VYPR

CWE-22

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')

BaseStableLikelihood: High

Description

The product uses external input to construct a pathname that is intended to identify a file or directory that is located underneath a restricted parent directory, but the product does not properly neutralize special elements within the pathname that can cause the pathname to resolve to a location that is outside of the restricted directory.

Hierarchy (View 1000)

Parents

Children

Related attack patterns (CAPEC)

CAPEC-126 · CAPEC-64 · CAPEC-76 · CAPEC-78 · CAPEC-79

CVEs mapped to this weakness (10,411)

page 23 of 521
  • CVE-2022-47027CriApr 14, 2023
    risk 0.64cvss 9.8epss 0.01

    Timmystudios Fast Typing Keyboard v1.275.1.162 allows unauthorized apps to overwrite arbitrary files in its internal storage via a dictionary traversal vulnerability and achieve arbitrary code execution.

  • CVE-2023-1478CriApr 10, 2023
    risk 0.64cvss 9.8epss 0.01

    The Hummingbird WordPress plugin before 3.4.2 does not validate the generated file path for page cache files before writing them, leading to a path traversal vulnerability in the page cache module.

  • CVE-2023-27603CriApr 10, 2023
    risk 0.64cvss 9.8epss 0.02

    In Apache Linkis <=1.3.1, due to the Manager module engineConn material upload does not check the zip path, This is a Zip Slip issue, which will lead to a potential RCE vulnerability. We recommend users upgrade the version of Linkis to version 1.3.2.

  • CVE-2023-29478CriApr 7, 2023
    risk 0.64cvss 9.8epss 0.02

    BiblioCraft before 2.4.6 does not sanitize path-traversal characters in filenames, allowing restricted write access to almost anywhere on the filesystem. This includes the Minecraft mods folder, which results in code execution.

  • CVE-2020-19279CriApr 4, 2023
    risk 0.64cvss 9.8epss 0.01

    Directory Traversal vulnerability found in B3log Wide allows a an attacker to escalate privileges via symbolic links.

  • CVE-2021-33353CriMar 8, 2023
    risk 0.64cvss 9.8epss 0.02

    Directory Traversal vulnerability in Wyomind Help Desk Magento 2 extension v.1.3.6 and before fixed in v.1.3.7 allows attacker to execute arbitrary code via the file attachment directory setting.

  • CVE-2023-22336CriMar 6, 2023
    risk 0.64cvss 9.8epss 0.01

    Path traversal vulnerability in SS1 Ver.13.0.0.40 and earlier and Rakuraku PC Cloud Agent Ver.2.1.8 and earlier allows a remote attacker to upload a specially crafted file to an arbitrary directory. As a result of exploiting this vulnerability with CVE-2023-22335 and…

  • CVE-2021-36471CriFeb 7, 2023
    risk 0.64cvss 9.8epss 0.02

    Directory Traversal vulnerability in AdminLTE 3.1.0 allows remote attackers to gain escalated privilege and view sensitive information via /admin/index2.html, /admin/index3.html URIs. Note: AdminLTE developers dispute that this a weakness with AdminLTE and is instead a…

  • CVE-2022-48253CriJan 11, 2023
    risk 0.64cvss 9.8epss 0.03

    nhttpd in Nostromo before 2.1 is vulnerable to a path traversal that may allow an attacker to execute arbitrary commands on the remote server. The vulnerability occurs when the homedirs option is used.

  • CVE-2022-4063CriDec 19, 2022
    risk 0.64cvss 9.8epss 0.10

    The InPost Gallery WordPress plugin before 2.1.4.1 insecurely uses PHP's extract() function when rendering HTML views, allowing attackers to force the inclusion of malicious files & URLs, which may enable them to run code on servers.

  • CVE-2022-46255CriDec 14, 2022
    risk 0.64cvss 9.8epss 0.02

    An improper limitation of a pathname to a restricted directory vulnerability was identified in GitHub Enterprise Server that enabled remote code execution. A check was added within Pages to ensure the working directory is clean before unpacking new content to prevent an…

  • CVE-2022-38165CriNov 17, 2022
    risk 0.64cvss 9.8epss 0.01

    Arbitrary file write in F-Secure Policy Manager through 2022-08-10 allows unauthenticated users to write the file with the contents in arbitrary locations on the F-Secure Policy Manager Server.

  • CVE-2022-44006CriNov 16, 2022
    risk 0.64cvss 9.8epss 0.02

    An issue was discovered in BACKCLICK Professional 5.9.63. Due to improper validation or sanitization of upload filenames, an externally reachable, unauthenticated update function permits writing files outside the intended target location. Achieving remote code execution is…

  • CVE-2022-34822CriNov 8, 2022
    risk 0.64cvss 9.8epss 0.01

    Path traversal vulnerability in CLUSTERPRO X 5.0 for Windows and earlier, EXPRESSCLUSTER X 5.0 for Windows and earlier, CLUSTERPRO X 5.0 SingleServerSafe for Windows and earlier, EXPRESSCLUSTER X 5.0 SingleServerSafe for Windows and earlier allows a remote unauthenticated…

  • CVE-2022-22128CriOct 17, 2022
    risk 0.64cvss 9.8epss 0.02

    Tableau discovered a path traversal vulnerability affecting Tableau Server Administration Agent’s internal file transfer service that could allow remote code execution.Tableau only supports product versions for 24 months after release. Older versions have reached their End of…

  • CVE-2022-20775HigKEVSep 30, 2022
    risk 0.64cvss 7.8epss 0.12

    A vulnerability in the CLI of Cisco SD-WAN Software could allow an authenticated, local attacker to gain elevated privileges. This vulnerability is due to improper access controls on commands within the application CLI. An attacker could exploit this vulnerability by running…

  • CVE-2022-28814CriSep 28, 2022
    risk 0.64cvss 9.8epss 0.01

    Carlo Gavazzi UWP3.0 in multiple versions and CPY Car Park Server in Version 2.8.3 was discovered to be vulnerable to a relative path traversal vulnerability which enables remote attackers to read arbitrary files and gain full control of the device.

  • CVE-2022-39033CriSep 28, 2022
    risk 0.64cvss 9.8epss 0.02

    Smart eVision’s file acquisition function has a path traversal vulnerability due to insufficient filtering for special characters in the URL parameter. An unauthenticated remote attacker can exploit this vulnerability to bypass authentication, access restricted paths to…

  • CVE-2022-25371CriSep 2, 2022
    risk 0.64cvss 9.8epss 0.05

    Apache OFBiz uses the Birt project plugin (https://eclipse.github.io/birt-website/) to create data visualizations and reports. By leveraging a bug in Birt (https://bugs.eclipse.org/bugs/show_bug.cgi?id=538142) it is possible to perform a remote code execution (RCE) attack in…

  • CVE-2020-21642CriAug 15, 2022
    risk 0.64cvss 9.8epss 0.07

    Directory Traversal vulnerability ZDBQAREFSUBDIR parameter in /zropusermgmt API in Zoho ManageEngine Analytics Plus before 4350 allows remote attackers to run arbitrary code.