VYPR

CWE-22

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')

BaseStableLikelihood: High

Description

The product uses external input to construct a pathname that is intended to identify a file or directory that is located underneath a restricted parent directory, but the product does not properly neutralize special elements within the pathname that can cause the pathname to resolve to a location that is outside of the restricted directory.

Hierarchy (View 1000)

Parents

Children

Related attack patterns (CAPEC)

CAPEC-126 · CAPEC-64 · CAPEC-76 · CAPEC-78 · CAPEC-79

CVEs mapped to this weakness (10,483)

page 305 of 525
  • CVE-2022-43748MedOct 26, 2022
    risk 0.38cvss 5.8epss 0.01

    Improper limitation of a pathname to a restricted directory ('Path Traversal') vulnerability in file operation management in Synology Presto File Server before 2.1.2-1601 allows remote attackers to write arbitrary files via unspecified vectors.

  • CVE-2022-34836MedAug 24, 2022
    risk 0.38cvss 5.9epss 0.01

    Relative Path Traversal vulnerability in ABB Zenon 8.20 allows the user to access files on the Zenon system and user also can add own log messages and e.g., flood the log entries. An attacker who successfully exploit the vulnerability could access the Zenon runtime activities…

  • CVE-2022-34762MedJul 13, 2022
    risk 0.38cvss 5.9epss 0.01

    A CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability exists that could cause unauthorized firmware image loading when unsigned images are added to the firmware image path. Affected Products: X80 advanced RTU Communication Module…

  • CVE-2022-31062MedJun 20, 2022
    risk 0.38cvss 5.3epss 0.06

    ### Impact A plugin public script can be used to read content of system files. ### Patches Upgrade to version 1.0.2. ### Workarounds `b/deploy/index.php` file can be deleted if deploy feature is not used.

  • CVE-2022-28541MedApr 11, 2022
    risk 0.38cvss 5.9epss 0.00

    Uncontrolled search path element vulnerability in Samsung Update prior to version 3.0.77.0 allows attackers to execute arbitrary code as Samsung Update permission.

  • CVE-2022-27906MedMar 25, 2022
    risk 0.38cvss 5.9epss 0.01

    Mendelson OFTP2 before 1.1 b43 is affected by directory traversal. To access the vulnerable code path, the attacker has to know one of the configured Odette IDs of the OFTP2 server. An attacker can upload files to the server outside of the intended upload directory.

  • CVE-2021-35521MedJul 22, 2021
    risk 0.38cvss 5.9epss 0.01

    A path traversal in Thrift command handlers in IDEMIA Morpho Wave Compact and VisionPass devices before 2.6.2 allows remote authenticated attackers to achieve denial of services and information disclosure via TCP/IP packets.

  • CVE-2020-2504MedDec 24, 2020
    risk 0.38cvss 5.8epss 0.01

    If exploited, this absolute path traversal vulnerability could allow attackers to traverse files in File Station. QNAP has already fixed these issues in QES 2.1.1 Build 20201006 and later.

  • CVE-2020-5720MedFeb 6, 2020
    risk 0.38cvss 5.9epss 0.01

    MikroTik WinBox before 3.21 is vulnerable to a path traversal vulnerability that allows creation of arbitrary files wherevere WinBox has write permissions. WinBox is vulnerable to this attack if it connects to a malicious endpoint or if an attacker mounts a man in the middle…

  • CVE-2018-20251MedFeb 5, 2019
    risk 0.38cvss 5.5epss 0.31

    In WinRAR versions prior to and including 5.61, there is path traversal vulnerability when crafting the filename field of the ACE format. The UNACE module (UNACEV2.dll) creates files and folders as written in the filename field even when WinRAR validator noticed the traversal…

  • CVE-2018-18990MedFeb 5, 2019
    risk 0.38cvss 5.3epss 0.39

    LCDS Laquis SCADA prior to version 4.1.0.4150 allows a user-supplied path in file operations prior to proper validation. An attacker can leverage this vulnerability to disclose sensitive information under the context of the web server process.

  • CVE-2018-19043MedJan 31, 2019
    risk 0.38cvss 5.3epss 0.10

    The Media File Manager plugin 1.4.2 for WordPress allows arbitrary file renaming (specifying a "from" and "to" filename) via a ../ directory traversal in the dir parameter of an mrelocator_rename action to the wp-admin/admin-ajax.php URI.

  • CVE-2018-19042MedJan 31, 2019
    risk 0.38cvss 5.3epss 0.10

    The Media File Manager plugin 1.4.2 for WordPress allows arbitrary file movement via a ../ directory traversal in the dir_from and dir_to parameters of an mrelocator_move action to the wp-admin/admin-ajax.php URI.

  • CVE-2018-19040MedJan 31, 2019
    risk 0.38cvss 5.3epss 0.12

    The Media File Manager plugin 1.4.2 for WordPress allows directory listing via a ../ directory traversal in the dir parameter of an mrelocator_getdir action to the wp-admin/admin-ajax.php URI.

  • CVE-2017-6020MedApr 17, 2018
    risk 0.38cvss 5.3epss 0.08

    Leao Consultoria e Desenvolvimento de Sistemas (LCDS) LTDA ME LAquis SCADA software versions prior to version 4.1.0.3237 do not neutralize external input to ensure that users are not calling for absolute path sequences outside of their privilege level.

  • CVE-2017-9965MedJan 2, 2018
    risk 0.38cvss 5.8epss 0.05

    An exposure of sensitive information vulnerability exists in Schneider Electric's Pelco VideoXpert Enterprise versions 2.0 and prior. Using a directory traversal attack, an unauthorized person can view web server files.

  • CVE-2017-6805MedMar 20, 2017
    risk 0.38cvss 5.3epss 0.08

    Directory traversal vulnerability in the TFTP server in MobaXterm Personal Edition 9.4 allows remote attackers to read arbitrary files via a .. (dot dot) in a GET command.

  • CVE-2026-82264MedAug 28, 2026
    risk 0.37cvss 6.8epss 0.01

    Duplicacy through 3.2.5 contains a path traversal vulnerability in the restore function that fails to validate entry paths deserialized from snapshot files. Attackers can craft malicious snapshot entries with directory traversal sequences to write files outside the restore…

  • CVE-2026-61625MedAug 20, 2026
    risk 0.37cvss 6.8epss 0.00

    VictoriaMetrics is a scalable solution for monitoring and managing time series data. Prior to 1.122.25, 1.136.12, and 1.146.0, vmrestore does not validate backup part path components before using lib/backup/actions/restore.go and lib/backup/fslocal/fslocal.go to write restored…

  • CVE-2026-63328MedAug 18, 2026
    risk 0.37cvss —epss 0.00

    Trivy is a security scanner. Prior to 0.72.0, plugin manifest metadata is used by pkg/plugin/manager.go to construct paths under ~/.trivy/plugins without confining plugin names to that root, allowing an attacker who persuades a user to install or run a malicious plugin to write…