VYPR

CWE-22

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')

BaseStableLikelihood: High

Description

The product uses external input to construct a pathname that is intended to identify a file or directory that is located underneath a restricted parent directory, but the product does not properly neutralize special elements within the pathname that can cause the pathname to resolve to a location that is outside of the restricted directory.

Hierarchy (View 1000)

Parents

Children

Related attack patterns (CAPEC)

CAPEC-126 · CAPEC-64 · CAPEC-76 · CAPEC-78 · CAPEC-79

CVEs mapped to this weakness (10,483)

page 266 of 525
  • CVE-2022-30300MedFeb 16, 2023
    risk 0.42cvss 6.5epss 0.01

    A relative path traversal vulnerability [CWE-23] in FortiWeb 7.0.0 through 7.0.1, 6.3.6 through 6.3.18, 6.4 all versions may allow an authenticated attacker to obtain unauthorized access to files and data via specifically crafted HTTP GET requests.

  • CVE-2023-23136MedFeb 1, 2023
    risk 0.42cvss 6.5epss 0.01

    lmxcms v1.41 was discovered to contain an arbitrary file deletion vulnerability via BackdbAction.class.php.

  • CVE-2022-22731MedJan 30, 2023
    risk 0.42cvss 6.5epss 0.01

    A CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability exists in a function that could allow an attacker to create or overwrite critical files that are used to execute code, such as programs or libraries and cause path traversal…

  • CVE-2022-0223MedJan 30, 2023
    risk 0.42cvss 6.5epss 0.01

    A CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability exists that could allow an attacker to create or overwrite critical files that are used to execute code, such as programs or libraries and cause unauthenticated code execution.…

  • CVE-2022-25936HigJan 30, 2023
    risk 0.42cvss 7.5epss 0.01

    Versions of the package servst before 2.0.3 are vulnerable to Directory Traversal due to improper sanitization of the filePath variable.

  • CVE-2022-41154MedJan 26, 2023
    risk 0.42cvss 6.5epss 0.02

    A directory traversal vulnerability exists in the m2m DELETE_FILE cmd functionality of Siretta QUARTZ-GOLD G5.0.1.5-210720-141020. A specially-crafted network packet can lead to arbitrary file deletion. An attacker can send a network request to trigger this vulnerability.

  • CVE-2022-38088MedJan 26, 2023
    risk 0.42cvss 6.5epss 0.02

    A directory traversal vulnerability exists in the httpd downfile.cgi functionality of Siretta QUARTZ-GOLD G5.0.1.5-210720-141020. A specially-crafted HTTP request can lead to arbitrary file read. An attacker can send an HTTP request to trigger this vulnerability.

  • CVE-2022-25882HigJan 26, 2023
    risk 0.42cvss 7.5epss 0.02

    Versions of the package onnx before 1.13.0 are vulnerable to Directory Traversal as the external_data field of the tensor proto can have a path to the file which is outside the model current directory or user-provided directory, for example "../../../etc/passwd"

  • CVE-2022-41956MedJan 14, 2023
    risk 0.42cvss 6.5epss 0.02

    Autolab is a course management service, initially developed by a team of students at Carnegie Mellon University, that enables instructors to offer autograded programming assignments to their students over the Web. A file disclosure vulnerability was discovered in Autolab's…

  • CVE-2022-42282MedJan 13, 2023
    risk 0.42cvss 6.5epss 0.00

    NVIDIA BMC contains a vulnerability in SPX REST API, where an authorized attacker can access arbitrary files, which may lead to information disclosure.

  • CVE-2022-46309MedJan 3, 2023
    risk 0.42cvss 6.5epss 0.01

    Vitals ESP upload function has a path traversal vulnerability. A remote attacker with general user privilege can exploit this vulnerability to access arbitrary system files.

  • CVE-2022-46305MedJan 3, 2023
    risk 0.42cvss 6.5epss 0.00

    ChangingTec ServiSign component has a path traversal vulnerability. An unauthenticated LAN attacker can exploit this vulnerability to bypass authentication and access arbitrary system files.

  • CVE-2022-4778MedDec 29, 2022
    risk 0.42cvss 6.5epss 0.01

    StreamX applications from versions 6.02.01 to 6.04.34 are affected by a path traversal vulnerability that allows authenticated users to get unauthorized access to files on the server's filesystem. StreamX applications using StreamView HTML component with the public web server…

  • CVE-2020-36559HigDec 27, 2022
    risk 0.42cvss 7.5epss 0.01

    Due to improper sanitization of user input, HTTPEngine.Handle allows for directory traversal, allowing an attacker to read files outside of the target directory that the server has permission to read.

  • CVE-2019-25073HigDec 27, 2022
    risk 0.42cvss 7.5epss 0.01

    Improper path sanitization in github.com/goadesign/goa before v3.0.9, v2.0.10, or v1.4.3 allow remote attackers to read files outside of the intended directory.

  • CVE-2021-39369MedDec 26, 2022
    risk 0.42cvss 6.5epss 0.01

    In Philips (formerly Carestream) Vue MyVue PACS through 12.2.x.x, the VideoStream function allows Path Traversal by authenticated users to access files stored outside of the web root.

  • CVE-2022-45894MedDec 25, 2022
    risk 0.42cvss 6.5epss 0.01

    GetFile.aspx in Planet eStream before 6.72.10.07 allows ..\ directory traversal to read arbitrary local files.

  • CVE-2022-46492MedDec 23, 2022
    risk 0.42cvss 6.5epss 0.01

    nbnbk commit 879858451d53261d10f77d4709aee2d01c72c301 was discovered to contain an arbitrary file read vulnerability via the component /api/Index/getFileBinary.

  • CVE-2022-36221MedDec 21, 2022
    risk 0.42cvss 6.5epss 0.01

    Nokia Fastmile 3tg00118abad52 is affected by an authenticated path traversal vulnerability which allows attackers to read any named pipe file on the system.

  • CVE-2022-29511MedDec 15, 2022
    risk 0.42cvss 6.5epss 0.02

    A directory traversal vulnerability exists in the KnowledgebasePageActions.aspx ImportArticles functionality of Lansweeper lansweeper 10.1.1.0. A specially-crafted HTTP request can lead to arbitrary file read. An attacker can send an HTTP request to trigger this vulnerability.