VYPR

CWE-22

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')

BaseStableLikelihood: High

Description

The product uses external input to construct a pathname that is intended to identify a file or directory that is located underneath a restricted parent directory, but the product does not properly neutralize special elements within the pathname that can cause the pathname to resolve to a location that is outside of the restricted directory.

Hierarchy (View 1000)

Parents

Children

Related attack patterns (CAPEC)

CAPEC-126 · CAPEC-64 · CAPEC-76 · CAPEC-78 · CAPEC-79

CVEs mapped to this weakness (10,395)

page 28 of 520
  • CVE-2019-16868CriSep 25, 2019
    risk 0.64cvss 9.8epss 0.03

    emlog through 6.0.0beta has an arbitrary file deletion vulnerability via an admin/data.php?action=dell_all_bak request with directory traversal sequences in the bak[] parameter.

  • CVE-2019-15822CriAug 30, 2019
    risk 0.64cvss 9.8epss 0.03

    The wps-child-theme-generator plugin before 1.2 for WordPress has classes/helpers.php directory traversal.

  • CVE-2019-1010151CriJul 19, 2019
    risk 0.64cvss 9.8epss 0.02

    zzcms zzmcms 8.3 and earlier is affected by: File Delete to getshell. The impact is: getshell. The component is: /user/ppsave.php.

  • CVE-2019-7253CriJul 2, 2019
    risk 0.64cvss 9.8epss 0.03

    Linear eMerge E3-Series devices allow Directory Traversal.

  • CVE-2019-12144CriJun 11, 2019
    risk 0.64cvss 9.8epss 0.03

    An issue was discovered in SSHServerAPI.dll in Progress ipswitch WS_FTP Server 2018 before 8.6.1. Attackers have the ability to abuse a path traversal vulnerability using the SCP protocol. Attackers who leverage this flaw could also obtain remote code execution by crafting a…

  • CVE-2019-9642CriJun 5, 2019
    risk 0.64cvss 9.8epss 0.02

    An issue was discovered in proxy.php in pydio-core in Pydio through 8.2.2. Through an unauthenticated request, it possible to evaluate malicious PHP code by placing it on the fourth line of a .php file, as demonstrated by a PoC.php created by the guest account, with execution…

  • CVE-2019-12310CriJun 3, 2019
    risk 0.64cvss 9.8epss 0.03

    ExaGrid appliances with firmware version v4.8.1.1044.P50 have a /monitor/data/Upgrade/ directory traversal vulnerability, which allows remote attackers to view and retrieve verbose logging information. Files within this directory were observed to contain sensitive run-time…

  • CVE-2019-9106CriMay 31, 2019
    risk 0.64cvss 9.8epss 0.03

    The WebApp v04.68 in the supervisor on SAET Impianti Speciali TEBE Small 05.01 build 1137 devices allows remote attackers to execute or include local .php files, as demonstrated by menu=php://filter/convert.base64-encode/resource=index.php to read index.php.

  • CVE-2016-10759CriMay 24, 2019
    risk 0.64cvss 9.8epss 0.04

    The Xinha plugin in Precurio 2.1 allows Directory Traversal, with resultant arbitrary code execution, via ExtendedFileManager/Classes/ExtendedFileManager.php because ExtendedFileManager can be used to rename the .htaccess file that blocks .php uploads.

  • CVE-2019-7106CriMay 23, 2019
    risk 0.64cvss 9.8epss 0.08

    Adobe XD versions 16.0 and earlier have a path traversal vulnerability. Successful exploitation could lead to arbitrary code execution.

  • CVE-2019-7105CriMay 23, 2019
    risk 0.64cvss 9.8epss 0.08

    Adobe XD versions 16.0 and earlier have a path traversal vulnerability. Successful exploitation could lead to arbitrary code execution.

  • CVE-2018-6885CriMay 14, 2019
    risk 0.64cvss 9.8epss 0.01

    An issue was discovered in MicroStrategy Web Services (the Microsoft Office plugin) before 10.4 Hotfix 7, and before 10.11. The vulnerability is unauthenticated and leads to access to the asset files with the MicroStrategy user privileges. (This includes the credentials to…

  • CVE-2015-9287CriMay 13, 2019
    risk 0.64cvss 9.8epss 0.02

    Directory Traversal was discovered in University of Cambridge mod_ucam_webauth before 2.0.2. The key identification field ("kid") of the IdP's HTTP response message ("WLS-Response") can be manipulated by an attacker. The "kid" field is not signed like the rest of the message,…

  • CVE-2012-6652CriMay 13, 2019
    risk 0.64cvss 9.8epss 0.04

    Directory traversal vulnerability in pageflipbook.php script from index.php in Page Flip Book plugin for WordPress (wppageflip) allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the pageflipbook_language parameter.

  • CVE-2018-20525CriMar 21, 2019
    risk 0.64cvss 9.1epss 0.22

    Roxy Fileman 1.4.5 allows Directory Traversal in copydir.php, copyfile.php, and fileslist.php.

  • CVE-2019-8395CriFeb 17, 2019
    risk 0.64cvss 9.8epss 0.07

    An Insecure Direct Object Reference (IDOR) vulnerability exists in Zoho ManageEngine ServiceDesk Plus (SDP) before 10.0 build 10007 via an attachment to a request.

  • CVE-2019-7678CriFeb 9, 2019
    risk 0.64cvss 9.8epss 0.02

    A directory traversal vulnerability was discovered in Enphase Envoy R3.*.* via images/, include/, include/js, or include/css on TCP port 8888.

  • CVE-2019-7160CriJan 29, 2019
    risk 0.64cvss 9.8epss 0.03

    idreamsoft iCMS 7.0.13 allows admincp.php?app=files ../ Directory Traversal via the udir parameter to files.admincp.php, resulting in execution of arbitrary PHP code from a ZIP file via the admincp.php?app=apps zipfile parameter to apps.admincp.php.

  • CVE-2018-19328CriNov 17, 2018
    risk 0.64cvss 9.8epss 0.02

    LAOBANCMS 2.0 allows install/mysql_hy.php?riqi=../ Directory Traversal.

  • CVE-2018-18869CriOct 31, 2018
    risk 0.64cvss 9.8epss 0.04

    EmpireCMS V7.5 allows remote attackers to upload and execute arbitrary code via ..%2F directory traversal in a .php filename in the upload/e/admin/ecmscom.php path parameter.