VYPR

CWE-22

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')

BaseStableLikelihood: High

Description

The product uses external input to construct a pathname that is intended to identify a file or directory that is located underneath a restricted parent directory, but the product does not properly neutralize special elements within the pathname that can cause the pathname to resolve to a location that is outside of the restricted directory.

Hierarchy (View 1000)

Parents

Children

Related attack patterns (CAPEC)

CAPEC-126 · CAPEC-64 · CAPEC-76 · CAPEC-78 · CAPEC-79

CVEs mapped to this weakness (10,395)

page 27 of 520
  • CVE-2020-10564CriMar 13, 2020
    risk 0.64cvss 9.8epss 0.09

    An issue was discovered in the File Upload plugin before 4.13.0 for WordPress. A directory traversal can lead to remote code execution by uploading a crafted txt file into the lib directory, because of a wfu_include_lib call.

  • CVE-2019-12182CriMar 13, 2020
    risk 0.64cvss 9.8epss 0.05

    Directory Traversal in Safescan Timemoto and TA-8000 series version 1.0 allows unauthenticated remote attackers to execute code via the administrative API.

  • CVE-2020-8803CriFeb 13, 2020
    risk 0.64cvss 9.8epss 0.03

    SuiteCRM through 7.11.11 allows Directory Traversal to include arbitrary .php files within the webroot via add_to_prospect_list.

  • CVE-2015-5952CriJan 15, 2020
    risk 0.64cvss 9.8epss 0.03

    Directory traversal vulnerability in Thomson Reuters for FATCA before 5.2 allows remote attackers to execute arbitrary files via the item parameter.

  • CVE-2019-19628CriJan 5, 2020
    risk 0.64cvss 9.8epss 0.04

    In GitLab EE 11.3 through 12.5.3, 12.4.5, and 12.3.8, insufficient parameter sanitization for the Maven package registry could lead to privilege escalation and remote code execution vulnerabilities under certain conditions.

  • CVE-2019-11994CriJan 3, 2020
    risk 0.64cvss 9.8epss 0.07

    A security vulnerability has been identified in HPE SimpliVity 380 Gen 9, HPE SimpliVity 380 Gen 10, HPE SimpliVity 380 Gen 10 G, HPE SimpliVity 2600 Gen 10, SimpliVity OmniCube, SimpliVity OmniStack for Cisco, SimpliVity OmniStack for Lenovo and SimpliVity OmniStack for Dell…

  • CVE-2019-19088CriJan 3, 2020
    risk 0.64cvss 9.8epss 0.02

    Gitlab Enterprise Edition (EE) 11.3 through 12.4.2 allows Directory Traversal.

  • CVE-2019-19790CriDec 13, 2019
    risk 0.64cvss 9.8epss 0.03

    Path traversal in RadChart in Telerik UI for ASP.NET AJAX allows a remote attacker to read and delete an image with extension .BMP, .EXIF, .GIF, .ICON, .JPEG, .PNG, .TIFF, or .WMF on the server through a specially crafted request. NOTE: RadChart was discontinued in 2014 in favor…

  • CVE-2019-16246CriDec 12, 2019
    risk 0.64cvss 9.8epss 0.03

    Intesync Solismed 3.3sp1 allows Local File Inclusion (LFI), a different vulnerability than CVE-2019-15931. This leads to unauthenticated code execution.

  • CVE-2019-15931CriDec 12, 2019
    risk 0.64cvss 9.8epss 0.03

    Intesync Solismed 3.3sp allows Directory Traversal, a different vulnerability than CVE-2019-16246.

  • CVE-2019-19459CriDec 3, 2019
    risk 0.64cvss 9.8epss 0.04

    An issue was discovered in SALTO ProAccess SPACE 5.4.3.0. An attacker can write arbitrary content to arbitrary files, as demonstrated by CVE-2019-19458 files under the web root, or .bat files that will be used with auto start. This allows an attacker to execute arbitrary…

  • CVE-2013-3073CriNov 14, 2019
    risk 0.64cvss 9.8epss 0.04

    A Symlink Traversal vulnerability exists in NETGEAR Centria WNDR4700 Firmware 1.0.0.34.

  • CVE-2013-4657CriNov 13, 2019
    risk 0.64cvss 9.8epss 0.02

    Symlink Traversal vulnerability in NETGEAR WNR3500U and WNR3500L due to misconfiguration in the SMB service.

  • CVE-2013-4654CriNov 13, 2019
    risk 0.64cvss 9.8epss 0.03

    Symlink Traversal vulnerability in TP-LINK TL-WDR4300 and TL-1043ND..

  • CVE-2013-4656CriNov 13, 2019
    risk 0.64cvss 9.8epss 0.02

    Symlink Traversal vulnerability in ASUS RT-AC66U and RT-N56U due to misconfiguration in the SMB service.

  • CVE-2019-13551CriOct 31, 2019
    risk 0.64cvss 9.8epss 0.05

    Advantech WISE-PaaS/RMM, Versions 3.3.29 and prior. Path traversal vulnerabilities are caused by a lack of proper validation of a user-supplied path prior to use in file operations. An attacker can leverage these vulnerabilities to remotely execute code while posing as an…

  • CVE-2009-3887CriOct 29, 2019
    risk 0.64cvss 9.8epss 0.03

    ytnef has directory traversal

  • CVE-2019-18189CriOct 28, 2019
    risk 0.64cvss 9.8epss 0.05

    A directory traversal vulnerability in Trend Micro Apex One, OfficeScan (11.0, XG) and Worry-Free Business Security (9.5, 10.0) may allow an attacker to bypass authentication and log on to an affected product's management console as a root user. The vulnerability does not…

  • CVE-2013-4658CriOct 25, 2019
    risk 0.64cvss 9.8epss 0.09

    Linksys EA6500 has SMB Symlink Traversal allowing symbolic links to be created to locations outside of the Samba share.

  • CVE-2019-17399CriOct 9, 2019
    risk 0.64cvss 9.8epss 0.02

    The Shack Forms Pro extension before 4.0.32 for Joomla! allows path traversal via a file attachment.