VYPR

CWE-22

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')

BaseStableLikelihood: High

Description

The product uses external input to construct a pathname that is intended to identify a file or directory that is located underneath a restricted parent directory, but the product does not properly neutralize special elements within the pathname that can cause the pathname to resolve to a location that is outside of the restricted directory.

Hierarchy (View 1000)

Parents

Children

Related attack patterns (CAPEC)

CAPEC-126 · CAPEC-64 · CAPEC-76 · CAPEC-78 · CAPEC-79

CVEs mapped to this weakness (10,483)

page 264 of 525
  • CVE-2023-40274HigAug 14, 2023
    risk 0.42cvss 7.5epss 0.01

    An issue was discovered in zola 0.13.0 through 0.17.2. The custom implementation of a web server, available via the "zola serve" command, allows directory traversal. The handle_request function, used by the server to process HTTP requests, does not account for sequences of…

  • CVE-2020-26065MedAug 4, 2023
    risk 0.42cvss 6.5epss 0.02

    A vulnerability in the web-based management interface of Cisco SD-WAN vManage Software could allow an authenticated, remote attacker to conduct path traversal attacks and obtain read access to sensitive files on an affected system. The vulnerability is due to insufficient…

  • CVE-2023-37896HigAug 4, 2023
    risk 0.42cvss 7.5epss 0.01

    Nuclei is a vulnerability scanner. Prior to version 2.9.9, a security issue in the Nuclei project affected users utilizing Nuclei as Go code (SDK) running custom templates. This issue did not affect CLI users. The problem was related to sanitization issues with payload loading…

  • CVE-2022-26838MedAug 3, 2023
    risk 0.42cvss 6.5epss 0.01

    Path traversal vulnerability in Importing Mobile Device Data of Cybozu Remote Service 3.1.2 allows a remote authenticated attacker to cause a denial-of-service (DoS) condition.

  • CVE-2023-3329MedAug 2, 2023
    risk 0.42cvss 6.5epss 0.01

    SpiderControl SCADA Webserver versions 2.08 and prior are vulnerable to path traversal. An attacker with administrative privileges could overwrite files on the webserver using the HMI's upload file feature. This could create size zero files anywhere on the webserver, potentially…

  • CVE-2023-35016MedJul 31, 2023
    risk 0.42cvss 6.5epss 0.01

    IBM Security Verify Governance, Identity Manager 10.0 could allow a remote attacker to traverse directories on the system. An attacker could send a specially crafted URL request containing "dot dot" sequences (/../) to view arbitrary files on the system. IBM X-Force ID: 257772.

  • CVE-2022-46900MedJul 25, 2023
    risk 0.42cvss 6.5epss 0.01

    An issue was discovered in Vocera Report Server and Voice Server 5.x through 5.8. There is Path Traversal in the Task Exec filename. The Vocera Report Console contains various jobs that are executed on the server at specified intervals, e.g., backup, etc. An authenticated user…

  • CVE-2023-3813HigJul 21, 2023
    risk 0.42cvss 7.5epss 0.01

    The Jupiter X Core plugin for WordPress is vulnerable to arbitrary file downloads in versions up to, and including, 4.6.6. This makes it possible for unauthenticated attackers to download the contents of arbitrary files on the server, which can contain sensitive information. The…

  • CVE-2023-37781MedJul 17, 2023
    risk 0.42cvss 6.5epss 0.01

    An issue in the emqx_sn plugin of EMQX v4.3.8 allows attackers to execute a directory traversal via uploading a crafted .txt file.

  • CVE-2023-34135MedJul 13, 2023
    risk 0.42cvss 6.5epss 0.02

    Path Traversal vulnerability in SonicWall GMS and Analytics allows a remote authenticated attacker to read arbitrary files from the underlying file system via web service. This issue affects GMS: 9.3.2-SP1 and earlier versions; Analytics: 2.5.0.4-R7 and earlier versions.

  • CVE-2023-37960MedJul 12, 2023
    risk 0.42cvss 6.5epss 0.01

    Jenkins MathWorks Polyspace Plugin 1.0.5 and earlier allows attackers with Item/Configure permission to send emails with arbitrary files from the Jenkins controller file systems.

  • CVE-2023-25606MedJul 11, 2023
    risk 0.42cvss 6.5epss 0.01

    An improper limitation of a pathname to a restricted directory ('Path Traversal') vulnerability [CWE-23] in FortiAnalyzer and FortiManager management interface 7.2.0 through 7.2.1, 7.0.0 through 7.0.5, 6.4  all versions may allow a remote and authenticated attacker to…

  • CVE-2023-37288MedJul 10, 2023
    risk 0.42cvss 6.5epss 0.01

    SmartBPM.NET component has a vulnerability of path traversal within its file download function. An unauthenticated remote attacker can exploit this vulnerability to access arbitrary system files.

  • CVE-2023-23547MedJul 6, 2023
    risk 0.42cvss 6.5epss 0.01

    A directory traversal vulnerability exists in the luci2-io file-export mib functionality of Milesight UR32L v32.3.0.5. A specially crafted network request can lead to arbitrary file read. An attacker can send a network request to trigger this vulnerability.

  • CVE-2023-36827HigJul 5, 2023
    risk 0.42cvss 7.5epss 0.01

    Fides is an open-source privacy engineering platform for managing the fulfillment of data privacy requests in a runtime environment, and the enforcement of privacy regulations in code. A path traversal (directory traversal) vulnerability affects fides versions lower than version…

  • CVE-2023-35975MedJul 5, 2023
    risk 0.42cvss 6.5epss 0.01

    An authenticated path traversal vulnerability exists in the ArubaOS command line interface. Successful exploitation of this vulnerability results in the ability to delete arbitrary files in the underlying operating system.

  • CVE-2023-36819MedJul 3, 2023
    risk 0.42cvss 6.5epss 0.01

    Knowage is the professional open source suite for modern business analytics over traditional sources and big data systems. The endpoint `_/knowage/restful-services/dossier/importTemplateFile_` allows authenticated users to download template hosted on the server. However,…

  • CVE-2023-32608MedJun 30, 2023
    risk 0.42cvss 6.5epss 0.01

    Directory traversal vulnerability in Pleasanter (Community Edition and Enterprise Edition) 1.3.39.2 and earlier versions allows a remote authenticated attacker to alter an arbitrary file on the server.

  • CVE-2022-42474MedJun 13, 2023
    risk 0.42cvss 6.5epss 0.01

    A relative path traversal vulnerability [CWE-23] in Fortinet FortiOS version 7.2.0 through 7.2.3, version 7.0.0 through 7.0.9 and before 6.4.12, FortiProxy version 7.2.0 through 7.2.1 and 7.0.0 through 7.0.7, FortiSwitchManager version 7.2.0 through 7.2.1 and before 7.0.1 allows…

  • CVE-2023-34345MedJun 12, 2023
    risk 0.42cvss 6.5epss 0.01

    AMI BMC contains a vulnerability in the SPX REST API, where an attacker with the required privileges can access arbitrary files, which may lead to information disclosure.