VYPR

CWE-22

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')

BaseStableLikelihood: High

Description

The product uses external input to construct a pathname that is intended to identify a file or directory that is located underneath a restricted parent directory, but the product does not properly neutralize special elements within the pathname that can cause the pathname to resolve to a location that is outside of the restricted directory.

Hierarchy (View 1000)

Parents

Children

Related attack patterns (CAPEC)

CAPEC-126 · CAPEC-64 · CAPEC-76 · CAPEC-78 · CAPEC-79

CVEs mapped to this weakness (10,395)

page 215 of 520
  • CVE-2020-5811MedDec 30, 2020
    risk 0.46cvss 6.5epss 0.09

    An authenticated path traversal vulnerability exists during package installation in Umbraco CMS <= 8.9.1 or current, which could result in arbitrary files being written outside of the site home and expected paths when installing an Umbraco package.

  • CVE-2020-26405HigNov 17, 2020
    risk 0.46cvss 7.1epss 0.01

    Path traversal vulnerability in package upload functionality in GitLab CE/EE starting from 12.8 allows an attacker to save packages in arbitrary locations. Affected versions are >=12.8, <13.3.9,>=13.4, <13.4.5,>=13.5, <13.5.2.

  • CVE-2020-15229HigOct 14, 2020
    risk 0.46cvss 8.2epss 0.02

    Singularity (an open source container platform) from version 3.1.1 through 3.6.3 has a vulnerability. Due to insecure handling of path traversal and the lack of path sanitization within `unsquashfs`, it is possible to overwrite/create any files on the host filesystem during the…

  • CVE-2020-11700MedSep 17, 2020
    risk 0.46cvss 6.5epss 0.07

    An issue was discovered in Titan SpamTitan 7.07. Improper sanitization of the parameter fname, used on the page certs-x.php, would allow an attacker to retrieve the contents of arbitrary files. The user has to be authenticated before interacting with this page.

  • CVE-2020-7376HigAug 24, 2020
    risk 0.46cvss 7.1epss 0.01

    The Metasploit Framework module "post/osx/gather/enum_osx module" is affected by a relative path traversal vulnerability in the get_keychains method which can be exploited to write arbitrary files to arbitrary locations on the host filesystem when the module is run on a…

  • CVE-2020-8227MedAug 21, 2020
    risk 0.46cvss 6.8epss 0.26

    Missing sanitization of a server response in Nextcloud Desktop Client 2.6.4 for Linux allowed a malicious Nextcloud Server to store files outside of the dedicated sync directory.

  • CVE-2020-5366HigJul 9, 2020
    risk 0.46cvss 7.1epss 0.02

    Dell EMC iDRAC9 versions prior to 4.20.20.20 contain a Path Traversal Vulnerability. A remote authenticated malicious user with low privileges could potentially exploit this vulnerability by manipulating input parameters to gain unauthorized read access to the arbitrary files.

  • CVE-2020-12010HigMay 8, 2020
    risk 0.46cvss 7.1epss 0.01

    Advantech WebAccess Node, Version 8.4.4 and prior, Version 9.0.0. Multiple relative path traversal vulnerabilities exist that may allow an authenticated user to use a specially crafted file to delete files outside the application’s control.

  • CVE-2013-4861MedJan 28, 2020
    risk 0.46cvss 6.5epss 0.07

    Directory traversal vulnerability in cgi-bin/cmh/get_file.sh in MiCasaVerde VeraLite with firmware 1.5.408 allows remote authenticated users to read arbirary files via a .. (dot dot) in the filename parameter.

  • CVE-2013-1597MedJan 24, 2020
    risk 0.46cvss 6.5epss 0.14

    A Directory Traversal vulnerability exists in Vivotek PT7135 IP Cameras 0300a and 0400a via a specially crafted GET request, which could let a malicious user obtain user credentials.

  • CVE-2020-5513MedJan 6, 2020
    risk 0.46cvss 6.8epss 0.26

    Gila CMS 1.11.8 allows /cm/delete?t=../ Directory Traversal.

  • CVE-2020-5512MedJan 6, 2020
    risk 0.46cvss 6.8epss 0.19

    Gila CMS 1.11.8 allows /admin/media?path=../ Path Traversal.

  • CVE-2015-9538MedNov 26, 2019
    risk 0.46cvss 6.5epss 0.10

    The NextGEN Gallery plugin before 2.1.15 for WordPress allows ../ Directory Traversal in path selection.

  • CVE-2019-17199HigOct 5, 2019
    risk 0.46cvss 7.5epss 0.10

    www/getfile.php in WPO WebPageTest 19.04 on Windows allows Directory Traversal (for reading arbitrary files) because of an unanchored regular expression, as demonstrated by the a.jpg\.. substring.

  • CVE-2019-10009MedJun 3, 2019
    risk 0.46cvss 6.5epss 0.11

    A Directory Traversal issue was discovered in the Web GUI in Titan FTP Server 2019 Build 3505. When an authenticated user attempts to preview an uploaded file (through PreviewHandler.ashx) by using a \..\..\ technique, arbitrary files can be loaded in the server response outside…

  • CVE-2019-9723HigMay 30, 2019
    risk 0.46cvss 7.1epss 0.01

    LogicalDOC Community Edition 8.x before 8.2.1 has a path traversal vulnerability that allows reading arbitrary files and the creation of directories, in the class PluginRegistry.

  • CVE-2019-1836HigMay 3, 2019
    risk 0.46cvss 7.1epss 0.00

    A vulnerability in the system shell for Cisco Nexus 9000 Series Fabric Switches in Application Centric Infrastructure (ACI) mode could allow an authenticated, local attacker to use symbolic links to overwrite system files. These system files may be sensitive and should not be…

  • CVE-2019-7213MedApr 24, 2019
    risk 0.46cvss 6.5epss 0.42

    SmarterTools SmarterMail 16.x before build 6985 allows directory traversal. An authenticated user could delete arbitrary files or could create files in new folders in arbitrary locations on the mail server. This could lead to command execution on the server for instance by…

  • CVE-2019-6273MedMar 21, 2019
    risk 0.46cvss 6.5epss 0.12

    download_file in GL.iNet GL-AR300M-Lite devices with firmware 2.27 allows remote attackers to download arbitrary files.

  • CVE-2019-3474MedFeb 20, 2019
    risk 0.46cvss 6.5epss 0.09

    A path traversal vulnerability in the web application component of Micro Focus Filr 3.x allows a remote attacker authenticated as a low privilege user to download arbitrary files from the Filr server. This vulnerability affects all versions of Filr 3.x prior to Security Update 6.