VYPR

CWE-22

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')

BaseStableLikelihood: High

Description

The product uses external input to construct a pathname that is intended to identify a file or directory that is located underneath a restricted parent directory, but the product does not properly neutralize special elements within the pathname that can cause the pathname to resolve to a location that is outside of the restricted directory.

Hierarchy (View 1000)

Parents

Children

Related attack patterns (CAPEC)

CAPEC-126 · CAPEC-64 · CAPEC-76 · CAPEC-78 · CAPEC-79

CVEs mapped to this weakness (10,483)

page 263 of 525
  • CVE-2023-6015HigNov 16, 2023
    risk 0.42cvss 7.5epss 0.04

    MLflow allowed arbitrary files to be PUT onto the server.

  • CVE-2023-5245HigNov 15, 2023
    risk 0.42cvss 7.5epss 0.01

    FileUtil.extract() enumerates all zip file entries and extracts each file without validating whether file paths in the archive are outside the intended directory. When creating an instance of TensorflowModel using the saved_model format and an exported tensorflow model, the…

  • CVE-2023-34062HigNov 15, 2023
    risk 0.42cvss 7.5epss 0.01

    In Reactor Netty HTTP Server, versions 1.1.x prior to 1.1.13 and versions 1.0.x prior to 1.0.39, a malicious user can send a request using a specially crafted URL that can lead to a directory traversal attack. Specifically, an application is vulnerable if Reactor Netty HTTP…

  • CVE-2023-41356MedNov 3, 2023
    risk 0.42cvss 6.5epss 0.01

    NCSIST ManageEngine Mobile Device Manager(MDM) APP's special function has a path traversal vulnerability. An unauthenticated remote attacker can exploit this vulnerability to bypass authentication and read arbitrary system files.

  • CVE-2023-2621MedNov 1, 2023
    risk 0.42cvss 6.5epss 0.00

    The McFeeder server (distributed as part of SSW package), is susceptible to an arbitrary file write vulnerability on the MAIN computer system. This vulnerability stems from the use of an outdated version of a third-party library, which is used to extract archives uploaded to…

  • CVE-2023-45867MedOct 26, 2023
    risk 0.42cvss 6.5epss 0.01

    ILIAS (2013-09-12 release) contains a medium-criticality Directory Traversal local file inclusion vulnerability in the ScormAicc module. An attacker with a privileged account, typically holding the tutor role, can exploit this to gain unauthorized access to and potentially…

  • CVE-2023-46119HigOct 25, 2023
    risk 0.42cvss 7.5epss 0.01

    Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Parse Server crashes when uploading a file without extension. This vulnerability has been patched in versions 5.5.6 and 6.3.1.

  • CVE-2022-38485MedOct 25, 2023
    risk 0.42cvss 6.5epss 0.03

    A directory traversal vulnerability exists in the AgeVolt Portal prior to version 0.1 that leads to Information Disclosure. A remote authenticated attacker could leverage this vulnerability to read files from any location on the target operating system with web server privileges.

  • CVE-2023-44256MedOct 20, 2023
    risk 0.42cvss 6.5epss 0.01

    A server-side request forgery vulnerability [CWE-918] in Fortinet FortiAnalyzer version 7.4.0, version 7.2.0 through 7.2.3 and before 7.0.8 and FortiManager version 7.4.0, version 7.2.0 through 7.2.3 and before 7.0.8 allows a remote attacker with low privileges to view sensitive…

  • CVE-2023-31046MedOct 19, 2023
    risk 0.42cvss 6.5epss 0.02

    A Path Traversal vulnerability exists in PaperCut NG before 22.1.1 and PaperCut MF before 22.1.1. Under specific conditions, this could potentially allow an authenticated attacker to achieve read-only access to the server's filesystem, because requests beginning with "GET…

  • CVE-2023-34208MedOct 17, 2023
    risk 0.42cvss 6.5epss 0.01

    Path Traversal in create template function in EasyUse MailHunter Ultimate 2023 and earlier allow remote authenticated users to extract files into arbitrary directories via a crafted ZIP archive.

  • CVE-2023-45689MedOct 16, 2023
    risk 0.42cvss 6.5epss 0.01

    Lack of sufficient path validation in South River Technologies' Titan MFT and Titan SFTP servers on Windows and Linux allows an authenticated attacker with administrative privileges to read any file on the filesystem via path traversal

  • CVE-2023-21415MedOct 16, 2023
    risk 0.42cvss 6.5epss 0.01

    Sandro Poppi, member of the AXIS OS Bug Bounty Program, has found that the VAPIX API overlay_del.cgi is vulnerable to path traversal attacks that allows for file deletion. This flaw can only be exploited after authenticating with an operator- or administrator-privileged service…

  • CVE-2022-4244HigSep 25, 2023
    risk 0.42cvss 7.5epss 0.01

    A flaw was found in codeplex-codehaus. A directory traversal attack (also known as path traversal) aims to access files and directories stored outside the intended folder. By manipulating files with "dot-dot-slash (../)" sequences and their variations or by using absolute file…

  • CVE-2022-45447MedSep 20, 2023
    risk 0.42cvss 6.5epss 0.01

    M4 PDF plugin for Prestashop sites, in its 3.2.3 version and before, is vulnerable to a directory traversal vulnerability. The “f” parameter is not properly checked in the resource /m4pdf/pdf.php, returning any file given its relative path. An attacker that exploits this…

  • CVE-2023-37739MedSep 14, 2023
    risk 0.42cvss 6.5epss 0.01

    i-doit Pro v25 and below was discovered to be vulnerable to path traversal.

  • CVE-2023-4914HigSep 12, 2023
    risk 0.42cvss 7.5epss 0.01

    Relative Path Traversal in GitHub repository cecilapp/cecil prior to 7.47.1.

  • CVE-2023-41747MedAug 31, 2023
    risk 0.42cvss 6.5epss 0.00

    Sensitive information disclosure due to unauthenticated path traversal. The following products are affected: Acronis Cloud Manager (Windows) before build 6.2.23089.203.

  • CVE-2023-40828HigAug 28, 2023
    risk 0.42cvss 7.5epss 0.01

    An issue in pf4j pf4j v.3.9.0 and before allows a remote attacker to obtain sensitive information and execute arbitrary code via the expandIfZip method in the extract function.

  • CVE-2023-40827HigAug 28, 2023
    risk 0.42cvss 7.5epss 0.02

    An issue in pf4j pf4j v.3.9.0 and before allows a remote attacker to obtain sensitive information and execute arbitrary code via the loadpluginPath parameter.