VYPR

CWE-22

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')

BaseStableLikelihood: High

Description

The product uses external input to construct a pathname that is intended to identify a file or directory that is located underneath a restricted parent directory, but the product does not properly neutralize special elements within the pathname that can cause the pathname to resolve to a location that is outside of the restricted directory.

Hierarchy (View 1000)

Parents

Children

Related attack patterns (CAPEC)

CAPEC-126 · CAPEC-64 · CAPEC-76 · CAPEC-78 · CAPEC-79

CVEs mapped to this weakness (10,483)

page 267 of 525
  • CVE-2022-37906MedDec 12, 2022
    risk 0.42cvss 6.5epss 0.01

    An authenticated path traversal vulnerability exists in the ArubaOS command line interface. Successful exploitation of the vulnerability results in the ability to delete arbitrary files on the underlying operating system.

  • CVE-2022-41712MedNov 25, 2022
    risk 0.42cvss 6.5epss 0.01

    Frappe version 14.10.0 allows an external attacker to remotely obtain arbitrary local files. This is possible because the application does not correctly validate the information injected by the user in the import_file parameter.

  • CVE-2022-44280MedNov 23, 2022
    risk 0.42cvss 6.5epss 0.01

    Automotive Shop Management System v1.0 is vulnerable to Delete any file via /asms/classes/Master.php?f=delete_img.

  • CVE-2022-44008MedNov 16, 2022
    risk 0.42cvss 6.5epss 0.01

    An issue was discovered in BACKCLICK Professional 5.9.63. Due to improper validation, arbitrary local files can be retrieved by accessing the back-end Tomcat server directly.

  • CVE-2022-34662MedNov 1, 2022
    risk 0.42cvss 6.5epss 0.02

    When users add resources to the resource center with a relation path will cause path traversal issues and only for logged-in users. You could upgrade to version 3.0.0 or higher

  • CVE-2022-40742MedOct 31, 2022
    risk 0.42cvss 6.5epss 0.01

    Mail SQR Expert system has a Local File Inclusion vulnerability. An unauthenticated remote attacker can exploit this vulnerability to execute arbitrary PHP file with .asp file extension under specific system paths, to access and modify partial system information but does not…

  • CVE-2022-39023MedOct 31, 2022
    risk 0.42cvss 6.5epss 0.01

    U-Office Force Download function has a path traversal vulnerability. A remote attacker with general user privilege can exploit this vulnerability to download arbitrary system file.

  • CVE-2022-39022MedOct 31, 2022
    risk 0.42cvss 6.5epss 0.01

    U-Office Force Download function has a path traversal vulnerability. A remote attacker with general user privilege can exploit this vulnerability to download arbitrary system file.

  • CVE-2022-38196MedOct 25, 2022
    risk 0.42cvss 6.5epss 0.01

    Esri ArcGIS Server versions 10.9.1 and prior have a path traversal vulnerability that may result in a denial of service by allowing a remote, authenticated attacker to overwrite internal ArcGIS Server directory.

  • CVE-2022-3389HigOct 6, 2022
    risk 0.42cvss 7.5epss 0.01

    Path Traversal in GitHub repository ikus060/rdiffweb prior to 2.4.10.

  • CVE-2022-40123MedOct 3, 2022
    risk 0.42cvss 6.5epss 0.01

    mojoPortal v2.7 was discovered to contain a path traversal vulnerability via the "f" parameter at /DesignTools/CssEditor.aspx. This vulnerability allows authenticated attackers to read arbitrary files in the system.

  • CVE-2022-34429MedSep 30, 2022
    risk 0.42cvss 6.5epss 0.00

    Dell Hybrid Client below 1.8 version contains a Zip Slip Vulnerability in UI. A guest privilege attacker could potentially exploit this vulnerability, leading to system files modification.

  • CVE-2022-40082HigSep 28, 2022
    risk 0.42cvss 7.5epss 0.01

    Hertz v0.3.0 ws discovered to contain a path traversal vulnerability via the normalizePath function.

  • CVE-2022-39261HigSep 28, 2022
    risk 0.42cvss 7.5epss 0.03

    Twig is a template language for PHP. Versions 1.x prior to 1.44.7, 2.x prior to 2.15.3, and 3.x prior to 3.4.3 encounter an issue when the filesystem loader loads templates for which the name is a user input. It is possible to use the `source` or `include` statement to read…

  • CVE-2022-39034MedSep 28, 2022
    risk 0.42cvss 6.5epss 0.01

    Smart eVision has a path traversal vulnerability in the Report API function due to insufficient filtering for special characters in URLs. A remote attacker with general user privilege can exploit this vulnerability to bypass authentication, access restricted paths and download…

  • CVE-2022-40715MedSep 19, 2022
    risk 0.42cvss 6.5epss 0.01

    An issue was discovered in NOKIA 1350OMS R14.2. An Absolute Path Traversal vulnerability exists for a specific endpoint via the logfile parameter, allowing a remote authenticated attacker to read files on the filesystem arbitrarily.

  • CVE-2022-40713MedSep 19, 2022
    risk 0.42cvss 6.5epss 0.01

    An issue was discovered in NOKIA 1350OMS R14.2. Multiple Relative Path Traversal issues exist in different specific endpoints via the file parameter, allowing a remote authenticated attacker to read files on the filesystem arbitrarily.

  • CVE-2022-34002MedSep 16, 2022
    risk 0.42cvss 6.5epss 0.01

    The ‘document’ parameter of PDS Vista 7’s /application/documents/display.aspx page is vulnerable to a Local File Inclusion vulnerability which allows an low-privileged authenticated attacker to leak the configuration files and source code of the web application.

  • CVE-2022-32190HigSep 13, 2022
    risk 0.42cvss 7.5epss 0.02

    JoinPath and URL.JoinPath do not remove ../ path elements appended to a relative path. For example, JoinPath("https://go.dev", "../go") returns the URL "https://go.dev/../go", despite the JoinPath documentation stating that ../ path elements are removed from the result.

  • CVE-2022-38613MedSep 9, 2022
    risk 0.42cvss 6.5epss 0.01

    A Path Traversal vulnerability in SmartVista Cardgen v3.28.0 allows authenticated attackers to read arbitrary files in the system.