VYPR

CWE-22

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')

BaseStableLikelihood: High

Description

The product uses external input to construct a pathname that is intended to identify a file or directory that is located underneath a restricted parent directory, but the product does not properly neutralize special elements within the pathname that can cause the pathname to resolve to a location that is outside of the restricted directory.

Hierarchy (View 1000)

Parents

Children

Related attack patterns (CAPEC)

CAPEC-126 · CAPEC-64 · CAPEC-76 · CAPEC-78 · CAPEC-79

CVEs mapped to this weakness (10,483)

page 268 of 525
  • CVE-2022-37299MedSep 9, 2022
    risk 0.42cvss 6.5epss 0.04

    An issue was discovered in Shirne CMS 1.2.0. There is a Path Traversal vulnerability which could cause arbitrary file read via /static/ueditor/php/controller.php

  • CVE-2022-36593MedSep 2, 2022
    risk 0.42cvss 6.5epss 0.01

    kkFileView v4.0.0 was discovered to contain an arbitrary file deletion vulnerability via the fileName parameter at /controller/FileController.java.

  • CVE-2022-36687MedAug 29, 2022
    risk 0.42cvss 6.5epss 0.01

    Ingredients Stock Management System v1.0 was discovered to contain an arbitrary file deletion vulnerability via the component /classes/Master.php?f=delete_img.

  • CVE-2022-37423HigAug 12, 2022
    risk 0.42cvss 7.5epss 0.01

    Neo4j APOC (Awesome Procedures on Cypher) before 4.3.0.7 and 4.x before 4.4.0.8 allows Directory Traversal to sibling directories via apoc.log.stream.

  • CVE-2022-34365MedAug 10, 2022
    risk 0.42cvss 6.5epss 0.01

    WMS 3.7 contains a Path Traversal Vulnerability in Device API. An attacker could potentially exploit this vulnerability, to gain unauthorized read access to the files stored on the server filesystem, with the privileges of the running web application.

  • CVE-2022-20816MedAug 10, 2022
    risk 0.42cvss 6.5epss 0.01

    A vulnerability in the web-based management interface of Cisco Unified Communications Manager (Unified CM) and Cisco Unified Communications Manager Session Management Edition (Unified CM SME) could allow an authenticated, remote attacker to delete arbitrary files from an…

  • CVE-2022-30572MedAug 2, 2022
    risk 0.42cvss 6.5epss 0.01

    The iWay Service Manager Console component of TIBCO Software Inc.'s TIBCO iWay Service Manager contains an easily exploitable Directory Traversal vulnerability that allows a low privileged attacker with network access to read arbitrary resources on the affected system. Affected…

  • CVE-2021-46830MedJul 27, 2022
    risk 0.42cvss 6.5epss 0.01

    A path traversal vulnerability exists within GoAnywhere MFT before 6.8.3 that utilize self-registration for the GoAnywhere Web Client. This vulnerability could potentially allow an external user who self-registers with a specific username and/or profile information to gain…

  • CVE-2022-34551MedJul 27, 2022
    risk 0.42cvss 6.5epss 0.01

    Sims v1.0 was discovered to allow path traversal when downloading attachments.

  • CVE-2022-27610MedJul 27, 2022
    risk 0.42cvss 6.5epss 0.02

    Improper limitation of a pathname to a restricted directory ('Path Traversal') vulnerability in webapi component in Synology DiskStation Manager (DSM) before 6.2.3-25423 allows remote authenticated users to delete arbitrary files via unspecified vectors.

  • CVE-2022-1128MedJul 23, 2022
    risk 0.42cvss 6.5epss 0.01

    Inappropriate implementation in Web Share API in Google Chrome on Windows prior to 100.0.4896.60 allowed an attacker on the local network segment to leak cross-origin data via a crafted HTML page.

  • CVE-2022-31163HigJul 22, 2022
    risk 0.42cvss 7.5epss 0.02

    TZInfo is a Ruby library that provides access to time zone data and allows times to be converted using time zone rules. Versions prior to 0.36.1, as well as those prior to 1.2.10 when used with the Ruby data source tzinfo-data, are vulnerable to relative path traversal. With the…

  • CVE-2022-30302MedJul 19, 2022
    risk 0.42cvss 6.5epss 0.01

    Multiple relative path traversal vulnerabilities [CWE-23] in FortiDeceptor management interface 1.0.0 through 3.2.x, 3.3.0 through 3.3.2, 4.0.0 through 4.0.1 may allow a remote and authenticated attacker to retrieve and delete arbitrary files from the underlying filesystem via…

  • CVE-2022-2030MedJul 19, 2022
    risk 0.42cvss 6.5epss 0.01

    A directory traversal vulnerability caused by specific character sequences within an improperly sanitized URL was identified in some CGI programs of Zyxel USG FLEX 100(W) firmware versions 4.50 through 5.30, USG FLEX 200 firmware versions 4.50 through 5.30, USG FLEX 500 firmware…

  • CVE-2022-31202MedJul 17, 2022
    risk 0.42cvss 6.5epss 0.01

    The export function in SoftGuard Web (SGW) before 5.1.5 allows directory traversal to read an arbitrary local file via export or man.tcl.

  • CVE-2022-35410HigJul 8, 2022
    risk 0.42cvss 7.5epss 0.02

    mat2 (aka metadata anonymisation toolkit) before 0.13.0 allows ../ directory traversal during the ZIP archive cleaning process. This primarily affects mat2 web instances, in which clients could obtain sensitive information via a crafted archive.

  • CVE-2022-20791MedJul 6, 2022
    risk 0.42cvss 6.5epss 0.02

    A vulnerability in the database user privileges of Cisco Unified Communications Manager (Unified CM), Cisco Unified Communications Manager Session Management Edition (Unified CM SME), and Cisco Unified Communications Manager IM & Presence Service (Unified CM IM&P) could…

  • CVE-2022-33116MedJun 27, 2022
    risk 0.42cvss 6.5epss 0.02

    An issue in the jmpath variable in /modules/mindmap/index.php of GUnet Open eClass Platform (aka openeclass) v3.12.4 and below allows attackers to read arbitrary files via a directory traversal.

  • CVE-2021-41636MedJun 24, 2022
    risk 0.42cvss 6.5epss 0.01

    MELAG FTP Server 2.2.0.4 allows an attacker to use the CWD command to break out of the FTP servers root directory and operate on the entire operating system, while the access restrictions of the user running the FTP server apply.

  • CVE-2022-34179HigJun 23, 2022
    risk 0.42cvss 7.5epss 0.02

    Jenkins Embeddable Build Status Plugin 2.0.3 and earlier allows specifying a `style` query parameter that is used to choose a different SVG image style without restricting possible values, resulting in a relative path traversal vulnerability that allows attackers without…