VYPR

CWE-22

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')

BaseStableLikelihood: High

Description

The product uses external input to construct a pathname that is intended to identify a file or directory that is located underneath a restricted parent directory, but the product does not properly neutralize special elements within the pathname that can cause the pathname to resolve to a location that is outside of the restricted directory.

Hierarchy (View 1000)

Parents

Children

Related attack patterns (CAPEC)

CAPEC-126 · CAPEC-64 · CAPEC-76 · CAPEC-78 · CAPEC-79

CVEs mapped to this weakness (10,395)

page 25 of 520
  • CVE-2021-41290CriSep 30, 2021
    risk 0.64cvss 9.8epss 0.02

    ECOA BAS controller suffers from an arbitrary file write and path traversal vulnerability. Using the POST parameters, unauthenticated attackers can remotely set arbitrary values for location and content type and gain the possibility to execute arbitrary code on the affected…

  • CVE-2021-40098CriSep 27, 2021
    risk 0.64cvss 9.8epss 0.02

    An issue was discovered in Concrete CMS through 8.5.5. Path Traversal leading to RCE via external form by adding a regular expression.

  • CVE-2020-21125CriSep 15, 2021
    risk 0.64cvss 9.8epss 0.02

    An arbitrary file creation vulnerability in UReport 2.2.9 allows attackers to execute arbitrary code.

  • CVE-2021-34436CriSep 2, 2021
    risk 0.64cvss 9.8epss 0.02

    In Eclipse Theia 0.1.1 to 0.2.0, it is possible to exploit the default build to obtain remote code execution (and XXE) via the theia-xml-extension. This extension uses lsp4xml (recently renamed to LemMinX) in order to provide language support for XML. This is installed by…

  • CVE-2020-19305CriAug 3, 2021
    risk 0.64cvss 9.8epss 0.02

    An issue in /app/system/column/admin/index.class.php of Metinfo v7.0.0 causes the indeximg parameter to be deleted when the column is deleted, allowing attackers to escalate privileges.

  • CVE-2021-24375CriJul 6, 2021
    risk 0.64cvss 9.8epss 0.03

    Lack of authentication or validation in motor_load_more, motor_gallery_load_more, motor_quick_view and motor_project_quick_view AJAX handlers of the Motor WordPress theme before 3.1.0 allows an unauthenticated attacker access to arbitrary files in the server file system, and to…

  • CVE-2021-33576CriJun 18, 2021
    risk 0.64cvss 9.8epss 0.02

    An issue was discovered in Cleo LexiCom 5.5.0.0. Within the AS2 message, the sender can specify a filename. This filename can include path-traversal characters, allowing the file to be written to an arbitrary location on disk.

  • CVE-2020-18178CriMay 18, 2021
    risk 0.64cvss 9.8epss 0.02

    Path Traversal in HongCMS v4.0.0 allows remote attackers to view, edit, and delete arbitrary files via a crafted POST request to the component "/hcms/admin/index.php/language/ajax."

  • CVE-2021-20078CriApr 1, 2021
    risk 0.64cvss 9.1epss 0.60

    Manage Engine OpManager builds below 125346 are vulnerable to a remote denial of service vulnerability due to a path traversal issue in spark gateway component. This allows a remote attacker to remotely delete any directory or directories on the OS.

  • CVE-2021-29417CriMar 29, 2021
    risk 0.64cvss 9.8epss 0.04

    gitjacker before 0.1.0 allows remote attackers to execute arbitrary code via a crafted .git directory because of directory traversal.

  • CVE-2021-26293CriMar 4, 2021
    risk 0.64cvss 9.8epss 0.07

    An issue was discovered in AfterLogic Aurora through 8.5.3 and WebMail Pro through 8.5.3, when DAV is enabled. They allow directory traversal to create new files (such as an executable file under the web root). This is related to DAVServer.php in 8.x and DAV/Server.php in 7.x.

  • CVE-2021-3199CriJan 26, 2021
    risk 0.64cvss 9.8epss 0.08

    Directory traversal with remote code execution can occur in /upload in ONLYOFFICE Document Server before 5.6.3, when JWT is used, via a /.. sequence in an image upload parameter.

  • CVE-2020-27637CriJan 12, 2021
    risk 0.64cvss 9.8epss 0.02

    The R programming language’s default package manager CRAN is affected by a path traversal vulnerability that can lead to server compromise. This vulnerability affects packages installed via the R CMD install cli command or the install.packages() function from the interpreter.…

  • CVE-2020-13450CriJan 7, 2021
    risk 0.64cvss 9.8epss 0.06

    A directory traversal vulnerability in file upload function of Gotenberg through 6.2.1 allows an attacker to upload and overwrite any writable files outside the intended folder. This can lead to DoS, a change to program behavior, or code execution.

  • CVE-2020-36052CriJan 5, 2021
    risk 0.64cvss 9.8epss 0.02

    Directory traversal vulnerability in post-edit.php in MiniCMS V1.10 allows remote attackers to include and execute arbitrary files via the state parameter.

  • CVE-2020-5639CriDec 14, 2020
    risk 0.64cvss 9.8epss 0.05

    Directory traversal vulnerability in FileZen versions from V3.0.0 to V4.2.2 allows remote attackers to upload an arbitrary file in a specific directory via unspecified vectors. As a result, an arbitrary OS command may be executed.

  • CVE-2020-27730CriDec 11, 2020
    risk 0.64cvss 9.8epss 0.02

    In versions 3.0.0-3.9.0, 2.0.0-2.9.0, and 1.0.1, the NGINX Controller Agent does not use absolute paths when calling system utilities.

  • CVE-2020-29600CriDec 7, 2020
    risk 0.64cvss 9.8epss 0.04

    In AWStats through 7.7, cgi-bin/awstats.pl?config= accepts an absolute pathname, even though it was intended to only read a file in the /etc/awstats/awstats.conf format. NOTE: this issue exists because of an incomplete fix for CVE-2017-1000501.

  • CVE-2017-15681CriNov 27, 2020
    risk 0.64cvss 9.8epss 0.02

    In Crafter CMS Crafter Studio 3.0.1 a directory traversal vulnerability exists which allows unauthenticated attackers to overwrite files from the operating system which can lead to RCE.

  • CVE-2020-15929CriNov 24, 2020
    risk 0.64cvss 9.8epss 0.05

    In Ortus TestBox 2.4.0 through 4.1.0, unvalidated query string parameters passed to system/runners/HTMLRunner.cfm allow an attacker to write an arbitrary CFM file (within the application's context) containing attacker-defined CFML tags, leading to Remote Code Execution.