VYPR

CWE-22

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')

BaseStableLikelihood: High

Description

The product uses external input to construct a pathname that is intended to identify a file or directory that is located underneath a restricted parent directory, but the product does not properly neutralize special elements within the pathname that can cause the pathname to resolve to a location that is outside of the restricted directory.

Hierarchy (View 1000)

Parents

Children

Related attack patterns (CAPEC)

CAPEC-126 · CAPEC-64 · CAPEC-76 · CAPEC-78 · CAPEC-79

CVEs mapped to this weakness (10,481)

page 221 of 525
  • CVE-2020-5366HigJul 9, 2020
    risk 0.46cvss 7.1epss 0.02

    Dell EMC iDRAC9 versions prior to 4.20.20.20 contain a Path Traversal Vulnerability. A remote authenticated malicious user with low privileges could potentially exploit this vulnerability by manipulating input parameters to gain unauthorized read access to the arbitrary files.

  • CVE-2020-12010HigMay 8, 2020
    risk 0.46cvss 7.1epss 0.01

    Advantech WebAccess Node, Version 8.4.4 and prior, Version 9.0.0. Multiple relative path traversal vulnerabilities exist that may allow an authenticated user to use a specially crafted file to delete files outside the application’s control.

  • CVE-2013-4861MedJan 28, 2020
    risk 0.46cvss 6.5epss 0.07

    Directory traversal vulnerability in cgi-bin/cmh/get_file.sh in MiCasaVerde VeraLite with firmware 1.5.408 allows remote authenticated users to read arbirary files via a .. (dot dot) in the filename parameter.

  • CVE-2013-1597MedJan 24, 2020
    risk 0.46cvss 6.5epss 0.14

    A Directory Traversal vulnerability exists in Vivotek PT7135 IP Cameras 0300a and 0400a via a specially crafted GET request, which could let a malicious user obtain user credentials.

  • CVE-2020-5513MedJan 6, 2020
    risk 0.46cvss 6.8epss 0.26

    Gila CMS 1.11.8 allows /cm/delete?t=../ Directory Traversal.

  • CVE-2020-5512MedJan 6, 2020
    risk 0.46cvss 6.8epss 0.19

    Gila CMS 1.11.8 allows /admin/media?path=../ Path Traversal.

  • CVE-2015-9538MedNov 26, 2019
    risk 0.46cvss 6.5epss 0.10

    The NextGEN Gallery plugin before 2.1.15 for WordPress allows ../ Directory Traversal in path selection.

  • CVE-2019-17199HigOct 5, 2019
    risk 0.46cvss 7.5epss 0.10

    www/getfile.php in WPO WebPageTest 19.04 on Windows allows Directory Traversal (for reading arbitrary files) because of an unanchored regular expression, as demonstrated by the a.jpg\.. substring.

  • CVE-2019-10009MedJun 3, 2019
    risk 0.46cvss 6.5epss 0.11

    A Directory Traversal issue was discovered in the Web GUI in Titan FTP Server 2019 Build 3505. When an authenticated user attempts to preview an uploaded file (through PreviewHandler.ashx) by using a \..\..\ technique, arbitrary files can be loaded in the server response outside…

  • CVE-2019-9723HigMay 30, 2019
    risk 0.46cvss 7.1epss 0.01

    LogicalDOC Community Edition 8.x before 8.2.1 has a path traversal vulnerability that allows reading arbitrary files and the creation of directories, in the class PluginRegistry.

  • CVE-2019-1836HigMay 3, 2019
    risk 0.46cvss 7.1epss 0.00

    A vulnerability in the system shell for Cisco Nexus 9000 Series Fabric Switches in Application Centric Infrastructure (ACI) mode could allow an authenticated, local attacker to use symbolic links to overwrite system files. These system files may be sensitive and should not be…

  • CVE-2019-7213MedApr 24, 2019
    risk 0.46cvss 6.5epss 0.42

    SmarterTools SmarterMail 16.x before build 6985 allows directory traversal. An authenticated user could delete arbitrary files or could create files in new folders in arbitrary locations on the mail server. This could lead to command execution on the server for instance by…

  • CVE-2019-6273MedMar 21, 2019
    risk 0.46cvss 6.5epss 0.12

    download_file in GL.iNet GL-AR300M-Lite devices with firmware 2.27 allows remote attackers to download arbitrary files.

  • CVE-2019-3474MedFeb 20, 2019
    risk 0.46cvss 6.5epss 0.09

    A path traversal vulnerability in the web application component of Micro Focus Filr 3.x allows a remote attacker authenticated as a low privilege user to download arbitrary files from the Filr server. This vulnerability affects all versions of Filr 3.x prior to Security Update 6.

  • CVE-2018-15490HigJan 2, 2019
    risk 0.46cvss 7.1epss 0.01

    An issue was discovered in ExpressVPN on Windows. The Xvpnd.exe process (which runs as a service with SYSTEM privileges) listens on TCP port 2015, which is used as an RPC interface for communication with the client side of the ExpressVPN application. A JSON-RPC protocol over…

  • CVE-2018-15705MedOct 31, 2018
    risk 0.46cvss 6.5epss 0.12

    WADashboard API in Advantech WebAccess 8.3.1 and 8.3.2 allows remote authenticated attackers to write or overwrite any file on the filesystem due to a directory traversal vulnerability in the writeFile API. An attacker can use this vulnerability to remotely execute arbitrary…

  • CVE-2018-10501HigSep 24, 2018
    risk 0.46cvss 7.0epss 0.00

    This vulnerability allows local attackers to escalate privileges on vulnerable installations of Samsung Notes Fixed in version 2.0.02.31. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability. The…

  • CVE-2018-1000647HigAug 20, 2018
    risk 0.46cvss 7.1epss 0.01

    LibreHealthIO lh-ehr version REL-2.0.0 contains a Authenticated Unrestricted File Deletion vulnerability in Import template that can result in Denial of service. This attack appear to be exploitable via User controlled parameter.

  • CVE-2018-1000194HigJun 5, 2018
    risk 0.46cvss 8.1epss 0.03

    A path traversal vulnerability exists in Jenkins 2.120 and older, LTS 2.107.2 and older in FilePath.java, SoloFilePathFilter.java that allows malicious agents to read and write arbitrary files on the Jenkins master, bypassing the agent-to-master security subsystem protection.

  • CVE-2018-9038MedApr 10, 2018
    risk 0.46cvss 6.5epss 0.09

    Monstra CMS 3.0.4 allows remote attackers to delete files via an admin/index.php?id=filesmanager&delete_dir=./&path=uploads/ request.