VYPR

CWE-22

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')

BaseStableLikelihood: High

Description

The product uses external input to construct a pathname that is intended to identify a file or directory that is located underneath a restricted parent directory, but the product does not properly neutralize special elements within the pathname that can cause the pathname to resolve to a location that is outside of the restricted directory.

Hierarchy (View 1000)

Parents

Children

Related attack patterns (CAPEC)

CAPEC-126 · CAPEC-64 · CAPEC-76 · CAPEC-78 · CAPEC-79

CVEs mapped to this weakness (10,395)

page 20 of 520
  • CVE-2024-31849CriApr 5, 2024
    risk 0.64cvss 9.8epss 0.06

    A path traversal vulnerability exists in the Java version of CData Connect < 23.4.8846 when running using the embedded Jetty server, which could allow an unauthenticated remote attacker to gain complete administrative access to the application.

  • CVE-2024-31848CriApr 5, 2024
    risk 0.64cvss 9.8epss 0.08

    A path traversal vulnerability exists in the Java version of CData API Server < 23.4.8844 when running using the embedded Jetty server, which could allow an unauthenticated remote attacker to gain complete administrative access to the application.

  • CVE-2024-25693CriApr 4, 2024
    risk 0.64cvss 9.9epss 0.01

    There is a path traversal in Esri Portal for ArcGIS versions <= 11.2. Successful exploitation may allow a remote, authenticated attacker to traverse the file system to access files or execute code outside of the intended directory. 

  • CVE-2024-27768CriMar 18, 2024
    risk 0.64cvss 9.8epss 0.01

    Unitronics Unistream Unilogic – Versions prior to 1.35.227 - CWE-22: 'Path Traversal' may allow RCE

  • CVE-2024-28222CriMar 7, 2024
    risk 0.64cvss 9.8epss 0.01

    In Veritas NetBackup before 8.1.2 and NetBackup Appliance before 3.1.2, the BPCD process inadequately validates the file path, allowing an unauthenticated attacker to upload and execute a custom file.

  • CVE-2024-27764CriMar 5, 2024
    risk 0.64cvss 9.8epss 0.01

    An issue in Jeewms v.3.7 and before allows a remote attacker to escalate privileges via the AuthInterceptor component.

  • CVE-2024-26261CriFeb 15, 2024
    risk 0.64cvss 9.8epss 0.01

    The functionality for file download in HGiga OAKlouds' certain modules contains an Arbitrary File Read and Delete vulnerability. Attackers can put file path in specific request parameters, allowing them to download the file without login. Furthermore, the file will be deleted…

  • CVE-2023-40266CriFeb 8, 2024
    risk 0.64cvss 9.8epss 0.01

    An issue was discovered in Atos Unify OpenScape Xpressions WebAssistant V7 before V7R1 FR5 HF42 P911. It allows path traversal.

  • CVE-2024-24398CriFeb 6, 2024
    risk 0.64cvss 9.8epss 0.02

    Directory Traversal vulnerability in Stimulsoft GmbH Stimulsoft Dashboard.JS before v.2024.1.2 allows a remote attacker to execute arbitrary code via a crafted payload to the fileName parameter of the Save function.

  • CVE-2023-7077CriFeb 5, 2024
    risk 0.64cvss 9.8epss 0.01

    Sharp NEC Displays (P403, P463, P553, P703, P801, X554UN, X464UN, X554UNS, X464UNV, X474HB, X464UNS, X554UNV, X555UNS, X555UNV, X754HB, X554HB, E705, E805, E905, UN551S, UN551VS, X551UHD, X651UHD, X841UHD, X981UHD, MD551C8) allows an attacker execute remote code by sending…

  • CVE-2024-24482CriFeb 2, 2024
    risk 0.64cvss 9.8epss 0.01

    Aprktool before 2.9.3 on Windows allows ../ and /.. directory traversal.

  • CVE-2023-49569CriJan 12, 2024
    risk 0.64cvss 9.8epss 0.02

    A path traversal vulnerability was discovered in go-git versions prior to v5.11. This vulnerability allows an attacker to create and amend files across the filesystem. In the worse case scenario, remote code execution could be achieved. Applications are only affected if they…

  • CVE-2023-6190CriDec 27, 2023
    risk 0.64cvss 9.8epss 0.01

    Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in İzmir Katip Çelebi University University Information Management System allows Absolute Path Traversal. This issue affects University Information Management System: before…

  • CVE-2023-5991CriDec 26, 2023
    risk 0.64cvss 9.8epss 0.03

    The Hotel Booking Lite WordPress plugin before 4.8.5 does not validate file paths provided via user input, as well as does not have proper CSRF and authorisation checks, allowing unauthenticated users to download and delete arbitrary files on the server

  • CVE-2023-6026CriNov 30, 2023
    risk 0.64cvss 9.8epss 0.01

    A Path traversal vulnerability has been reported in elijaa/phpmemcachedadmin affecting version 1.3.0. This vulnerability allows an attacker to delete files stored on the server due to lack of proper verification of user-supplied input.

  • CVE-2023-42000CriNov 27, 2023
    risk 0.64cvss 9.8epss 0.01

    Arcserve UDP prior to 9.2 contains a path traversal vulnerability in com.ca.arcflash.ui.server.servlet.FileHandlingServlet.doUpload(). An unauthenticated remote attacker can exploit it to upload arbitrary files to any location on the file system where the UDP agent is installed.

  • CVE-2023-30967CriOct 26, 2023
    risk 0.64cvss 9.8epss 0.01

    Gotham Orbital-Simulator service prior to 0.692.0 was found to be vulnerable to a Path traversal issue allowing an unauthenticated user to read arbitrary files on the file system.

  • CVE-2023-39332CriOct 18, 2023
    risk 0.64cvss 9.8epss 0.02

    Various `node:fs` functions allow specifying paths as either strings or `Uint8Array` objects. In Node.js environments, the `Buffer` class extends the `Uint8Array` class. Node.js prevents path traversal through strings (see CVE-2023-30584) and `Buffer` objects (see…

  • CVE-2023-3701CriOct 4, 2023
    risk 0.64cvss 9.9epss 0.01

    Aqua Drive, in its 2.4 version, is vulnerable to a relative path traversal vulnerability. By exploiting this vulnerability, an authenticated non privileged user could access/modify stored resources of other users. It could also be possible to access and modify the source and…

  • CVE-2023-44172CriSep 27, 2023
    risk 0.64cvss 9.8epss 0.01

    SeaCMS V12.9 was discovered to contain an arbitrary file write vulnerability via the component admin_weixin.php.