VYPR

CWE-22

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')

BaseStableLikelihood: High

Description

The product uses external input to construct a pathname that is intended to identify a file or directory that is located underneath a restricted parent directory, but the product does not properly neutralize special elements within the pathname that can cause the pathname to resolve to a location that is outside of the restricted directory.

Hierarchy (View 1000)

Parents

Children

Related attack patterns (CAPEC)

CAPEC-126 · CAPEC-64 · CAPEC-76 · CAPEC-78 · CAPEC-79

CVEs mapped to this weakness (10,483)

page 273 of 525
  • CVE-2021-37728MedSep 7, 2021
    risk 0.42cvss 6.5epss 0.01

    A remote path traversal vulnerability was discovered in Aruba Operating System Software version(s): Prior to 8.8.0.1, 8.7.1.4, 8.6.0.11, 8.5.0.13. Aruba has released patches for ArubaOS that address this security vulnerability.

  • CVE-2020-18127MedAug 30, 2021
    risk 0.42cvss 6.5epss 0.01

    An issue in the /config/config.php component of Indexhibit 2.1.5 allows attackers to arbitrarily view files.

  • CVE-2020-19547MedAug 25, 2021
    risk 0.42cvss 6.5epss 0.01

    Directory Traversal vulnerability exists in PopojiCMS 2.0.1 via the id parameter in admin.php.

  • CVE-2020-23069MedAug 18, 2021
    risk 0.42cvss 6.5epss 0.02

    Path Traversal vulneraility exists in webTareas 2.0 via the extpath parameter in general_serv.php, which could let a malicious user read arbitrary files.

  • CVE-2021-22933MedAug 16, 2021
    risk 0.42cvss 6.5epss 0.01

    A vulnerability in Pulse Connect Secure before 9.1R12 could allow an authenticated administrator to perform an arbitrary file delete via a maliciously crafted web request.

  • CVE-2021-27402MedAug 13, 2021
    risk 0.42cvss 6.5epss 0.01

    The SAS Admin portal of Mitel MiCollab before 9.2 FP2 could allow an unauthenticated attacker to access (view and modify) user data by injecting arbitrary directory paths due to improper URL validation, aka Directory Traversal.

  • CVE-2021-31731MedAug 12, 2021
    risk 0.42cvss 6.5epss 0.01

    A directory traversal issue in KiteCMS 1.1.1 allows remote administrators to overwrite arbitrary files via ../ in the path parameter to index.php/admin/Template/fileedit, with PHP code in the html parameter.

  • CVE-2021-22674MedAug 10, 2021
    risk 0.42cvss 6.5epss 0.01

    The affected product is vulnerable to a relative path traversal condition, which may allow an attacker access to unauthorized files and directories on the WebAccess/SCADA (WebAccess/SCADA versions prior to 8.4.5, WebAccess/SCADA versions prior to 9.0.1).

  • CVE-2021-21501HigAug 10, 2021
    risk 0.42cvss 7.5epss 0.04

    Improper configuration will cause ServiceComb ServiceCenter Directory Traversal problem in ServcieCenter 1.x.x versions and fixed in 2.0.0.

  • CVE-2021-38136MedAug 6, 2021
    risk 0.42cvss 6.5epss 0.01

    Corero SecureWatch Managed Services 9.7.2.0020 is affected by a Path Traversal vulnerability via the snap_file parameter in the /it-IT/splunkd/__raw/services/get_snapshot HTTP API endpoint. A ‘low privileged’ attacker can read any file on the target host.

  • CVE-2021-34638MedAug 5, 2021
    risk 0.42cvss 6.5epss 0.01

    Authenticated Directory Traversal in WordPress Download Manager <= 3.1.24 allows authenticated (Contributor+) users to obtain sensitive configuration file information, as well as allowing Author+ users to perform XSS attacks, by setting Download template to a file containing…

  • CVE-2021-36168MedAug 4, 2021
    risk 0.42cvss 6.5epss 0.01

    A Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') in Fortinet FortiPortal 6.x before 6.0.5, FortiPortal 5.3.x before 5.3.6 and any FortiPortal before 6.2.5 allows authenticated attacker to disclosure information via crafted GET request with…

  • CVE-2021-23415HigJul 28, 2021
    risk 0.42cvss 7.5epss 0.02

    This affects the package elFinder.AspNet before 1.1.1. The user-controlled file name is not properly sanitized before it is used to create a file system path.

  • CVE-2021-37445MedJul 25, 2021
    risk 0.42cvss 6.5epss 0.01

    In NCH Quorum v2.03 and earlier, an authenticated user can use directory traversal via logprop?file=/.. for file reading.

  • CVE-2021-37442MedJul 25, 2021
    risk 0.42cvss 6.5epss 0.01

    NCH IVM Attendant v5.12 and earlier allows path traversal via viewfile?file=/.. to read files.

  • CVE-2021-37440MedJul 25, 2021
    risk 0.42cvss 6.5epss 0.01

    NCH Axon PBX v2.22 and earlier allows path traversal for file disclosure via the logprop?file=/.. substring.

  • CVE-2021-37439MedJul 25, 2021
    risk 0.42cvss 6.5epss 0.01

    NCH FlexiServer v6.00 suffers from a syslog?file=/.. path traversal vulnerability.

  • CVE-2021-37469MedJul 25, 2021
    risk 0.42cvss 6.5epss 0.01

    In NCH WebDictate v2.13 and earlier, authenticated users can abuse logprop?file=/.. path traversal to read files on the filesystem.

  • CVE-2021-1617MedJul 22, 2021
    risk 0.42cvss 6.5epss 0.02

    Multiple vulnerabilities in the web-based management interface of Cisco Intersight Virtual Appliance could allow an authenticated, remote attacker to conduct a path traversal or command injection attack on an affected system. These vulnerabilities are due to insufficient input…

  • CVE-2021-32769HigJul 16, 2021
    risk 0.42cvss 7.5epss 0.02

    Micronaut is a JVM-based, full stack Java framework designed for building JVM applications. A path traversal vulnerability exists in versions prior to 2.5.9. With a basic configuration, it is possible to access any file from a filesystem, using "/../../" in the URL. This occurs…