VYPR

CWE-22

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')

BaseStableLikelihood: High

Description

The product uses external input to construct a pathname that is intended to identify a file or directory that is located underneath a restricted parent directory, but the product does not properly neutralize special elements within the pathname that can cause the pathname to resolve to a location that is outside of the restricted directory.

Hierarchy (View 1000)

Parents

Children

Related attack patterns (CAPEC)

CAPEC-126 · CAPEC-64 · CAPEC-76 · CAPEC-78 · CAPEC-79

CVEs mapped to this weakness (10,395)

page 186 of 520
  • CVE-2018-9851HigApr 8, 2018
    risk 0.49cvss 7.5epss 0.02

    In Gxlcms QY v1.0.0713, Lib\Lib\Action\Admin\TplAction.class.php allows remote attackers to read any file via a modified pathname in an Admin-Tpl request, as demonstrated by use of '|' instead of '/' as a directory separator, in conjunction with a ".." sequence.

  • CVE-2018-9850HigApr 8, 2018
    risk 0.49cvss 7.5epss 0.02

    In Gxlcms QY v1.0.0713, Lib\Lib\Action\Admin\DataAction.class.php allows remote attackers to delete any file via directory traversal sequences in the id parameter of an Admin-Data-del request.

  • CVE-2018-9331HigApr 7, 2018
    risk 0.49cvss 7.5epss 0.03

    An issue was discovered in zzcms 8.2. user/adv.php allows remote attackers to delete arbitrary files via directory traversal sequences in the oldimg parameter. This can be leveraged for database access by deleting install.lock.

  • CVE-2018-8969HigMar 24, 2018
    risk 0.49cvss 7.5epss 0.03

    An issue was discovered in zzcms 8.2. user/licence_save.php allows remote attackers to delete arbitrary files via directory traversal sequences in the oldimg parameter in an action=modify request. This can be leveraged for database access by deleting install.lock.

  • CVE-2018-8968HigMar 24, 2018
    risk 0.49cvss 7.5epss 0.03

    An issue was discovered in zzcms 8.2. user/manage.php allows remote attackers to delete arbitrary files via directory traversal sequences in the oldimg or oldflv parameter in an action=modify request. This can be leveraged for database access by deleting install.lock.

  • CVE-2018-8965HigMar 24, 2018
    risk 0.49cvss 7.5epss 0.03

    An issue was discovered in zzcms 8.2. user/ppsave.php allows remote attackers to delete arbitrary files via directory traversal sequences in the oldimg parameter in an action=modify request. This can be leveraged for database access by deleting install.lock.

  • CVE-2018-1211HigMar 23, 2018
    risk 0.49cvss 7.5epss 0.03

    Dell EMC iDRAC7/iDRAC8, versions prior to 2.52.52.52, contain a path traversal vulnerability in its Web server's URI parser which could be used to obtain specific sensitive data without authentication. A remote unauthenticated attacker may be able to read configuration settings…

  • CVE-2018-0542HigMar 22, 2018
    risk 0.49cvss 7.5epss 0.02

    Directory traversal vulnerability in WebProxy version 1.7.8 allows an attacker to read arbitrary files via unspecified vectors.

  • CVE-2018-8909HigMar 22, 2018
    risk 0.49cvss 7.5epss 0.02

    The Wire application before 2018-03-07 for Android allows attackers to write to pathnames outside of the downloads directory via a ../ in a filename of a received file, related to AssetService.scala.

  • CVE-2014-3626HigMar 19, 2018
    risk 0.49cvss 7.5epss 0.02

    The Grails Resource Plugin often has to exchange URIs for resources with other internal components. Those other components will decode any URI passed to them. To protect against directory traversal the Grails Resource Plugin did the following: normalized the URI, checked the…

  • CVE-2018-6810HigMar 6, 2018
    risk 0.49cvss 7.5epss 0.04

    Directory traversal vulnerability in NetScaler ADC 10.5, 11.0, 11.1, and 12.0, and NetScaler Gateway 10.5, 11.0, 11.1, and 12.0 allows remote attackers to traverse the directory on the target system via a crafted request.

  • CVE-2018-1316HigMar 5, 2018
    risk 0.49cvss 7.5epss 0.03

    The ODE process deployment web service was sensible to deployment messages with forged names. Using a path for the name was allowing directory traversal, resulting in the potential writing of files under unwanted locations, the overwriting of existing files or their deletion.…

  • CVE-2018-7586HigMar 1, 2018
    risk 0.49cvss 7.5epss 0.02

    In the nextgen-gallery plugin before 2.2.50 for WordPress, gallery paths are not secured.

  • CVE-2017-9447HigFeb 28, 2018
    risk 0.49cvss 7.5epss 0.02

    In the web interface of Parallels Remote Application Server (RAS) 15.5 Build 16140, a vulnerability exists due to improper validation of the file path when requesting a resource under the "RASHTML5Gateway" directory. A remote, unauthenticated attacker could exploit this weakness…

  • CVE-2018-7482HigFeb 28, 2018
    risk 0.49cvss 7.5epss 0.02

    The K2 component 2.8.0 for Joomla! has Incorrect Access Control with directory traversal, allowing an attacker to download arbitrary files, as demonstrated by a view=media&task=connector&cmd=file&target=l1_../configuration.php&download=1 request. The specific pathname…

  • CVE-2018-1299HigFeb 6, 2018
    risk 0.49cvss 7.5epss 0.03

    In Apache Allura before 1.8.0, unauthenticated attackers may retrieve arbitrary files through the Allura web application. Some webservers used with Allura, such as Nginx, Apache/mod_wsgi or paster may prevent the attack from succeeding. Others, such as gunicorn do not prevent it…

  • CVE-2018-1048HigJan 24, 2018
    risk 0.49cvss 7.5epss 0.02

    It was found that the AJP connector in undertow, as shipped in Jboss EAP 7.1.0.GA, does not use the ALLOW_ENCODED_SLASH option and thus allow the the slash / anti-slash characters encoded in the url which may lead to path traversal and result in the information disclosure of…

  • CVE-2018-6184HigJan 24, 2018
    risk 0.49cvss 7.5epss 0.09

    ZEIT Next.js 4 before 4.2.3 has Directory Traversal under the /_next request namespace.

  • CVE-2015-9250HigJan 12, 2018
    risk 0.49cvss 7.5epss 0.02

    An issue was discovered in Skybox Platform before 7.5.201. Directory Traversal exists in /skyboxview/webskybox/attachmentdownload and /skyboxview/webskybox/filedownload via the tempFileName parameter.

  • CVE-2014-5068HigJan 11, 2018
    risk 0.49cvss 7.5epss 0.03

    Directory traversal vulnerability in the web application in Symmetricom s350i 2.70.15 allows remote attackers to read arbitrary files via a (1) ../ (dot dot slash) or (2) ..\ (dot dot forward slash) before a file name.