VYPR

CWE-22

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')

BaseStableLikelihood: High

Description

The product uses external input to construct a pathname that is intended to identify a file or directory that is located underneath a restricted parent directory, but the product does not properly neutralize special elements within the pathname that can cause the pathname to resolve to a location that is outside of the restricted directory.

Hierarchy (View 1000)

Parents

Children

Related attack patterns (CAPEC)

CAPEC-126 · CAPEC-64 · CAPEC-76 · CAPEC-78 · CAPEC-79

CVEs mapped to this weakness (10,483)

page 278 of 525
  • CVE-2019-3662MedNov 14, 2019
    risk 0.42cvss 6.5epss 0.01

    Path Traversal: '/absolute/pathname/here' vulnerability in McAfee Advanced Threat Defense (ATD) prior to 4.8 allows remote authenticated attacker to gain unintended access to files on the system via carefully constructed HTTP requests.

  • CVE-2019-16876HigNov 7, 2019
    risk 0.42cvss 7.5epss 0.01

    Portainer before 1.22.1 allows Directory Traversal.

  • CVE-2019-17324MedOct 30, 2019
    risk 0.42cvss 6.5epss 0.01

    ClipSoft REXPERT 1.0.0.527 and earlier version allows directory traversal by issuing a special HTTP POST request with ../ characters. This could lead to create malicious HTML file, because they can inject a content with crafted template. User interaction is required to exploit…

  • CVE-2019-17322MedOct 30, 2019
    risk 0.42cvss 6.5epss 0.01

    ClipSoft REXPERT 1.0.0.527 and earlier version allows arbitrary file creation via a POST request with the parameter set to the file path to be written. This can be an executable file that is written to in the arbitrary directory. User interaction is required to exploit this…

  • CVE-2019-14424MedOct 17, 2019
    risk 0.42cvss 6.5epss 0.01

    A Local File Inclusion (LFI) issue in the addon CUx-Daemon 1.11a of the eQ-3 Homematic CCU-Firmware 2.35.16 until 2.45.6 allows remote authenticated attackers to read sensitive files via a simple HTTP Request.

  • CVE-2019-12704MedOct 16, 2019
    risk 0.42cvss 6.5epss 0.02

    A vulnerability in the web-based management interface of Cisco SPA100 Series Analog Telephone Adapters (ATAs) could allow an authenticated, remote attacker to view the contents of arbitrary files on an affected device. The vulnerability is due to improper input validation in the…

  • CVE-2019-16198MedOct 3, 2019
    risk 0.42cvss 6.5epss 0.02

    KSLabs KSWEB 3.93 allows ../ directory traversal, as demonstrated by the hostFile parameter.

  • CVE-2019-17073MedOct 1, 2019
    risk 0.42cvss 6.5epss 0.02

    emlog through 6.0.0beta allows remote authenticated users to delete arbitrary files via admin/template.php?action=del&tpl=../ directory traversal.

  • CVE-2019-7618MedOct 1, 2019
    risk 0.42cvss 6.5epss 0.01

    A local file disclosure flaw was found in Elastic Code versions 7.3.0, 7.3.1, and 7.3.2. If a malicious code repository is imported into Code it is possible to read arbitrary files from the local filesystem of the Kibana instance running Code with the permission of the Kibana…

  • CVE-2019-16867MedSep 25, 2019
    risk 0.42cvss 6.5epss 0.01

    HongCMS 3.0.0 allows arbitrary file deletion via a ../ in the file parameter to admin/index.php/database/ajax?action=delete, a similar issue to CVE-2018-16774. (If the attacker deletes config.php and visits install/index.php, they can reinstall the product.)

  • CVE-2018-1847MedSep 18, 2019
    risk 0.42cvss 6.5epss 0.02

    IBM Financial Transaction Manager (FTM) for Multi-Platform (MP) v2.0.0.0 through 2.0.0.5, v2.1.0.0 through 2.1.0.4, v2.1.1.0 through 2.1.1.4, and v3.0.0.0 through 3.0.0.8 could allow a remote attacker to traverse directories on the system. An attacker could send a…

  • CVE-2016-10977MedSep 17, 2019
    risk 0.42cvss 6.5epss 0.02

    The nelio-ab-testing plugin before 4.5.0 for WordPress has filename=..%2f directory traversal.

  • CVE-2019-5484HigSep 13, 2019
    risk 0.42cvss 7.5epss 0.03

    Bower before 1.8.8 has a path traversal vulnerability permitting file write in arbitrary locations via install command, which allows attackers to write arbitrary files when a malicious package is extracted.

  • CVE-2019-5956MedSep 12, 2019
    risk 0.42cvss 6.5epss 0.02

    Directory traversal vulnerability in WonderCMS 2.6.0 and earlier allows remote attackers to delete arbitrary files via unspecified vectors.

  • CVE-2019-15648MedAug 27, 2019
    risk 0.42cvss 6.5epss 0.01

    The insert-or-embed-articulate-content-into-wordpress plugin before 4.29991 for WordPress has insufficient restrictions on deleting or renaming by a Subscriber.

  • CVE-2019-15055MedAug 26, 2019
    risk 0.42cvss 6.5epss 0.02

    MikroTik RouterOS through 6.44.5 and 6.45.x through 6.45.3 improperly handles the disk name, which allows authenticated users to delete arbitrary files. Attackers can exploit this vulnerability to reset credential storage, which allows them access to the management interface as…

  • CVE-2019-14751HigAug 22, 2019
    risk 0.42cvss 7.5epss 0.06

    NLTK Downloader before 3.4.5 is vulnerable to a directory traversal, allowing attackers to write arbitrary files via a ../ (dot dot slash) in an NLTK package (ZIP archive) that is mishandled during extraction.

  • CVE-2019-10375MedAug 7, 2019
    risk 0.42cvss 6.5epss 0.01

    An arbitrary file read vulnerability in Jenkins File System SCM Plugin 2.1 and earlier allows attackers able to configure jobs in Jenkins to obtain the contents of any file on the Jenkins master.

  • CVE-2019-7859HigAug 2, 2019
    risk 0.42cvss 7.5epss 0.01

    A path traversal vulnerability in the WYSIWYG editor for Magento 2.1 prior to 2.1.18, Magento 2.2 prior to 2.2.9, Magento 2.3 prior to 2.3.2 could result in unauthorized access to uploaded images due to insufficient access control.

  • CVE-2019-5221MedJul 10, 2019
    risk 0.42cvss 6.5epss 0.00

    There is a path traversal vulnerability on Huawei Share. The software does not properly validate the path, an attacker could crafted a file path when transporting file through Huawei Share, successful exploit could allow the attacker to transport a file to arbitrary path on the…