VYPR

CWE-22

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')

BaseStableLikelihood: High

Description

The product uses external input to construct a pathname that is intended to identify a file or directory that is located underneath a restricted parent directory, but the product does not properly neutralize special elements within the pathname that can cause the pathname to resolve to a location that is outside of the restricted directory.

Hierarchy (View 1000)

Parents

Children

Related attack patterns (CAPEC)

CAPEC-126 · CAPEC-64 · CAPEC-76 · CAPEC-78 · CAPEC-79

CVEs mapped to this weakness (10,395)

page 200 of 520
  • CVE-2024-42501HigSep 17, 2024
    risk 0.47cvss 7.2epss 0.01

    An authenticated Path Traversal vulnerabilities exists in the ArubaOS. Successful exploitation of this vulnerability allows an attacker to install unsigned packages on the underlying operating system, enabling the threat actor to execute arbitrary code or install implants.

  • CVE-2024-34656HigSep 4, 2024
    risk 0.47cvss 7.3epss 0.00

    Path traversal in Samsung Notes prior to version 4.4.21.62 allows local attackers to execute arbitrary code.

  • CVE-2024-2602HigJul 11, 2024
    risk 0.47cvss 7.3epss 0.00

    CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability exists that could result in remote code execution when an authenticated user executes a saved project file that has been tampered by a malicious actor.

  • CVE-2024-27178HigJun 14, 2024
    risk 0.47cvss 7.2epss 0.01

    An attacker can get Remote Code Execution by overwriting files. Overwriting files is enable by falsifying file name variable. This vulnerability can be executed in combination with other vulnerabilities and difficult to execute alone. So, the CVSS score for this vulnerability…

  • CVE-2024-27177HigJun 14, 2024
    risk 0.47cvss 7.2epss 0.01

    An attacker can get Remote Code Execution by overwriting files. Overwriting files is enable by falsifying package name variable. This vulnerability can be executed in combination with other vulnerabilities and difficult to execute alone. So, the CVSS score for this…

  • CVE-2024-27176HigJun 14, 2024
    risk 0.47cvss 7.2epss 0.01

    An attacker can get Remote Code Execution by overwriting files. Overwriting files is enable by falsifying session ID variable. This vulnerability can be executed in combination with other vulnerabilities and difficult to execute alone. So, the CVSS score for this vulnerability…

  • CVE-2024-35219HigMay 27, 2024
    risk 0.47cvss 8.3epss 0.04

    OpenAPI Generator allows generation of API client libraries (SDK generation), server stubs, documentation and configuration automatically given an OpenAPI Spec. Prior to version 7.6.0, attackers can exploit a path traversal vulnerability to read and delete files and folders from…

  • CVE-2024-4347HigMay 23, 2024
    risk 0.47cvss 7.2epss 0.01

    The WP Fastest Cache plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 1.2.6 via the specificDeleteCache function. This makes it possible for authenticated attackers to delete arbitrary files on the server, which can include…

  • CVE-2023-37385HigMay 17, 2024
    risk 0.47cvss 7.3epss 0.01

    Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in StylemixThemes Consulting allows PHP Local File Inclusion.This issue affects Consulting: from n/a through 6.5.6.

  • CVE-2023-42033HigMay 3, 2024
    risk 0.47cvss 7.2epss 0.03

    Visualware MyConnection Server doPostUploadfiles Directory Traversal Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Visualware MyConnection Server. Although authentication is required to…

  • CVE-2023-39460HigMay 3, 2024
    risk 0.47cvss 7.2epss 0.03

    Triangle MicroWorks SCADA Data Gateway Event Log Directory Traversal Arbitrary File Creation Vulnerability. This vulnerability allows remote attackers to create arbitrary files on affected installations of Triangle MicroWorks SCADA Data Gateway. Although authentication is…

  • CVE-2024-31220HigApr 5, 2024
    risk 0.47cvss 7.3epss 0.00

    Sunshine is a self-hosted game stream host for Moonlight. Starting in version 0.16.0 and prior to version 0.18.0, an attacker may be able to remotely read arbitrary files without authentication due to a path traversal vulnerability. Users who exposed the Sunshine configuration…

  • CVE-2023-41973HigMar 26, 2024
    risk 0.47cvss 7.3epss 0.00

    ZSATray passes the previousInstallerName as a config parameter to TrayManager, and TrayManager constructs the path and appends previousInstallerName to get the full path of the exe. Fixed Version: Win ZApp 4.3.0.121 and later.

  • CVE-2023-41877HigMar 20, 2024
    risk 0.47cvss 7.2epss 0.01

    GeoServer is an open source software server written in Java that allows users to share and edit geospatial data. A path traversal vulnerability in versions 2.23.4 and prior requires GeoServer Administrator with access to the admin console to misconfigure the Global Settings for…

  • CVE-2024-27121HigMar 12, 2024
    risk 0.47cvss 7.2epss 0.01

    Path traversal vulnerability exists in Machine Automation Controller NJ Series and Machine Automation Controller NX Series. An arbitrary file in the affected product may be accessed or arbitrary code may be executed by processing a specially crafted request sent from a remote…

  • CVE-2023-6294HigFeb 12, 2024
    risk 0.47cvss 7.2epss 0.01

    The Popup Builder WordPress plugin before 4.2.6 does not validate a parameter before making a request to it, which could allow users with the administrator role to perform SSRF attack in Multisite WordPress configurations.

  • CVE-2021-46902HigFeb 4, 2024
    risk 0.47cvss 7.2epss 0.01

    An issue was discovered in LTOS-Web-Interface in Meinberg LANTIME-Firmware before 6.24.029 MBGID-9343 and 7 before 7.04.008 MBGID-6303. Path validation is mishandled, and thus an admin can read or delete files in violation of expected access controls.

  • CVE-2023-50916HigJan 10, 2024
    risk 0.47cvss 7.2epss 0.05

    Kyocera Device Manager before 3.1.1213.0 allows NTLM credential exposure during UNC path authentication via a crafted change from a local path to a UNC path. It allows administrators to configure the backup location of the database used by the application. Attempting to change…

  • CVE-2023-6222HigDec 18, 2023
    risk 0.47cvss 7.2epss 0.01

    IThe Quttera Web Malware Scanner WordPress plugin before 3.4.2.1 does not validate user input used in a path, which could allow users with an admin role to perform path traversal attacks

  • CVE-2023-45316HigDec 12, 2023
    risk 0.47cvss 7.3epss 0.00

    Mattermost fails to validate if a relative path is passed in /plugins/playbooks/api/v0/telemetry/run/<telem_run_id> as a telemetry run ID, allowing an attacker to use a path traversal payload that points to a different endpoint leading to a CSRF attack.