VYPR

CWE-22

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')

BaseStableLikelihood: High

Description

The product uses external input to construct a pathname that is intended to identify a file or directory that is located underneath a restricted parent directory, but the product does not properly neutralize special elements within the pathname that can cause the pathname to resolve to a location that is outside of the restricted directory.

Hierarchy (View 1000)

Parents

Children

Related attack patterns (CAPEC)

CAPEC-126 · CAPEC-64 · CAPEC-76 · CAPEC-78 · CAPEC-79

CVEs mapped to this weakness (10,483)

page 275 of 525
  • CVE-2020-4789MedJan 27, 2021
    risk 0.42cvss 6.5epss 0.03

    IBM QRadar SIEM 7.4.2 GA to 7.4.2 Patch 1, 7.4.0 to 7.4.1 Patch 1, and 7.3.0 to 7.3.3 Patch 5 could allow a remote attacker to traverse directories on the system. An attacker could send a specially-crafted URL request containing "dot dot" sequences (/../) to view arbitrary files…

  • CVE-2020-23161MedJan 26, 2021
    risk 0.42cvss 6.5epss 0.02

    Local file inclusion in Pyrescom Termod4 time management devices before 10.04k allows authenticated remote attackers to traverse directories and read sensitive files via the Maintenance > Logs menu and manipulating the file-path in the URL.

  • CVE-2021-1357MedJan 20, 2021
    risk 0.42cvss 6.5epss 0.01

    Multiple vulnerabilities in Cisco Unified Communications Manager IM & Presence Service (Unified CM IM&P) could allow an attacker to conduct path traversal attacks and SQL injection attacks on an affected system. One of the SQL injection vulnerabilities that affects…

  • CVE-2021-1259MedJan 20, 2021
    risk 0.42cvss 6.5epss 0.02

    A vulnerability in the web-based management interface of Cisco SD-WAN vManage Software could allow an authenticated, remote attacker to conduct path traversal attacks and obtain write access to sensitive files on an affected system. The vulnerability is due to insufficient…

  • CVE-2021-3178MedJan 19, 2021
    risk 0.42cvss 6.5epss 0.02

    fs/nfsd/nfs3xdr.c in the Linux kernel through 5.10.8, when there is an NFS export of a subdirectory of a filesystem, allows remote attackers to traverse to other parts of the filesystem via READDIRPLUS. NOTE: some parties argue that such a subdirectory export is not intended to…

  • CVE-2020-5683HigDec 16, 2020
    risk 0.42cvss 7.5epss 0.03

    Directory traversal vulnerability in GROWI versions prior to v4.2.3 (v4.2 Series), GROWI versions prior to v4.1.12 (v4.1 Series), and GROWI v3 series and earlier GROWI versions prior to v4.2.3 (v4.2 Series), GROWI versions prior to v4.1.12 (v4.1 Series), and GROWI v3 series and…

  • CVE-2020-29529HigDec 3, 2020
    risk 0.42cvss 7.5epss 0.03

    HashiCorp go-slug up to 0.4.3 did not fully protect against directory traversal while unpacking tar archives, and protections could be bypassed with specific constructions of multiple symlinks. Fixed in 0.5.0.

  • CVE-2020-29373MedNov 28, 2020
    risk 0.42cvss 6.5epss 0.01

    An issue was discovered in fs/io_uring.c in the Linux kernel before 5.6. It unsafely handles the root directory during path lookups, and thus a process inside a mount namespace can escape to unintended filesystem locations, aka CID-ff002b30181d.

  • CVE-2020-15246HigNov 23, 2020
    risk 0.42cvss 7.5epss 0.02

    October is a free, open-source, self-hosted CMS platform based on the Laravel PHP Framework. In October CMS from version 1.0.421 and before version 1.0.469, an attacker can read local files on an October CMS server via a specially crafted request. Issue has been patched in Build…

  • CVE-2020-26078MedNov 18, 2020
    risk 0.42cvss 6.5epss 0.01

    A vulnerability in the file system of Cisco IoT Field Network Director (FND) could allow an authenticated, remote attacker to overwrite files on an affected system. The vulnerability is due to insufficient file system protections. An attacker could exploit this vulnerability by…

  • CVE-2020-7763HigNov 5, 2020
    risk 0.42cvss 7.5epss 0.02

    This affects the package phantom-html-to-pdf before 0.6.1.

  • CVE-2020-7758HigNov 2, 2020
    risk 0.42cvss 7.5epss 0.02

    This affects versions of package browserless-chrome before 1.40.2-chrome-stable. User input flowing from the workspace endpoint gets used to create a file path filePath and this is fetched and then sent back to a user. This can be escaped to fetch arbitrary files from a server.

  • CVE-2020-7757MedNov 2, 2020
    risk 0.42cvss 6.5epss 0.02

    This affects all versions of package droppy. It is possible to traverse directories to fetch configuration files from a droopy server.

  • CVE-2020-4782MedOct 28, 2020
    risk 0.42cvss 6.5epss 0.03

    IBM WebSphere Application Server 7.0, 8.0, 8.5, and 9.0 could allow a remote attacker to traverse directories on the system. An attacker could send a specially-crafted URL request containing "dot dot" sequences (/../) to view arbitrary files on the system.

  • CVE-2020-2293MedOct 8, 2020
    risk 0.42cvss 6.5epss 0.01

    Jenkins Persona Plugin 2.4 and earlier allows users with Overall/Read permission to read arbitrary files on the Jenkins controller.

  • CVE-2020-5789MedOct 1, 2020
    risk 0.42cvss 6.5epss 0.01

    Relative Path Traversal in Teltonika firmware TRB2_R_00.02.04.3 allows a remote, authenticated attacker to read the contents of arbitrary files on disk.

  • CVE-2020-5788MedOct 1, 2020
    risk 0.42cvss 6.5epss 0.01

    Relative Path Traversal in Teltonika firmware TRB2_R_00.02.04.3 allows a remote, authenticated attacker to delete arbitrary files on disk via the admin/system/admin/certificates/delete action.

  • CVE-2020-5787MedOct 1, 2020
    risk 0.42cvss 6.5epss 0.02

    Relative Path Traversal in Teltonika firmware TRB2_R_00.02.04.3 allows a remote, authenticated attacker to delete arbitrary files on disk via the admin/services/packages/remove action.

  • CVE-2020-3130MedSep 23, 2020
    risk 0.42cvss 6.5epss 0.02

    A vulnerability in the web management interface of Cisco Unity Connection could allow an authenticated remote attacker to overwrite files on the underlying filesystem. The vulnerability is due to insufficient input validation. An attacker could exploit this vulnerability by…

  • CVE-2020-2278MedSep 16, 2020
    risk 0.42cvss 6.5epss 0.01

    Jenkins Storable Configs Plugin 1.0 and earlier does not restrict the user-specified file name, allowing attackers with Job/Configure permission to replace any other '.xml' file on the Jenkins controller with a job config.xml file's content.