VYPR

CWE-22

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')

BaseStableLikelihood: High

Description

The product uses external input to construct a pathname that is intended to identify a file or directory that is located underneath a restricted parent directory, but the product does not properly neutralize special elements within the pathname that can cause the pathname to resolve to a location that is outside of the restricted directory.

Hierarchy (View 1000)

Parents

Children

Related attack patterns (CAPEC)

CAPEC-126 · CAPEC-64 · CAPEC-76 · CAPEC-78 · CAPEC-79

CVEs mapped to this weakness (10,483)

page 262 of 525
  • CVE-2023-29962MedJan 4, 2024
    risk 0.42cvss 6.5epss 0.01

    S-CMS v5.0 was discovered to contain an arbitrary file read vulnerability.

  • CVE-2023-41780MedJan 3, 2024
    risk 0.42cvss 6.4epss 0.00

    There is an unsafe DLL loading vulnerability in ZTE ZXCLOUD iRAI. Due to the  program  failed to adequately validate the user's input, an attacker could exploit this vulnerability  to escalate local privileges.

  • CVE-2023-5672MedDec 26, 2023
    risk 0.42cvss 6.5epss 0.01

    The WP Mail Log WordPress plugin before 1.1.3 does not properly validate file path parameters when attaching files to emails, leading to local file inclusion, and allowing an attacker to leak the contents of arbitrary files.

  • CVE-2022-41761MedDec 25, 2023
    risk 0.42cvss 6.5epss 0.01

    An issue was discovered in NOKIA NFM-T R19.9. An Absolute Path Traversal vulnerability exists under /cgi-bin/R19.9/viewlog.pl of the VM Manager WebUI via the logfile parameter, allowing a remote authenticated attacker to read arbitrary files.

  • CVE-2022-41760MedDec 25, 2023
    risk 0.42cvss 6.5epss 0.01

    An issue was discovered in NOKIA NFM-T R19.9. Relative Path Traversal can occur under /oms1350/data/cpb/log of the Network Element Manager via the filename parameter, allowing a remote authenticated attacker to read arbitrary files.

  • CVE-2023-46177MedDec 18, 2023
    risk 0.42cvss 6.5epss 0.01

    IBM MQ Appliance 9.3 LTS and 9.3 CD could allow a remote attacker to traverse directories on the system. An attacker could send a specially crafted URL request to view arbitrary files on the system. IBM X-Force ID: 269536.

  • CVE-2023-6559HigDec 16, 2023
    risk 0.42cvss 7.5epss 0.01

    The MW WP Form plugin for WordPress is vulnerable to arbitrary file deletion in all versions up to, and including, 5.0.3. This is due to the plugin not properly validating the path of an uploaded file prior to deleting it. This makes it possible for unauthenticated attackers to…

  • CVE-2023-48382MedDec 15, 2023
    risk 0.42cvss 6.5epss 0.01

    Softnext Mail SQR Expert is an email management platform, it has a Local File Inclusion (LFI) vulnerability in a mail deliver-related URL. An unauthenticated remote attacker can exploit this vulnerability to execute arbitrary PHP file with .asp file extension under specific…

  • CVE-2023-48381MedDec 15, 2023
    risk 0.42cvss 6.5epss 0.01

    Softnext Mail SQR Expert is an email management platform, it has a Local File Inclusion (LFI) vulnerability in a special URL. An unauthenticated remote attacker can exploit this vulnerability to execute arbitrary PHP file with .asp file extension under specific system paths, to…

  • CVE-2023-28465HigDec 12, 2023
    risk 0.42cvss 7.5epss 0.01

    The package-decompression feature in HL7 (Health Level 7) FHIR Core Libraries before 5.6.106 allows attackers to copy arbitrary files to certain directories via directory traversal, if an allowed directory name is a substring of the directory name chosen by the attacker. NOTE:…

  • CVE-2023-36654MedDec 12, 2023
    risk 0.42cvss 6.5epss 0.01

    Directory traversal in the log-download REST API endpoint in ProLion CryptoSpike 3.0.15P2 allows remote authenticated attackers to download host server SSH private keys (associated with a Linux root user) by injecting paths inside REST API endpoint parameters.

  • CVE-2023-5105MedDec 4, 2023
    risk 0.42cvss 6.5epss 0.01

    The Frontend File Manager Plugin WordPress plugin before 22.6 has a vulnerability that allows an Editor+ user to bypass the file download logic and download files such as `wp-config.php`

  • CVE-2023-44306MedDec 4, 2023
    risk 0.42cvss 6.5epss 0.01

    Dell DM5500 contains a path traversal vulnerability in the appliance. A remote attacker with high privileges could potentially exploit this vulnerability to overwrite configuration files stored on the server filesystem.

  • CVE-2023-5885MedNov 27, 2023
    risk 0.42cvss 6.5epss 0.01

    The discontinued FFS Colibri product allows a remote user to access files on the system including files containing login credentials for other users.

  • CVE-2023-4593MedNov 23, 2023
    risk 0.42cvss 6.5epss 0.01

    Path traversal vulnerability whose exploitation could allow an authenticated remote user to bypass SecurityManager's intended restrictions and list a parent directory via any filename, such as a multiple ..%2F value affecting the 'dodoc' parameter in the /MailAdmin_dll.htm file.

  • CVE-2023-6265MedNov 22, 2023
    risk 0.42cvss 6.5epss 0.02

    ** UNSUPPORTED WHEN ASSIGNED ** Draytek Vigor2960 v1.5.1.4 and v1.5.1.5 are vulnerable to directory traversal via the mainfunction.cgi dumpSyslog 'option' parameter allowing an authenticated attacker with access to the web management interface to delete arbitrary files.…

  • CVE-2023-47467MedNov 22, 2023
    risk 0.42cvss 6.5epss 0.01

    Directory Traversal vulnerability in jeecg-boot v.3.6.0 allows a remote privileged attacker to obtain sensitive information via the file directory structure.

  • CVE-2023-47251MedNov 22, 2023
    risk 0.42cvss 6.5epss 0.02

    In mprivacy-tools before 2.0.406g in m-privacy TightGate-Pro Server, a Directory Traversal in the print function of the VNC service allows authenticated attackers (with access to a VNC session) to automatically transfer malicious PDF documents by moving them into the .spool…

  • CVE-2023-6209MedNov 21, 2023
    risk 0.42cvss 6.5epss 0.01

    Relative URLs starting with three slashes were incorrectly parsed, and a path-traversal "/../" part in the path could be used to override the specified host. This could contribute to security problems in web sites. This vulnerability affects Firefox < 120, Firefox ESR < 115.5.0,…

  • CVE-2023-42428MedNov 17, 2023
    risk 0.42cvss 6.5epss 0.01

    Directory traversal vulnerability in CubeCart prior to 6.5.3 allows a remote authenticated attacker with an administrative privilege to delete directories and files in the system.