VYPR

CWE-22

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')

BaseStableLikelihood: High

Description

The product uses external input to construct a pathname that is intended to identify a file or directory that is located underneath a restricted parent directory, but the product does not properly neutralize special elements within the pathname that can cause the pathname to resolve to a location that is outside of the restricted directory.

Hierarchy (View 1000)

Parents

Children

Related attack patterns (CAPEC)

CAPEC-126 · CAPEC-64 · CAPEC-76 · CAPEC-78 · CAPEC-79

CVEs mapped to this weakness (10,481)

page 229 of 525
  • CVE-2022-20505MedDec 16, 2022
    risk 0.44cvss 6.7epss 0.00

    In openFile of CallLogProvider.java, there is a possible permission bypass due to a path traversal error. This could lead to local escalation of privilege with User execution privileges needed. User interaction is not needed for exploitationProduct: AndroidVersions:…

  • CVE-2022-45833MedDec 6, 2022
    risk 0.44cvss 6.8epss 0.01

    Auth. Path Traversal vulnerability in Easy WP SMTP plugin <= 1.5.1 on WordPress.

  • CVE-2022-36400MedNov 11, 2022
    risk 0.44cvss 6.7epss 0.00

    Path traversal in the installer software for some Intel(r) NUC Kit Wireless Adapter drivers for Windows 10 before version 22.40 may allow an authenticated user to potentially enable escalation of privilege via local access.

  • CVE-2022-31473MedAug 4, 2022
    risk 0.44cvss 6.8epss 0.02

    In BIG-IP Versions 16.1.x before 16.1.1 and 15.1.x before 15.1.4, when running in Appliance mode, an authenticated attacker may be able to bypass Appliance mode restrictions due to a directory traversal vulnerability in an undisclosed page within iApps. A successful exploit can…

  • CVE-2022-27620MedAug 3, 2022
    risk 0.44cvss 6.8epss 0.01

    Improper limitation of a pathname to a restricted directory ('Path Traversal') vulnerability in webapi component in Synology SSO Server before 2.2.3-0331 allows remote authenticated users to read arbitrary files via unspecified vectors.

  • CVE-2022-27618MedAug 3, 2022
    risk 0.44cvss 6.8epss 0.01

    Improper limitation of a pathname to a restricted directory ('Path Traversal') vulnerability in webapi component in Synology Storage Analyzer before 2.1.0-0390 allows remote authenticated users to delete arbitrary files via unspecified vectors.

  • CVE-2022-1264MedJul 20, 2022
    risk 0.44cvss 6.8epss 0.01

    The affected product may allow an attacker with access to the Ignition web configuration to run arbitrary code.

  • CVE-2022-31159HigJul 15, 2022
    risk 0.44cvss 7.9epss 0.02

    The AWS SDK for Java enables Java developers to work with Amazon Web Services. A partial-path traversal issue exists within the `downloadDirectory` method in the AWS S3 TransferManager component of the AWS SDK for Java v1 prior to version 1.12.261. Applications using the SDK…

  • CVE-2022-24248MedApr 12, 2022
    risk 0.44cvss 6.5epss 0.21

    RiteCMS version 3.1.0 and below suffers from an arbitrary file deletion via path traversal vulnerability in Admin Panel. Exploiting the vulnerability allows an authenticated attacker to delete any file in the web root (along with any other file on the server that the PHP process…

  • CVE-2022-24731MedMar 23, 2022
    risk 0.44cvss 6.8epss 0.01

    Argo CD is a declarative, GitOps continuous delivery tool for Kubernetes. Argo CD starting with version 1.5.0 but before versions 2.1.11, 2.2.6, and 2.3.0 is vulnerable to a path traversal vulnerability, allowing a malicious user with read/write access to leak sensitive files…

  • CVE-2021-20876MedDec 24, 2021
    risk 0.44cvss 6.8epss 0.01

    Path traversal vulnerability in GroupSession Free edition ver5.1.1 and earlier, GroupSession byCloud ver5.1.1 and earlier, and GroupSession ZION ver5.1.1 and earlier allows an attacker with an administrative privilege to obtain sensitive information stored in the hierarchy above…

  • CVE-2021-35230MedOct 22, 2021
    risk 0.44cvss 6.7epss 0.00

    As a result of an unquoted service path vulnerability present in the Kiwi CatTools Installation Wizard, a local attacker could gain escalated privileges by inserting an executable into the path of the affected service or uninstall entry.

  • CVE-2021-42771HigOct 20, 2021
    risk 0.44cvss 7.8epss 0.01

    Babel.Locale in Babel before 2.9.1 allows attackers to load arbitrary locale .dat files (containing serialized Python objects) via directory traversal, leading to code execution.

  • CVE-2021-41103HigOct 4, 2021
    risk 0.44cvss 7.8epss 0.01

    containerd is an open source container runtime with an emphasis on simplicity, robustness and portability. A bug was found in containerd where container root directories and some plugins had insufficiently restricted permissions, allowing otherwise unprivileged Linux users to…

  • CVE-2021-21569MedSep 28, 2021
    risk 0.44cvss 6.8epss 0.01

    Dell NetWorker, versions 18.x and 19.x contain a Path traversal vulnerability. A NetWorker server user with remote access to NetWorker clients may potentially exploit this vulnerability and gain access to unauthorized information.

  • CVE-2021-28149MedMay 6, 2021
    risk 0.44cvss 6.5epss 0.16

    Hongdian H8922 3.0.5 devices allow Directory Traversal. The /log_download.cgi log export handler does not validate user input and allows a remote attacker with minimal privileges to download any file from the device by substituting ../ (e.g., ../../etc/passwd) This can be…

  • CVE-2021-29246MedMay 5, 2021
    risk 0.44cvss 6.7epss 0.02

    BTCPay Server through 1.0.7.0 suffers from directory traversal, which allows an attacker with admin privileges to achieve code execution. The attacker must craft a malicious plugin file with special characters to upload the file outside of the restricted directory.

  • CVE-2020-7858MedApr 22, 2021
    risk 0.44cvss 6.8epss 0.01

    There is a directory traversing vulnerability in the download page url of AquaNPlayer 2.0.0.92. The IP of the download page url is localhost and an attacker can traverse directories using "dot dot" sequences(../../) to view host file on the system. This vulnerability can cause…

  • CVE-2020-28337HigFeb 15, 2021
    risk 0.44cvss 7.2epss 0.17

    A directory traversal issue in the Utils/Unzip module in Microweber through 1.1.20 allows an authenticated attacker to gain remote code execution via the backup restore feature. To exploit the vulnerability, an attacker must have the credentials of an administrative user, upload…

  • CVE-2020-14366MedNov 9, 2020
    risk 0.44cvss 6.8epss 0.01

    A vulnerability was found in keycloak, where path traversal using URL-encoded path segments in the request is possible because the resources endpoint applies a transformation of the url path to the file path. Only few specific folder hierarchies can be exposed by this flaw