VYPR

CWE-22

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')

BaseStableLikelihood: High

Description

The product uses external input to construct a pathname that is intended to identify a file or directory that is located underneath a restricted parent directory, but the product does not properly neutralize special elements within the pathname that can cause the pathname to resolve to a location that is outside of the restricted directory.

Hierarchy (View 1000)

Parents

Children

Related attack patterns (CAPEC)

CAPEC-126 · CAPEC-64 · CAPEC-76 · CAPEC-78 · CAPEC-79

CVEs mapped to this weakness (10,483)

page 277 of 525
  • CVE-2020-10977MedApr 8, 2020
    risk 0.42cvss 5.5epss 0.43

    GitLab EE/CE 8.5 to 12.9 is vulnerable to a an path traversal when moving an issue between projects.

  • CVE-2020-4240MedMar 31, 2020
    risk 0.42cvss 6.5epss 0.02

    IBM Spectrum Protect Plus 10.1.0 through 10.1.5 could allow a remote attacker to traverse directories on the system. An attacker could send a specially-crafted URL request to overwrite or create arbitrary files on the system. IBM X-Force ID: 175417.

  • CVE-2019-19486MedMar 20, 2020
    risk 0.42cvss 6.5epss 0.02

    Local File Inclusion in minPlayCommand.php in Centreon (19.04.4 and below) allows an attacker to traverse paths via a plugin test.

  • CVE-2020-10458MedMar 12, 2020
    risk 0.42cvss 6.5epss 0.02

    Path Traversal in admin/imagepaster/operations.php in Chadha PHPKB Standard Multi-Language 9 allows attackers to delete any folder on the webserver using a dot-dot-slash sequence (../) via the GET parameter crdir, when the GET parameter action is set to df, causing a Denial of…

  • CVE-2019-19290MedMar 10, 2020
    risk 0.42cvss 6.5epss 0.02

    A vulnerability has been identified in Control Center Server (CCS) (All versions < V1.5.0). The DOWNLOADS section in the web interface of the Control Center Server (CCS) contains a path traversal vulnerability that could allow an authenticated remote attacker to access and…

  • CVE-2020-1737HigMar 9, 2020
    risk 0.42cvss 7.5epss 0.00

    A flaw was found in Ansible 2.7.17 and prior, 2.8.9 and prior, and 2.9.6 and prior when using the Extract-Zip function from the win_unzip module as the extracted file(s) are not checked if they belong to the destination folder. An attacker could take advantage of this flaw by…

  • CVE-2020-1853MedFeb 17, 2020
    risk 0.42cvss 6.5epss 0.01

    GaussDB 200 with version of 6.5.1 have a path traversal vulnerability. Due to insufficient input path validation, an authenticated attacker can traverse directories and download files to a specific directory. Successful exploit may cause information leakage.

  • CVE-2020-9033MedFeb 17, 2020
    risk 0.42cvss 6.5epss 0.01

    Symmetricom SyncServer S100 2.90.70.3, S200 1.30, S250 1.25, S300 2.65.0, and S350 2.80.1 devices allow Directory Traversal via the FileName parameter to authlog.php.

  • CVE-2020-9032MedFeb 17, 2020
    risk 0.42cvss 6.5epss 0.01

    Symmetricom SyncServer S100 2.90.70.3, S200 1.30, S250 1.25, S300 2.65.0, and S350 2.80.1 devices allow Directory Traversal via the FileName parameter to kernlog.php.

  • CVE-2020-9031MedFeb 17, 2020
    risk 0.42cvss 6.5epss 0.01

    Symmetricom SyncServer S100 2.90.70.3, S200 1.30, S250 1.25, S300 2.65.0, and S350 2.80.1 devices allow Directory Traversal via the FileName parameter to daemonlog.php.

  • CVE-2020-9030MedFeb 17, 2020
    risk 0.42cvss 6.5epss 0.01

    Symmetricom SyncServer S100 2.90.70.3, S200 1.30, S250 1.25, S300 2.65.0, and S350 2.80.1 devices allow Directory Traversal via the FileName parameter to the syslog.php.

  • CVE-2020-9029MedFeb 17, 2020
    risk 0.42cvss 6.5epss 0.01

    Symmetricom SyncServer S100 2.90.70.3, S200 1.30, S250 1.25, S300 2.65.0, and S350 2.80.1 devices allow Directory Traversal via the FileName parameter to messagelog.php.

  • CVE-2015-3309HigFeb 13, 2020
    risk 0.42cvss 7.5epss 0.02

    Directory traversal vulnerability in node/utils/Minify.js in Etherpad 1.1.2 through 1.5.4 allows remote attackers to read arbitrary files with permissions of the user running the service via a .. (dot dot) in the path parameter of HTTP API requests. NOTE: This vulnerability is…

  • CVE-2020-5221MedJan 22, 2020
    risk 0.42cvss 6.5epss 0.01

    In uftpd before 2.11, it is possible for an unauthenticated user to perform a directory traversal attack using multiple different FTP commands and read and write to arbitrary locations on the filesystem due to the lack of a well-written chroot jail in compose_abspath(). This has…

  • CVE-2019-14766MedJan 21, 2020
    risk 0.42cvss 6.5epss 0.01

    Path Traversal in the file browser of DIMO YellowBox CRM before 6.3.4 allows a standard authenticated user to browse the server filesystem.

  • CVE-2020-5840HigJan 6, 2020
    risk 0.42cvss 7.5epss 0.01

    An issue was discovered in HashBrown CMS before 1.3.2. Server/Entity/Resource/Connection.js allows an attacker to reach a parent directory via a crafted name or ID field.

  • CVE-2019-6022MedDec 26, 2019
    risk 0.42cvss 6.5epss 0.02

    Directory traversal vulnerability in Cybozu Office 10.0.0 to 10.8.3 allows remote authenticated attackers to alter arbitrary files via the 'Customapp' function.

  • CVE-2019-19229MedDec 4, 2019
    risk 0.42cvss 6.5epss 0.02

    admincgi-bin/service.fcgi on Fronius Solar Inverter devices before 3.14.1 (HM 1.12.1) allows action=download&filename= Directory Traversal.

  • CVE-2019-16765HigNov 25, 2019
    risk 0.42cvss 7.4epss 0.05

    If an attacker can get a user to open a specially prepared directory tree as a workspace in Visual Studio Code with the CodeQL extension active, arbitrary code of the attacker's choosing may be executed on the user's behalf. This is fixed in version 1.0.1 of the extension. Users…

  • CVE-2019-10767HigNov 21, 2019
    risk 0.42cvss 7.5epss 0.02

    An attacker can include file contents from outside the `/adapter/xxx/` directory, where `xxx` is the name of an existent adapter like "admin". It is exploited using the administrative web panel with a request for an adapter file. **Note:** The attacker has to be logged in if the…