VYPR

CWE-22

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')

BaseStableLikelihood: High

Description

The product uses external input to construct a pathname that is intended to identify a file or directory that is located underneath a restricted parent directory, but the product does not properly neutralize special elements within the pathname that can cause the pathname to resolve to a location that is outside of the restricted directory.

Hierarchy (View 1000)

Parents

Children

Related attack patterns (CAPEC)

CAPEC-126 · CAPEC-64 · CAPEC-76 · CAPEC-78 · CAPEC-79

CVEs mapped to this weakness (10,483)

page 315 of 525
  • CVE-2022-31475MedJul 21, 2022
    risk 0.36cvss 5.5epss 0.01

    Authenticated (custom plugin role) Arbitrary File Read via Export function vulnerability in GiveWP's GiveWP plugin <= 2.20.2 at WordPress.

  • CVE-2022-20101MedMay 3, 2022
    risk 0.36cvss 5.5epss 0.00

    In aee daemon, there is a possible information disclosure due to a path traversal. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS06419017; Issue ID: ALPS06270870.

  • CVE-2022-20727MedApr 15, 2022
    risk 0.36cvss 5.5epss 0.01

    Multiple vulnerabilities in the Cisco IOx application hosting environment on multiple Cisco platforms could allow an attacker to inject arbitrary commands into the underlying host operating system, execute arbitrary code on the underlying host operating system, install…

  • CVE-2022-20726MedApr 15, 2022
    risk 0.36cvss 5.5epss 0.01

    Multiple vulnerabilities in the Cisco IOx application hosting environment on multiple Cisco platforms could allow an attacker to inject arbitrary commands into the underlying host operating system, execute arbitrary code on the underlying host operating system, install…

  • CVE-2022-20725MedApr 15, 2022
    risk 0.36cvss 5.5epss 0.01

    Multiple vulnerabilities in the Cisco IOx application hosting environment on multiple Cisco platforms could allow an attacker to inject arbitrary commands into the underlying host operating system, execute arbitrary code on the underlying host operating system, install…

  • CVE-2022-20724MedApr 15, 2022
    risk 0.36cvss 5.5epss 0.01

    Multiple vulnerabilities in the Cisco IOx application hosting environment on multiple Cisco platforms could allow an attacker to inject arbitrary commands into the underlying host operating system, execute arbitrary code on the underlying host operating system, install…

  • CVE-2022-20723MedApr 15, 2022
    risk 0.36cvss 5.5epss 0.02

    Multiple vulnerabilities in the Cisco IOx application hosting environment on multiple Cisco platforms could allow an attacker to inject arbitrary commands into the underlying host operating system, execute arbitrary code on the underlying host operating system, install…

  • CVE-2022-20722MedApr 15, 2022
    risk 0.36cvss 5.5epss 0.01

    Multiple vulnerabilities in the Cisco IOx application hosting environment on multiple Cisco platforms could allow an attacker to inject arbitrary commands into the underlying host operating system, execute arbitrary code on the underlying host operating system, install…

  • CVE-2022-20721MedApr 15, 2022
    risk 0.36cvss 5.5epss 0.01

    Multiple vulnerabilities in the Cisco IOx application hosting environment on multiple Cisco platforms could allow an attacker to inject arbitrary commands into the underlying host operating system, execute arbitrary code on the underlying host operating system, install…

  • CVE-2022-20720MedApr 15, 2022
    risk 0.36cvss 5.5epss 0.02

    Multiple vulnerabilities in the Cisco IOx application hosting environment on multiple Cisco platforms could allow an attacker to inject arbitrary commands into the underlying host operating system, execute arbitrary code on the underlying host operating system, install…

  • CVE-2022-20719MedApr 15, 2022
    risk 0.36cvss 5.5epss 0.03

    Multiple vulnerabilities in the Cisco IOx application hosting environment on multiple Cisco platforms could allow an attacker to inject arbitrary commands into the underlying host operating system, execute arbitrary code on the underlying host operating system, install…

  • CVE-2022-20718MedApr 15, 2022
    risk 0.36cvss 5.5epss 0.02

    Multiple vulnerabilities in the Cisco IOx application hosting environment on multiple Cisco platforms could allow an attacker to inject arbitrary commands into the underlying host operating system, execute arbitrary code on the underlying host operating system, install…

  • CVE-2022-20677MedApr 15, 2022
    risk 0.36cvss 5.5epss 0.01

    Multiple vulnerabilities in the Cisco IOx application hosting environment on multiple Cisco platforms could allow an attacker to inject arbitrary commands into the underlying host operating system, execute arbitrary code on the underlying host operating system, install…

  • CVE-2021-27755MedFeb 21, 2022
    risk 0.36cvss 5.5epss 0.00

    "Sametime Android potential path traversal vulnerability when using File class"

  • CVE-2021-27753MedFeb 21, 2022
    risk 0.36cvss 5.5epss 0.00

    "Sametime Android PathTraversal Vulnerability"

  • CVE-2021-23520MedJan 31, 2022
    risk 0.36cvss 5.5epss 0.01

    The package juce-framework/juce before 6.1.5 are vulnerable to Arbitrary File Write via Archive Extraction (Zip Slip) via the ZipFile::uncompressEntry function in juce_ZipFile.cpp. This vulnerability is triggered when the archive is extracted upon calling uncompressTo() on a…

  • CVE-2022-22790MedJan 28, 2022
    risk 0.36cvss 5.6epss 0.01

    SYNEL - eharmony Directory Traversal. Directory Traversal - is an attack against a server or a Web application aimed at unauthorized access to the file system. on the "Name" parameter the attacker can return to the root directory and open the host file. The path exposes…

  • CVE-2020-25881MedOct 29, 2021
    risk 0.36cvss 5.5epss 0.01

    A vulnerability was discovered in the filename parameter in pathindex.php?r=cms-backend/attachment/delete&sub=&filename=../../../../111.txt&filetype=image/jpeg of the master version of RKCMS. This vulnerability allows for an attacker to perform a directory traversal via a…

  • CVE-2021-42556MedOct 22, 2021
    risk 0.36cvss 5.5epss 0.01

    Rasa X before 0.42.4 allows Directory Traversal during archive extraction. In the functionality that allows a user to load a trained model archive, an attacker has arbitrary write capability within specific directories via a crafted archive file.

  • CVE-2021-34711MedOct 6, 2021
    risk 0.36cvss 5.5epss 0.00

    A vulnerability in the debug shell of Cisco IP Phone software could allow an authenticated, local attacker to read any file on the device file system. This vulnerability is due to insufficient input validation. An attacker could exploit this vulnerability by providing crafted…