Peter's DDC4000 series is vulnerable to a path traversal vulnerability, which may allow an unauthenticated attacker to read files on the system.

  • CVE-2019-25213CriOct 16, 2024
    risk 0.64cvss 9.8epss 0.03

    The Advanced Access Manager plugin for WordPress is vulnerable to Unauthenticated Arbitrary File Read in versions up to, and including, 5.9.8.1 due to insufficient validation on the aam-media parameter. This allows unauthenticated attackers to read any file on the server,…

  • CVE-2024-46446CriOct 7, 2024
    risk 0.64cvss 9.8epss 0.01

    Mecha CMS 3.0.0 is vulnerable to Directory Traversal. An attacker can construct cookies and URIs that bypass user identity checks. Parameters can then be passed through the POST method, resulting in the Deletion of Arbitrary Files or Website Takeover.

  • CVE-2024-33109CriSep 19, 2024
    risk 0.64cvss 9.9epss 0.01

    Directory Traversal in the web interface of the Tiptel IP 286 with firmware version 2.61.13.10 allows attackers to overwrite arbitrary files on the phone via the Ringtone upload function.

  • CVE-2024-46376CriSep 18, 2024
    risk 0.64cvss 9.8epss 0.01

    Best House Rental Management System 1.0 contains an arbitrary file upload vulnerability in the update_account() function of the file rental/admin_class.php.

  • CVE-2024-46375CriSep 18, 2024
    risk 0.64cvss 9.8epss 0.01

    Best House Rental Management System 1.0 contains an arbitrary file upload vulnerability in the signup() function of the file rental/admin_class.php.

  • CVE-2024-7961CriSep 12, 2024
    risk 0.64cvss 9.8epss 0.01

    A path traversal vulnerability exists in the Rockwell Automation affected product. If exploited, the threat actor could upload arbitrary files to the server that could result in a remote code execution.

  • CVE-2024-44761CriAug 28, 2024
    risk 0.64cvss 9.8epss 0.01

    An issue in EQ Enterprise Management System before v2.0.0 allows attackers to execute a directory traversal via crafted requests.

  • CVE-2024-3980CriAug 27, 2024
    risk 0.64cvss 9.9epss 0.01

    The MicroSCADA Pro/X SYS600 product allows an authenticated user input to control or influence paths or file names that are used in filesystem operations. If exploited the vulnerability allows the attacker to access or modify system files or other files that are critical to the…

  • CVE-2023-7249CriAug 12, 2024
    risk 0.64cvss 9.8epss 0.01

    Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in OpenText OpenText Directory Services allows Path Traversal.This issue affects OpenText Directory Services: from 16.4.2 before 24.1.