VYPR

CWE-22

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')

BaseStableLikelihood: High

Description

The product uses external input to construct a pathname that is intended to identify a file or directory that is located underneath a restricted parent directory, but the product does not properly neutralize special elements within the pathname that can cause the pathname to resolve to a location that is outside of the restricted directory.

Hierarchy (View 1000)

Parents

Children

Related attack patterns (CAPEC)

CAPEC-126 · CAPEC-64 · CAPEC-76 · CAPEC-78 · CAPEC-79

CVEs mapped to this weakness (10,395)

page 26 of 520
  • CVE-2020-12315CriNov 12, 2020
    risk 0.64cvss 9.8epss 0.02

    Path traversal in the Intel(R) EMA before version 1.3.3 may allow an unauthenticated user to potentially enable escalation of privilege via network access.

  • CVE-2020-27160CriOct 27, 2020
    risk 0.64cvss 9.8epss 0.05

    Addressed remote code execution vulnerability in AvailableApps.php that allowed escalation of privileges in Western Digital My Cloud NAS devices prior to 5.04.114 (issue 3 of 3).

  • CVE-2020-21526CriSep 30, 2020
    risk 0.64cvss 9.8epss 0.02

    An Arbitrary file writing vulnerability in halo v1.1.3. In an interface to write files in the background, a directory traversal check is performed on the input path parameter, but the startsWith function can be used to bypass it.

  • CVE-2020-21522CriSep 30, 2020
    risk 0.64cvss 9.8epss 0.02

    An issue was discovered in halo V1.1.3. A Zip Slip Directory Traversal Vulnerability in the backend,the attacker can overwrite some files, such as ftl files, .bashrc files in the user directory, and finally get the permissions of the operating system.

  • CVE-2020-24626CriSep 23, 2020
    risk 0.64cvss 9.8epss 0.03

    Unathenticated directory traversal in the ReceiverServlet class doPost() method can lead to arbitrary remote code execution in HPE Pay Per Use (PPU) Utility Computing Service (UCS) Meter version 1.9.

  • CVE-2020-6142CriSep 1, 2020
    risk 0.64cvss 9.8epss 0.09

    A remote code execution vulnerability exists in the Modules.php functionality of OS4Ed openSIS 7.3. A specially crafted HTTP request can cause local file inclusion. An attacker can send an HTTP request to trigger this vulnerability.

  • CVE-2020-7522CriAug 31, 2020
    risk 0.64cvss 9.8epss 0.02

    Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability exists in SFAPV9601 - APC Easy UPS On-Line Software (V2.0 and earlier) when accessing a vulnerable method of `SoundUploadServlet` which may lead to uploading executable files to…

  • CVE-2020-7521CriAug 31, 2020
    risk 0.64cvss 9.8epss 0.02

    Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability exists in SFAPV9601 - APC Easy UPS On-Line Software (V2.0 and earlier) when accessing a vulnerable method of `FileUploadServlet` which may lead to uploading executable files to…

  • CVE-2020-16245CriAug 25, 2020
    risk 0.64cvss 9.8epss 0.08

    Advantech iView, Versions 5.7 and prior. The affected product is vulnerable to path traversal vulnerabilities that could allow an attacker to create/download arbitrary files, limit system availability, and remotely execute code.

  • CVE-2020-5609CriAug 5, 2020
    risk 0.64cvss 9.8epss 0.02

    Directory traversal vulnerability in CAMS for HIS CENTUM CS 3000 (includes CENTUM CS 3000 Small) R3.08.10 to R3.09.50, CENTUM VP (includes CENTUM VP Small, Basic) R4.01.00 to R6.07.00, B/M9000CS R5.04.01 to R5.05.01, and B/M9000 VP R6.01.01 to R8.03.01 allows a remote…

  • CVE-2020-14507CriJul 15, 2020
    risk 0.64cvss 9.8epss 0.05

    Advantech iView, versions 5.6 and prior, is vulnerable to multiple path traversal vulnerabilities that could allow an attacker to create/download arbitrary files, limit system availability, and remotely execute code.

  • CVE-2020-7497CriJun 16, 2020
    risk 0.64cvss 9.8epss 0.02

    A CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability exists in EcoStruxure Operator Terminal Expert 3.1 Service Pack 1 and prior (formerly known as Vijeo XD)which could cause arbitrary application execution when the computer…

  • CVE-2020-6109CriJun 8, 2020
    risk 0.64cvss 9.8epss 0.05

    An exploitable path traversal vulnerability exists in the Zoom client, version 4.6.10 processes messages including animated GIFs. A specially crafted chat message can cause an arbitrary file write, which could potentially be abused to achieve arbitrary code execution. An…

  • CVE-2020-12832CriMay 13, 2020
    risk 0.64cvss 9.8epss 0.07

    WordPress Plugin Simple File List before 4.2.8 is prone to a vulnerability that lets attackers delete arbitrary files because the application fails to properly verify user-supplied input.

  • CVE-2020-12006CriMay 8, 2020
    risk 0.64cvss 9.8epss 0.04

    Advantech WebAccess Node, Version 8.4.4 and prior, Version 9.0.0. Multiple relative path traversal vulnerabilities exist that may allow a low privilege user to overwrite files outside the application’s control.

  • CVE-2020-10794CriMay 7, 2020
    risk 0.64cvss 9.8epss 0.01

    Gira TKS-IP-Gateway 4.0.7.7 is vulnerable to unauthenticated path traversal that allows an attacker to download the application database. This can be combined with CVE-2020-10795 for remote root access.

  • CVE-2020-11705CriApr 12, 2020
    risk 0.64cvss 9.8epss 0.01

    An issue was discovered in ProVide (formerly zFTPServer) through 13.1. /ajax/ImportCertificate allows an attacker to load an arbitrary certificate in .pfx format or overwrite arbitrary files via the fileName parameter.

  • CVE-2020-10631CriApr 9, 2020
    risk 0.64cvss 9.8epss 0.01

    An attacker could use a specially crafted URL to delete or read files outside the WebAccess/NMS's (versions prior to 3.0.2) control.

  • CVE-2020-6974CriApr 7, 2020
    risk 0.64cvss 9.8epss 0.02

    Honeywell Notifier Web Server (NWS) Version 3.50 is vulnerable to a path traversal attack, which allows an attacker to bypass access to restricted directories. Honeywell has released a firmware update to address the problem.

  • CVE-2020-8600CriMar 18, 2020
    risk 0.64cvss 9.8epss 0.04

    Trend Micro Worry-Free Business Security (9.0, 9.5, 10.0) is affected by a directory traversal vulnerability that could allow an attacker to manipulate a key file to bypass authentication.