VYPR

CWE-22

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')

BaseStableLikelihood: High

Description

The product uses external input to construct a pathname that is intended to identify a file or directory that is located underneath a restricted parent directory, but the product does not properly neutralize special elements within the pathname that can cause the pathname to resolve to a location that is outside of the restricted directory.

Hierarchy (View 1000)

Parents

Children

Related attack patterns (CAPEC)

CAPEC-126 · CAPEC-64 · CAPEC-76 · CAPEC-78 · CAPEC-79

CVEs mapped to this weakness (10,395)

page 24 of 520
  • CVE-2021-43741CriApr 13, 2022
    risk 0.64cvss 9.8epss 0.05

    CMSimple 5.4 is vulnerable to Directory Traversal. The vulnerability exists when a user changes the file name to malicious file on config.php leading to remote code execution.

  • CVE-2021-45887CriMar 13, 2022
    risk 0.64cvss 9.8epss 0.03

    An issue was discovered in PONTON X/P Messenger before 3.11.2. Due to path traversal in private/SchemaSetUpload.do for uploaded ZIP files, an executable script can be uploaded by web application administrators, giving the attacker remote code execution on the underlying server…

  • CVE-2021-42854CriMar 10, 2022
    risk 0.64cvss 9.8epss 0.02

    It was discovered that the SteelCentral AppInternals Dynamic Sampling Agent's (DSA) PluginServlet has directory traversal vulnerabilities at the "/api/appInternals/1.0/plugin/pmx" API. The affected endpoint does not have any input validation of the user's input that allows a…

  • CVE-2021-32008CriMar 4, 2022
    risk 0.64cvss 9.9epss 0.01

    This issue affects: Secomea GateManager Version 9.6.621421014 and all prior versions. Improper Limitation of a Pathname to restricted directory, allows logged in GateManager admin to delete system Files or Directories.

  • CVE-2022-24312CriFeb 9, 2022
    risk 0.64cvss 9.8epss 0.03

    A CWE-22: Improper Limitation of a Pathname to a Restricted Directory vulnerability exists that could cause modification of an existing file by adding at end of file or create a new file in the context of the Data Server potentially leading to remote code execution when an…

  • CVE-2022-24311CriFeb 9, 2022
    risk 0.64cvss 9.8epss 0.04

    A CWE-22: Improper Limitation of a Pathname to a Restricted Directory vulnerability exists that could cause modification of an existing file by inserting at beginning of file or create a new file in the context of the Data Server potentially leading to remote code execution when…

  • CVE-2022-0320CriFeb 1, 2022
    risk 0.64cvss 9.8epss 0.02

    The Essential Addons for Elementor WordPress plugin before 5.0.5 does not validate and sanitise some template data before it them in include statements, which could allow unauthenticated attackers to perform Local File Inclusion attack and read arbitrary files on the server,…

  • CVE-2020-17383CriJan 24, 2022
    risk 0.64cvss 9.8epss 0.04

    A directory traversal vulnerability on Telos Z/IP One devices through 4.0.0r grants an unauthenticated individual root level access to the device's file system. This can be used to identify configuration settings, password hashes for built-in accounts, and the cleartext password…

  • CVE-2021-37128CriJan 3, 2022
    risk 0.64cvss 9.8epss 0.01

    HwPCAssistant has a Path Traversal vulnerability .Successful exploitation of this vulnerability may write any file.

  • CVE-2021-44548CriDec 23, 2021
    risk 0.64cvss 9.8epss 0.05

    An Improper Input Validation vulnerability in DataImportHandler of Apache Solr allows an attacker to provide a Windows UNC path resulting in an SMB network call being made from the Solr host to another host on the network. If the attacker has wider access to the network, this…

  • CVE-2021-31746CriDec 10, 2021
    risk 0.64cvss 9.8epss 0.02

    Zip Slip vulnerability in Pluck-CMS Pluck 4.7.15 allows an attacker to upload specially crafted zip files, resulting in directory traversal and potentially arbitrary code execution.

  • CVE-2021-43798HigKEVDec 7, 2021
    risk 0.64cvss 7.5epss 0.89

    Grafana is an open-source platform for monitoring and observability. Grafana versions 8.0.0-beta1 through 8.3.0 (except for patched versions) iss vulnerable to directory traversal, allowing access to local files. The vulnerable URL path is: `<grafana_host_url>/public/plugins//`,…

  • CVE-2021-43674CriDec 3, 2021
    risk 0.64cvss 9.8epss 0.01

    ThinkUp 2.0-beta.10 is affected by a path manipulation vulnerability in Smarty.class.php. NOTE: This vulnerability only affects products that are no longer supported by the maintainer

  • CVE-2021-43691CriNov 29, 2021
    risk 0.64cvss 9.8epss 0.02

    tripexpress v1.1 is affected by a path manipulation vulnerability in file system/helpers/dompdf/load_font.php. The variable src is coming from $_SERVER["argv"] then there is a path manipulation vulnerability.

  • CVE-2021-40358CriNov 9, 2021
    risk 0.64cvss 9.9epss 0.01

    A vulnerability has been identified in SIMATIC PCS 7 V8.2 (All versions), SIMATIC PCS 7 V9.0 (All versions < V9.0 SP3 UC04), SIMATIC PCS 7 V9.1 (All versions < V9.1 SP1), SIMATIC WinCC V15 and earlier (All versions < V15 SP1 Update 7), SIMATIC WinCC V16 (All versions < V16…

  • CVE-2021-40371CriOct 25, 2021
    risk 0.64cvss 9.8epss 0.07

    Gridpro Request Management for Windows Azure Pack before 2.0.7912 allows Directory Traversal for remote code execution, as demonstrated by ..\\ in a scriptName JSON value to ServiceManagerTenant/GetVisibilityMap.

  • CVE-2020-27304CriOct 21, 2021
    risk 0.64cvss 9.8epss 0.03

    The CivetWeb web library does not validate uploaded filepaths when running on an OS other than Windows, when using the built-in HTTP form-based file upload mechanism, via the mg_handle_form_request API. Web applications that use the file upload form handler, and use parts of the…

  • CVE-2021-20125CriOct 13, 2021
    risk 0.64cvss 9.8epss 0.04

    An arbitrary file upload and directory traversal vulnerability exists in the file upload functionality of DownloadFileServlet in Draytek VigorConnect 1.6.0-B3. An unauthenticated attacker could leverage this vulnerability to upload files to any location on the target operating…

  • CVE-2021-40887CriOct 11, 2021
    risk 0.64cvss 9.8epss 0.02

    Projectsend version r1295 is affected by a directory traversal vulnerability. Because of lacking sanitization input for files[] parameter, an attacker can add ../ to move all PHP files or any file on the system that has permissions to /upload/files/ folder.

  • CVE-2021-40960CriOct 1, 2021
    risk 0.64cvss 9.8epss 0.10

    Galera WebTemplate 1.0 is affected by a directory traversal vulnerability that could reveal information from /etc/passwd and /etc/shadow.