VYPR

CWE-22

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')

BaseStableLikelihood: High

Description

The product uses external input to construct a pathname that is intended to identify a file or directory that is located underneath a restricted parent directory, but the product does not properly neutralize special elements within the pathname that can cause the pathname to resolve to a location that is outside of the restricted directory.

Hierarchy (View 1000)

Parents

Children

Related attack patterns (CAPEC)

CAPEC-126 · CAPEC-64 · CAPEC-76 · CAPEC-78 · CAPEC-79

CVEs mapped to this weakness (10,483)

page 270 of 525
  • CVE-2022-1554HigMay 3, 2022
    risk 0.42cvss 7.5epss 0.01

    Path Traversal due to `send_file` call in GitHub repository clinical-genomics/scout prior to 4.52.

  • CVE-2022-24897HigMay 2, 2022
    risk 0.42cvss 7.5epss 0.02

    APIs to evaluate content with Velocity is a package for APIs to evaluate content with Velocity. Starting with version 2.3 and prior to 12.6.7, 12.10.3, and 13.0, the velocity scripts are not properly sandboxed against using the Java File API to perform read or write operations…

  • CVE-2022-29970HigMay 2, 2022
    risk 0.42cvss 7.5epss 0.02

    Sinatra before 2.2.0 does not validate that the expanded path matches public_dir when serving static files.

  • CVE-2022-23457HigApr 25, 2022
    risk 0.42cvss 7.5epss 0.03

    ESAPI (The OWASP Enterprise Security API) is a free, open source, web application security control library. Prior to version 2.3.0.0, the default implementation of `Validator.getValidDirectoryPath(String, String, File, boolean)` may incorrectly treat the tested input string as a…

  • CVE-2022-20790MedApr 21, 2022
    risk 0.42cvss 6.5epss 0.02

    A vulnerability in the web-based management interface of Cisco Unified Communications Manager (Unified CM) and Cisco Unified Communications Manager Session Management Edition (Unified CM SME) could allow an authenticated, remote attacker to read arbitrary files from the…

  • CVE-2021-37293MedApr 11, 2022
    risk 0.42cvss 6.5epss 0.01

    A Directory Traversal vulnerability exists in KevinLAB Inc Building Energy Management System 4ST BEMS 1.0.0 via the page GET parameter in index.php.

  • CVE-2021-41026MedApr 6, 2022
    risk 0.42cvss 6.5epss 0.01

    A relative path traversal in FortiWeb versions 6.4.1, 6.4.0, and 6.3.0 through 6.3.15 may allow an authenticated attacker to retrieve arbitrary files from the underlying filesystem via specially crafted web requests.

  • CVE-2022-27248MedApr 3, 2022
    risk 0.42cvss 6.5epss 0.03

    A directory traversal vulnerability in IdeaRE RefTree before 2021.09.17 allows remote authenticated users to download arbitrary .dwg files from a remote server by specifying an absolute or relative path when invoking the affected DownloadDwg endpoint. An attack uses the path…

  • CVE-2022-28157MedMar 29, 2022
    risk 0.42cvss 6.5epss 0.01

    Jenkins Pipeline: Phoenix AutoTest Plugin 1.3 and earlier allows attackers with Item/Configure permission to upload arbitrary files from the Jenkins controller via FTP to an attacker-specified FTP server.

  • CVE-2022-28156MedMar 29, 2022
    risk 0.42cvss 6.5epss 0.02

    Jenkins Pipeline: Phoenix AutoTest Plugin 1.3 and earlier allows attackers with Item/Configure permission to copy arbitrary files and directories from the Jenkins controller to the agent workspace.

  • CVE-2022-28148MedMar 29, 2022
    risk 0.42cvss 6.5epss 0.02

    The file browser in Jenkins Continuous Integration with Toad Edge Plugin 2.3 and earlier may interpret some paths to files as absolute on Windows, resulting in a path traversal vulnerability allowing attackers with Item/Read permission to obtain the contents of arbitrary files…

  • CVE-2022-26252MedMar 27, 2022
    risk 0.42cvss 6.5epss 0.02

    aaPanel v6.8.21 was discovered to be vulnerable to directory traversal. This vulnerability allows attackers to obtain the root user private SSH key(id_rsa).

  • CVE-2022-27208MedMar 15, 2022
    risk 0.42cvss 6.5epss 0.02

    Jenkins Kubernetes Continuous Deploy Plugin 2.3.1 and earlier allows users with Credentials/Create permission to read arbitrary files on the Jenkins controller.

  • CVE-2022-27203MedMar 15, 2022
    risk 0.42cvss 6.5epss 0.02

    Jenkins Extended Choice Parameter Plugin 346.vd87693c5a_86c and earlier allows attackers with Item/Configure permission to read values from arbitrary JSON and Java properties files on the Jenkins controller.

  • CVE-2021-24692MedMar 14, 2022
    risk 0.42cvss 6.5epss 0.01

    The Simple Download Monitor WordPress plugin before 3.9.5 allows users with a role as low as Contributor to download any file on the web server (such as wp-config.php) via a path traversal vector.

  • CVE-2022-25511MedMar 11, 2022
    risk 0.42cvss 6.5epss 0.01

    An issue in the ?filename= argument of the route /DataPackageTable in FreeTAKServer-UI v1.9.8 allows attackers to place arbitrary files anywhere on the system.

  • CVE-2022-21132MedMar 10, 2022
    risk 0.42cvss 6.5epss 0.02

    Directory traversal vulnerability in pfSense-pkg-WireGuard pfSense-pkg-WireGuard 0.1.5 versions prior to 0.1.5_4 and pfSense-pkg-WireGuard 0.1.6 versions prior to 0.1.6_1 allows a remote authenticated attacker to lead a pfSense user to view a file outside the public folder.

  • CVE-2021-24820MedFeb 28, 2022
    risk 0.42cvss 6.5epss 0.03

    The Cost Calculator WordPress plugin through 1.6 allows authenticated users (Contributor+ in versions < 1.5, and Admin+ in versions <= 1.6) to perform path traversal and local PHP file inclusion on Windows Web Servers via the Cost Calculator post's Layout

  • CVE-2022-23135MedFeb 24, 2022
    risk 0.42cvss 6.5epss 0.01

    There is a directory traversal vulnerability in some home gateway products of ZTE. Due to the lack of verification of user modified destination path, an attacker with specific permissions could modify the FTP access path to access and modify the system path contents without…

  • CVE-2021-40841MedFeb 18, 2022
    risk 0.42cvss 6.5epss 0.01

    A Path Traversal vulnerability for a log file in LiveConfig 2.12.2 allows authenticated attackers to read files on the underlying server.