VYPR

CWE-22

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')

BaseStableLikelihood: High

Description

The product uses external input to construct a pathname that is intended to identify a file or directory that is located underneath a restricted parent directory, but the product does not properly neutralize special elements within the pathname that can cause the pathname to resolve to a location that is outside of the restricted directory.

Hierarchy (View 1000)

Parents

Children

Related attack patterns (CAPEC)

CAPEC-126 · CAPEC-64 · CAPEC-76 · CAPEC-78 · CAPEC-79

CVEs mapped to this weakness (10,395)

page 213 of 520
  • CVE-2023-2270HigJun 15, 2023
    risk 0.46cvss 7.0epss 0.00

    The Netskope client service running with NT\SYSTEM privileges accepts network connections from localhost to start various services and execute commands. The connection handling function of Netskope client before R100 in this service utilized a relative path to download and unzip…

  • CVE-2023-28344HigMay 31, 2023
    risk 0.46cvss 7.1epss 0.01

    An issue was discovered in Faronics Insight 10.0.19045 on Windows. The Insight Teacher Console application allows unauthenticated attackers to view constantly updated screenshots of student desktops and to submit falsified screenshots on behalf of students. Attackers are able to…

  • CVE-2023-25305HigApr 4, 2023
    risk 0.46cvss 7.1epss 0.01

    PolyMC Launcher <= 1.4.3 is vulnerable to Directory Traversal. A mrpack file can be maliciously crafted to create arbitrary files outside of the installation directory.

  • CVE-2023-25303HigApr 4, 2023
    risk 0.46cvss 7.1epss 0.01

    ATLauncher <= 3.4.26.0 is vulnerable to Directory Traversal. A mrpack file can be maliciously crafted to create arbitrary files outside of the installation directory.

  • CVE-2023-1134HigMar 27, 2023
    risk 0.46cvss 7.1epss 0.01

    Delta Electronics InfraSuite Device Master versions prior to 1.0.5 are affected by a path traversal vulnerability, which could allow an attacker to read local files, disclose plaintext credentials, and escalate privileges.

  • CVE-2023-25814HigMar 9, 2023
    risk 0.46cvss 7.1epss 0.01

    metersphere is an open source continuous testing platform. In versions prior to 2.7.1 a user who has permission to create a resource file through UI operations is able to append a path to their submission query which will be read by the system and displayed to the user. This…

  • CVE-2023-24057HigJan 26, 2023
    risk 0.46cvss 8.1epss 0.01

    HL7 (Health Level 7) FHIR Core Libraries before 5.6.92 allow attackers to extract files into arbitrary directories via directory traversal from a crafted ZIP or TGZ archive (for a prepackaged terminology cache, NPM package, or comparison archive).

  • CVE-2022-29844MedJan 26, 2023
    risk 0.46cvss 6.7epss 0.36

    A vulnerability in the FTP service of Western Digital My Cloud OS 5 devices running firmware versions prior to 5.26.119 allows an attacker to read and write arbitrary files. This could lead to a full NAS compromise and would give remote execution capabilities to the attacker.

  • CVE-2022-42280HigJan 13, 2023
    risk 0.46cvss 7.1epss 0.00

    NVIDIA BMC contains a vulnerability in SPX REST auth handler, where an un-authorized attacker can exploit a path traversal, which may lead to authentication bypass.

  • CVE-2022-44942HigDec 7, 2022
    risk 0.46cvss 8.1epss 0.01

    Casdoor before v1.126.1 was discovered to contain an arbitrary file deletion vulnerability via the uploadFile function.

  • CVE-2022-44748HigNov 24, 2022
    risk 0.46cvss 7.1epss 0.01

    A directory traversal vulnerability in the ZIP archive extraction routines of KNIME Server since 4.3.0 can result in arbitrary files being overwritten on the server's file system. This vulnerability is also known as 'Zip-Slip'. An attacker can create a KNIME workflow that,…

  • CVE-2022-45381HigNov 15, 2022
    risk 0.46cvss 8.1epss 0.01

    Jenkins Pipeline Utility Steps Plugin 2.13.1 and earlier does not restrict the set of enabled prefix interpolators and bundles versions of Apache Commons Configuration library that enable the 'file:' prefix interpolator by default, allowing attackers able to configure Pipelines…

  • CVE-2022-38120MedNov 10, 2022
    risk 0.46cvss 6.5epss 0.06

    UPSMON PRO’s has a path traversal vulnerability. A remote attacker with general user privilege can exploit this vulnerability to bypass authentication and access arbitrary system files.

  • CVE-2022-41670HigNov 4, 2022
    risk 0.46cvss 7.0epss 0.00

    A CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability exists in the SGIUtility component that allows adversaries with local user privileges to load malicious DLL which could result in execution of malicious code. Affected…

  • CVE-2022-41667HigNov 4, 2022
    risk 0.46cvss 7.0epss 0.00

    A CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability exists that allows adversaries with local user privileges to load a malicious DLL which could lead to execution of malicious code. Affected Products: EcoStruxure Operator…

  • CVE-2021-45448HigNov 2, 2022
    risk 0.46cvss 7.1epss 0.01

    Pentaho Business Analytics Server versions before 9.2.0.2 and 8.3.0.25 using the Pentaho Analyzer plugin exposes a service endpoint for templates which allows a user-supplied path to access resources that are out of bounds.  The software uses external input to construct a…

  • CVE-2022-20822HigOct 26, 2022
    risk 0.46cvss 7.1epss 0.01

    A vulnerability in the web-based management interface of Cisco Identity Services Engine (ISE) could allow an authenticated, remote attacker to read and delete files on an affected device. This vulnerability is due to insufficient validation of user-supplied input. An attacker…

  • CVE-2022-33937HigOct 12, 2022
    risk 0.46cvss 7.1epss 0.00

    Dell GeoDrive, Versions 1.0 - 2.2, contain a Path Traversal Vulnerability in the reporting function. A local, low privileged attacker could potentially exploit this vulnerability, to gain unauthorized delete access to the files stored on the server filesystem, with the…

  • CVE-2022-34430HigOct 11, 2022
    risk 0.46cvss 7.1epss 0.01

    Dell Hybrid Client below 1.8 version contains a Zip Bomb Vulnerability in UI. A guest privilege attacker could potentially exploit this vulnerability, leading to system files modification.

  • CVE-2022-31194HigAug 1, 2022
    risk 0.46cvss 8.2epss 0.01

    DSpace open source software is a repository application which provides durable access to digital resources. dspace-jspui is a UI component for DSpace. The JSPUI resumable upload implementations in SubmissionController and FileUploadRequest are vulnerable to multiple path…