VYPR

CWE-22

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')

BaseStableLikelihood: High

Description

The product uses external input to construct a pathname that is intended to identify a file or directory that is located underneath a restricted parent directory, but the product does not properly neutralize special elements within the pathname that can cause the pathname to resolve to a location that is outside of the restricted directory.

Hierarchy (View 1000)

Parents

Children

Related attack patterns (CAPEC)

CAPEC-126 · CAPEC-64 · CAPEC-76 · CAPEC-78 · CAPEC-79

CVEs mapped to this weakness (10,483)

page 269 of 525
  • CVE-2022-34177HigJun 23, 2022
    risk 0.42cvss 7.5epss 0.02

    Jenkins Pipeline: Input Step Plugin 448.v37cea_9a_10a_70 and earlier archives files uploaded for `file` parameters for Pipeline `input` steps on the controller as part of build metadata, using the parameter name without sanitization as a relative path inside a build-related…

  • CVE-2022-25856HigJun 17, 2022
    risk 0.42cvss 7.5epss 0.02

    The package github.com/argoproj/argo-events/sensors/artifacts before 1.7.1 are vulnerable to Directory Traversal in the (g *GitArtifactReader).Read() API in git.go. This could allow arbitrary file reads if the GitArtifactReader is provided a pathname containing a symbolic link…

  • CVE-2022-26041MedJun 13, 2022
    risk 0.42cvss 6.5epss 0.02

    Directory traversal vulnerability in RCCMD 4.26 and earlier allows a remote authenticated attacker with an administrative privilege to read or alter an arbitrary file on the server via unspecified vectors.

  • CVE-2022-24278HigJun 10, 2022
    risk 0.42cvss 7.5epss 0.02

    The package convert-svg-core before 0.6.4 are vulnerable to Directory Traversal due to improper sanitization of SVG tags. Exploiting this vulnerability is possible by using a specially crafted SVG file.

  • CVE-2022-0779MedJun 8, 2022
    risk 0.42cvss 6.5epss 0.02

    The User Meta WordPress plugin before 2.4.4 does not validate the filepath parameter of its um_show_uploaded_file AJAX action, which could allow low privileged users such as subscriber to enumerate the local files on the web server via path traversal payloads

  • CVE-2022-28478MedJun 6, 2022
    risk 0.42cvss 6.5epss 0.02

    SeedDMS 6.0.17 and 5.1.24 are vulnerable to Directory Traversal. The "Remove file" functionality inside the "Log files management" menu does not sanitize user input allowing attackers with admin privileges to delete arbitrary files on the remote system.

  • CVE-2022-29597MedJun 2, 2022
    risk 0.42cvss 6.5epss 0.02

    Solutions Atlantic Regulatory Reporting System (RRS) v500 is vulnerable to Local File Inclusion (LFI). Any authenticated user has the ability to reference internal system files within requests made to the RRSWeb/maint/ShowDocument/ShowDocument.aspx page. The server will…

  • CVE-2022-30804MedJun 2, 2022
    risk 0.42cvss 6.5epss 0.01

    elitecms v1.01 is vulnerable to Delete any file via /admin/delete_image.php?file=.

  • CVE-2022-23082HigMay 31, 2022
    risk 0.42cvss 7.5epss 0.01

    In CureKit versions v1.0.1 through v1.1.3 are vulnerable to path traversal as the function isFileOutsideDir fails to sanitize the user input which may lead to path traversal.

  • CVE-2022-30508MedMay 26, 2022
    risk 0.42cvss 6.5epss 0.01

    DedeCMS v5.7.93 was discovered to contain arbitrary file deletion vulnerability in upload.php via the delete parameter.

  • CVE-2022-30428HigMay 25, 2022
    risk 0.42cvss 7.5epss 0.01

    In ginadmin through 05-10-2022, the incoming path value is not filtered, resulting in arbitrary file reading.

  • CVE-2022-30427HigMay 25, 2022
    risk 0.42cvss 7.5epss 0.02

    In ginadmin through 05-10-2022 the incoming path value is not filtered, resulting in directory traversal.

  • CVE-2021-32964MedMay 24, 2022
    risk 0.42cvss 6.5epss 0.01

    The AGG Software Web Server version 4.0.40.1014 and prior is vulnerable to a path traversal attack, which may allow an attacker to read arbitrary files from the file system.

  • CVE-2022-30948HigMay 17, 2022
    risk 0.42cvss 7.5epss 0.02

    Jenkins Mercurial Plugin 2.16 and earlier allows attackers able to configure pipelines to check out some SCM repositories stored on the Jenkins controller's file system using local paths as SCM URLs, obtaining limited information about other projects' SCM contents.

  • CVE-2022-30947HigMay 17, 2022
    risk 0.42cvss 7.5epss 0.01

    Jenkins Git Plugin 4.11.1 and earlier allows attackers able to configure pipelines to check out some SCM repositories stored on the Jenkins controller's file system using local paths as SCM URLs, obtaining limited information about other projects' SCM contents.

  • CVE-2022-29332MedMay 17, 2022
    risk 0.42cvss 6.5epss 0.01

    D-LINK DIR-825 AC1200 R2 is vulnerable to Directory Traversal. An attacker could use the "../../../../" setting of the FTP server folder to set the router's root folder for FTP access. This allows you to access the entire router file system via the FTP server.

  • CVE-2022-1560MedMay 16, 2022
    risk 0.42cvss 6.5epss 0.02

    The Amministrazione Aperta WordPress plugin before 3.8 does not validate the open parameter before using it in an include statement, leading to a Local File Inclusion issue. The original advisory mentions that unauthenticated users can exploit this, however the affected file…

  • CVE-2022-30062MedMay 11, 2022
    risk 0.42cvss 6.5epss 0.01

    ftcms <=2.1 was discovered to be vulnerable to Arbitrary File Read via tp.php

  • CVE-2022-30061MedMay 11, 2022
    risk 0.42cvss 6.5epss 0.01

    ftcms <=2.1 was discovered to be vulnerable to directory traversal attacks via the parameter tp.

  • CVE-2022-30059MedMay 11, 2022
    risk 0.42cvss 6.5epss 0.01

    Shopwind <=v3.4.2 was discovered to contain a Arbitrary File Delete vulnerability via the neirong parameter at \backend\controllers\DbController.php.