VYPR

CWE-22

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')

BaseStableLikelihood: High

Description

The product uses external input to construct a pathname that is intended to identify a file or directory that is located underneath a restricted parent directory, but the product does not properly neutralize special elements within the pathname that can cause the pathname to resolve to a location that is outside of the restricted directory.

Hierarchy (View 1000)

Parents

Children

Related attack patterns (CAPEC)

CAPEC-126 · CAPEC-64 · CAPEC-76 · CAPEC-78 · CAPEC-79

CVEs mapped to this weakness (10,395)

page 203 of 520
  • CVE-2021-23391HigJun 7, 2021
    risk 0.47cvss 7.3epss 0.00

    This affects all versions of package calipso. It is possible for a malicious module to overwrite files on an arbitrary file system through the module install functionality.

  • CVE-2021-1435HigMar 24, 2021
    risk 0.47cvss 7.2epss 0.08

    A vulnerability in the web UI of Cisco IOS XE Software could allow an authenticated, remote attacker to inject arbitrary commands that can be executed as the root user. This vulnerability is due to insufficient input validation. An attacker could exploit this vulnerability by…

  • CVE-2021-26725HigFeb 22, 2021
    risk 0.47cvss 7.2epss 0.01

    Path Traversal vulnerability when changing timezone using web GUI of Nozomi Networks Guardian, CMC allows an authenticated administrator to read-protected system files. This issue affects: Nozomi Networks Guardian 20.0.7.3 version 20.0.7.3 and prior versions. Nozomi Networks CMC…

  • CVE-2021-20072HigFeb 16, 2021
    risk 0.47cvss 7.2epss 0.01

    Racom's MIDGE Firmware 4.4.40.105 contains an issue that allows attackers to arbitrarily access and delete files via an authenticated directory traveral.

  • CVE-2020-3588HigNov 6, 2020
    risk 0.47cvss 7.3epss 0.00

    A vulnerability in virtualization channel messaging in Cisco Webex Meetings Desktop App for Windows could allow a local attacker to execute arbitrary code on a targeted system. This vulnerability occurs when this app is deployed in a virtual desktop environment and using virtual…

  • CVE-2020-27128MedNov 6, 2020
    risk 0.47cvss 6.5epss 0.61

    A vulnerability in the application data endpoints of Cisco SD-WAN vManage Software could allow an authenticated, remote attacker to write arbitrary files to an affected system. The vulnerability is due to improper validation of requests to APIs. An attacker could exploit this…

  • CVE-2020-3143HigSep 23, 2020
    risk 0.47cvss 7.2epss 0.08

    A vulnerability in the video endpoint API (xAPI) of Cisco TelePresence Collaboration Endpoint (CE) Software, Cisco TelePresence Codec (TC) Software, and Cisco RoomOS Software could allow an authenticated, remote attacker to conduct directory traversal attacks on an affected…

  • CVE-2020-14028HigSep 22, 2020
    risk 0.47cvss 7.2epss 0.02

    An issue was discovered in Ozeki NG SMS Gateway through 4.17.6. By leveraging a path traversal vulnerability in the Autoreply module's Script Name, an attacker may write to or overwrite arbitrary files, with arbitrary content, usually with NT AUTHORITY\SYSTEM privileges.

  • CVE-2019-19834HigJan 22, 2020
    risk 0.47cvss 7.2epss 0.02

    Directory Traversal in ruckus_cli2 in Ruckus Wireless Unleashed through 200.7.10.102.64 allows a remote attacker to jailbreak the CLI via enable->debug->script->exec with ../../../bin/sh as the parameter.

  • CVE-2019-19848HigDec 17, 2019
    risk 0.47cvss 7.2epss 0.01

    An issue was discovered in TYPO3 before 8.7.30, 9.x before 9.5.12, and 10.x before 10.2.2. It has been discovered that the extraction of manually uploaded ZIP archives in Extension Manager is vulnerable to directory traversal. Admin privileges are required in order to exploit…

  • CVE-2011-4350MedNov 26, 2019
    risk 0.47cvss 6.5epss 0.16

    Yaws 1.91 has a directory traversal vulnerability in the way certain URLs are processed. A remote authenticated user could use this flaw to obtain content of arbitrary local files via specially-crafted URL request.

  • CVE-2019-17327HigNov 8, 2019
    risk 0.47cvss 7.2epss 0.03

    JEUS 7 Fix#0~5 and JEUS 8Fix#0~1 versions contains a directory traversal vulnerability caused by improper input parameter check when uploading installation file in administration web page. That leads remote attacker to execute arbitrary code via uploaded file.

  • CVE-2019-17314HigOct 7, 2019
    risk 0.47cvss 7.2epss 0.02

    SugarCRM before 8.0.4 and 9.x before 9.0.2 allows directory traversal in the Configurator module by an Admin user.

  • CVE-2019-11013MedAug 22, 2019
    risk 0.47cvss 6.5epss 0.27

    Nimble Streamer 3.0.2-2 through 3.5.4-9 has a ../ directory traversal vulnerability. Successful exploitation could allow an attacker to traverse the file system to access files or directories that are outside of the restricted directory on the remote server.

  • CVE-2019-14312MedAug 9, 2019
    risk 0.47cvss 6.5epss 0.21

    Aptana Jaxer 1.0.3.4547 is vulnerable to a local file inclusion vulnerability in the wikilite source code viewer. This vulnerability allows a remote attacker to read internal files on the server via a tools/sourceViewer/index.html?filename=../ URI.

  • CVE-2019-10717HigJul 3, 2019
    risk 0.47cvss 7.1epss 0.05

    BlogEngine.NET 3.3.7.0 allows /api/filemanager Directory Traversal via the path parameter.

  • CVE-2016-10751HigMay 24, 2019
    risk 0.47cvss 7.2epss 0.03

    osClass 3.6.1 allows oc-admin/plugins.php Directory Traversal via the plugin parameter. This is exploitable for remote PHP code execution because an administrator can upload an image that contains PHP code in the EXIF data via index.php?page=ajax&action=ajax_upload.

  • CVE-2018-19512HigMar 21, 2019
    risk 0.47cvss 7.2epss 0.07

    In Webgalamb through 7.0, a system/ajax.php "wgmfile restore" directory traversal vulnerability could lead to arbitrary code execution by authenticated administrator users, because PHP files are restored under the document root directory.

  • CVE-2018-1000863HigDec 10, 2018
    risk 0.47cvss 8.2epss 0.07

    A data modification vulnerability exists in Jenkins 2.153 and earlier, LTS 2.138.3 and earlier in User.java, IdStrategy.java that allows attackers to submit crafted user names that can cause an improper migration of user record storage formats, potentially preventing the victim…

  • CVE-2018-9445MedNov 6, 2018
    risk 0.47cvss 6.8epss 0.01

    In readMetadata of Utils.cpp, there is a possible path traversal bug due to a confused deputy. This could lead to local escalation of privilege when mounting a USB device with no additional execution privileges needed. User interaction is not needed for exploitation. Product:…