VYPR

CWE-22

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')

BaseStableLikelihood: High

Description

The product uses external input to construct a pathname that is intended to identify a file or directory that is located underneath a restricted parent directory, but the product does not properly neutralize special elements within the pathname that can cause the pathname to resolve to a location that is outside of the restricted directory.

Hierarchy (View 1000)

Parents

Children

Related attack patterns (CAPEC)

CAPEC-126 · CAPEC-64 · CAPEC-76 · CAPEC-78 · CAPEC-79

CVEs mapped to this weakness (10,395)

page 22 of 520
  • CVE-2023-34880CriJun 15, 2023
    risk 0.64cvss 9.8epss 0.01

    cmseasy v7.7.7.7 20230520 was discovered to contain a path traversal vulnerability via the add_action method at lib/admin/language_admin.php. This vulnerability allows attackers to execute arbitrary code and perform a local file inclusion.

  • CVE-2023-34865CriJun 14, 2023
    risk 0.64cvss 9.8epss 0.01

    Directory traversal vulnerability in ujcms 6.0.2 allows attackers to move files via the rename feature.

  • CVE-2023-34409CriJun 6, 2023
    risk 0.64cvss 9.8epss 0.01

    In Percona Monitoring and Management (PMM) server 2.x before 2.37.1, the authenticate function in auth_server.go does not properly formalize and sanitize URL paths to reject path traversal attempts. This allows an unauthenticated remote user, when a crafted POST request is made…

  • CVE-2023-29736CriJun 1, 2023
    risk 0.64cvss 9.8epss 0.01

    Keyboard Themes 1.275.1.164 for Android contains a dictionary traversal vulnerability that allows unauthorized apps to overwrite arbitrary files in its internal storage and achieve arbitrary code execution.

  • CVE-2022-47526CriMay 31, 2023
    risk 0.64cvss 9.8epss 0.01

    Fox-IT DataDiode (aka Fox DataDiode) 3.4.3 suffers from a path traversal vulnerability with resultant arbitrary writing of files. A remote attacker could leverage this vulnerability to achieve arbitrary code execution in the context of the downstream node user. Exploitation of…

  • CVE-2023-28413CriMay 23, 2023
    risk 0.64cvss 9.8epss 0.02

    Directory traversal vulnerability in Snow Monkey Forms versions v5.0.6 and earlier allows a remote unauthenticated attacker to obtain sensitive information, alter the website, or cause a denial-of-service (DoS) condition.

  • CVE-2023-28408CriMay 23, 2023
    risk 0.64cvss 9.8epss 0.02

    Directory traversal vulnerability in MW WP Form versions v4.4.2 and earlier allows a remote unauthenticated attacker to alter the website or cause a denial-of-service (DoS) condition, and obtain sensitive information depending on settings.

  • CVE-2023-27507CriMay 23, 2023
    risk 0.64cvss 9.8epss 0.01

    MicroEngine Mailform version 1.1.0 to 1.1.8 contains a path traversal vulnerability. If the product's file upload function and server save option are enabled, a remote attacker may save an arbitrary file on the server and execute it.

  • CVE-2020-20012CriMay 23, 2023
    risk 0.64cvss 9.8epss 0.01

    WebPlus Pro v1.4.7.8.4-01 is vulnerable to Incorrect Access Control.

  • CVE-2023-30268CriMay 4, 2023
    risk 0.64cvss 9.8epss 0.01

    CLTPHP <=6.0 is vulnerable to Improper Input Validation.

  • CVE-2022-47757CriMay 4, 2023
    risk 0.64cvss 9.8epss 0.01

    In imo.im 2022.11.1051, a path traversal vulnerability delivered via an unsanitized deeplink can force the application to write a file into the application's data directory. This may allow an attacker to save a shared library under a special directory which the app uses to…

  • CVE-2023-27105CriApr 25, 2023
    risk 0.64cvss 9.8epss 0.01

    A vulnerability in the Wi-Fi file transfer module of Shanling M5S Portable Music Player with Shanling MTouch OS v4.3 and Shanling M2X Portable Music Player with Shanling MTouch OS v3.3 allows attackers to arbitrarily read, delete, or modify any critical system files via…

  • CVE-2023-27648CriApr 14, 2023
    risk 0.64cvss 9.8epss 0.03

    Directory Traversal vulnerability found in T-ME Studios Change Color of Keypad v.1.275.1.277 allows a remote attacker to execute arbitrary code via the dex file in the internal storage.

  • CVE-2022-47027CriApr 14, 2023
    risk 0.64cvss 9.8epss 0.01

    Timmystudios Fast Typing Keyboard v1.275.1.162 allows unauthorized apps to overwrite arbitrary files in its internal storage via a dictionary traversal vulnerability and achieve arbitrary code execution.

  • CVE-2023-1478CriApr 10, 2023
    risk 0.64cvss 9.8epss 0.01

    The Hummingbird WordPress plugin before 3.4.2 does not validate the generated file path for page cache files before writing them, leading to a path traversal vulnerability in the page cache module.

  • CVE-2023-27603CriApr 10, 2023
    risk 0.64cvss 9.8epss 0.02

    In Apache Linkis <=1.3.1, due to the Manager module engineConn material upload does not check the zip path, This is a Zip Slip issue, which will lead to a potential RCE vulnerability. We recommend users upgrade the version of Linkis to version 1.3.2.

  • CVE-2023-29478CriApr 7, 2023
    risk 0.64cvss 9.8epss 0.02

    BiblioCraft before 2.4.6 does not sanitize path-traversal characters in filenames, allowing restricted write access to almost anywhere on the filesystem. This includes the Minecraft mods folder, which results in code execution.

  • CVE-2020-19279CriApr 4, 2023
    risk 0.64cvss 9.8epss 0.01

    Directory Traversal vulnerability found in B3log Wide allows a an attacker to escalate privileges via symbolic links.

  • CVE-2021-33353CriMar 8, 2023
    risk 0.64cvss 9.8epss 0.02

    Directory Traversal vulnerability in Wyomind Help Desk Magento 2 extension v.1.3.6 and before fixed in v.1.3.7 allows attacker to execute arbitrary code via the file attachment directory setting.

  • CVE-2023-22336CriMar 6, 2023
    risk 0.64cvss 9.8epss 0.01

    Path traversal vulnerability in SS1 Ver.13.0.0.40 and earlier and Rakuraku PC Cloud Agent Ver.2.1.8 and earlier allows a remote attacker to upload a specially crafted file to an arbitrary directory. As a result of exploiting this vulnerability with CVE-2023-22335 and…