VYPR

CWE-22

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')

BaseStableLikelihood: High

Description

The product uses external input to construct a pathname that is intended to identify a file or directory that is located underneath a restricted parent directory, but the product does not properly neutralize special elements within the pathname that can cause the pathname to resolve to a location that is outside of the restricted directory.

Hierarchy (View 1000)

Parents

Children

Related attack patterns (CAPEC)

CAPEC-126 · CAPEC-64 · CAPEC-76 · CAPEC-78 · CAPEC-79

CVEs mapped to this weakness (10,395)

page 201 of 520
  • CVE-2023-49788HigDec 8, 2023
    risk 0.47cvss 7.2epss 0.01

    Collabora Online is a collaborative online office suite based on LibreOffice technology. Unlike a standalone dedicated Collabora Online server, the Built-in CODE Server (richdocumentscode) is run without chroot sandboxing. Vulnerable versions of the richdocumentscode app can be…

  • CVE-2023-46496HigDec 8, 2023
    risk 0.47cvss 8.3epss 0.01

    Directory Traversal vulnerability in EverShop NPM versions before v.1.0.0-rc.8 allows a remote attacker to obtain sensitive information via a crafted request to the DELETE function in api/files endpoint.

  • CVE-2023-22273HigNov 17, 2023
    risk 0.47cvss 7.2epss 0.02

    Adobe RoboHelp Server versions 11.4 and earlier are affected by an Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability that could lead to Remote Code Execution by an admin authenticated attacker. Exploitation of this issue does not…

  • CVE-2023-24592HigNov 14, 2023
    risk 0.47cvss 7.3epss 0.00

    Path traversal in the some Intel(R) oneAPI Toolkits and Component software before version 2023.1 may allow authenticated user to potentially enable escalation of privilege via local access.

  • CVE-2023-45880HigNov 14, 2023
    risk 0.47cvss 7.2epss 0.01

    GibbonEdu Gibbon through version 25.0.0 allows Directory Traversal via the report template builder. An attacker can create a new Asset Component. The templateFileDestination parameter can be set to an arbitrary pathname (and extension). This allows creation of PHP files outside…

  • CVE-2023-20220HigNov 1, 2023
    risk 0.47cvss 7.2epss 0.01

    Multiple vulnerabilities in the web-based management interface of Cisco Firepower Management Center (FMC) Software could allow an authenticated, remote attacker to execute arbitrary commands on the underlying operating system. To exploit these vulnerabilities, the attacker must…

  • CVE-2023-45686HigOct 16, 2023
    risk 0.47cvss 7.2epss 0.01

    Insufficient path validation when writing a file via WebDAV in South River Technologies' Titan MFT and Titan SFTP servers on Linux allows an authenticated attacker to write a file to any location on the filesystem via path traversal

  • CVE-2023-37428HigAug 22, 2023
    risk 0.47cvss 7.2epss 0.01

    A vulnerability in the EdgeConnect SD-WAN Orchestrator web-based management interface allows remote authenticated users to run arbitrary commands on the underlying host. A successful exploit could allow an attacker to execute arbitrary commands as root on the underlying…

  • CVE-2023-36220HigAug 7, 2023
    risk 0.47cvss 7.2epss 0.03

    Directory Traversal vulnerability in Textpattern CMS v4.8.8 allows a remote authenticated attacker to execute arbitrary code and gain access to sensitive information via the plugin Upload function.

  • CVE-2023-23842HigJul 26, 2023
    risk 0.47cvss 7.2epss 0.03

    The SolarWinds Network Configuration Manager was susceptible to the Directory Traversal Vulnerability. This vulnerability allows users with administrative access to SolarWinds Web Console to execute arbitrary commands.

  • CVE-2023-2435HigMay 31, 2023
    risk 0.47cvss 7.2epss 0.01

    The Blog-in-Blog plugin for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 2.0.0 via a shortcode attribute. This allows editor-level, and above, attackers to include and execute arbitrary files on the server, allowing the execution of any PHP…

  • CVE-2023-22914HigApr 24, 2023
    risk 0.47cvss 7.2epss 0.01

    A path traversal vulnerability in the “account_print.cgi” CGI program of Zyxel USG FLEX series firmware versions 4.50 through 5.35, and VPN series firmware versions 4.30 through 5.35, which could allow a remote authenticated attacker with administrator privileges to execute…

  • CVE-2023-26293HigApr 11, 2023
    risk 0.47cvss 7.3epss 0.00

    A vulnerability has been identified in Totally Integrated Automation Portal (TIA Portal) V15 (All versions), Totally Integrated Automation Portal (TIA Portal) V16 (All versions < V16 Update 7), Totally Integrated Automation Portal (TIA Portal) V17 (All versions < V17 Update 6),…

  • CVE-2023-22774HigMar 1, 2023
    risk 0.47cvss 7.2epss 0.01

    Authenticated path traversal vulnerabilities exist in the ArubaOS command line interface. Successful exploitation of these vulnerabilities result in the ability to delete arbitrary files in the underlying operating system.

  • CVE-2023-22773HigMar 1, 2023
    risk 0.47cvss 7.2epss 0.01

    Authenticated path traversal vulnerabilities exist in the ArubaOS command line interface. Successful exploitation of these vulnerabilities result in the ability to delete arbitrary files in the underlying operating system.

  • CVE-2022-33892HigFeb 16, 2023
    risk 0.47cvss 7.3epss 0.00

    Path traversal in the Intel(R) Quartus Prime Pro and Standard edition software may allow an authenticated user to potentially enable escalation of privilege via local access.

  • CVE-2023-0862HigFeb 16, 2023
    risk 0.47cvss 7.2epss 0.02

    The NetModule NSRW web administration interface is vulnerable to path traversals, which could lead to arbitrary file uploads and deletion. By uploading malicious files to the web root directory, authenticated users could gain remote command execution with elevated privileges. …

  • CVE-2022-45867HigJan 3, 2023
    risk 0.47cvss 7.2epss 0.01

    MyBB before 1.8.33 allows Directory Traversal. The Admin CP Languages module allows remote authenticated users, with high privileges, to achieve local file inclusion and execution.

  • CVE-2022-41158HigNov 25, 2022
    risk 0.47cvss 7.2epss 0.02

    Remote code execution vulnerability can be achieved by using cookie values as paths to a file by this builder program. A remote attacker could exploit the vulnerability to execute or inject malicious code.

  • CVE-2022-45184HigNov 14, 2022
    risk 0.47cvss 7.2epss 0.02

    The Web Server in Ironman Software PowerShell Universal v3.x and v2.x allows for directory traversal outside of the configuration directory, which allows a remote attacker with administrator privilege to create, delete, update, and display files outside of the configuration…