VYPR

CWE-22

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')

BaseStableLikelihood: High

Description

The product uses external input to construct a pathname that is intended to identify a file or directory that is located underneath a restricted parent directory, but the product does not properly neutralize special elements within the pathname that can cause the pathname to resolve to a location that is outside of the restricted directory.

Hierarchy (View 1000)

Parents

Children

Related attack patterns (CAPEC)

CAPEC-126 · CAPEC-64 · CAPEC-76 · CAPEC-78 · CAPEC-79

CVEs mapped to this weakness (10,485)

page 317 of 525
  • CVE-2020-12392MedMay 26, 2020
    risk 0.36cvss 5.5epss 0.00

    The 'Copy as cURL' feature of Devtools' network tab did not properly escape the HTTP POST data of a request, which can be controlled by the website. If a user used the 'Copy as cURL' feature and pasted the command into a terminal, it could have resulted in the disclosure of…

  • CVE-2020-12475MedMay 4, 2020
    risk 0.36cvss 5.5epss 0.01

    TP-Link Omada Controller Software 3.2.6 allows Directory Traversal for reading arbitrary files via com.tp_link.eap.web.portal.PortalController.getAdvertiseFile in /opt/tplink/EAPController/lib/eap-web-3.2.6.jar.

  • CVE-2019-19102MedApr 29, 2020
    risk 0.36cvss 5.5epss 0.01

    A directory traversal vulnerability in SharpZipLib used in the upgrade service in B&R Automation Studio versions 4.0.x, 4.1.x and 4.2.x allow unauthenticated users to write to certain local directories. The vulnerability is also known as zip slip.

  • CVE-2020-8446MedJan 30, 2020
    risk 0.36cvss 5.5epss 0.01

    In OSSEC-HIDS 2.7 through 3.5.0, the server component responsible for log analysis (ossec-analysisd) is vulnerable to path traversal (with write access) via crafted syscheck messages written directly to the analysisd UNIX domain socket by a local user.

  • CVE-2015-6591MedJan 15, 2020
    risk 0.36cvss 5.5epss 0.01

    Directory traversal vulnerability in application/templates/amelia/loadjs.php in Free Reprintables ArticleFR 3.0.7 and earlier allows local users to read arbitrary files via the s parameter.

  • CVE-2019-7289MedDec 18, 2019
    risk 0.36cvss 5.5epss 0.00

    A parsing issue in the handling of directory paths was addressed with improved path validation. This issue is fixed in Shortcuts 2.1.3 for iOS. A local user may be able to view senstive user information.

  • CVE-2019-5251MedDec 13, 2019
    risk 0.36cvss 5.5epss 0.01

    There is a path traversal vulnerability in several Huawei smartphones. The system does not sufficiently validate certain pathnames from the application. An attacker could trick the user into installing, backing up and restoring a malicious application. Successful exploit could…

  • CVE-2019-0074MedOct 9, 2019
    risk 0.36cvss 5.5epss 0.00

    A path traversal vulnerability in NFX150 Series and QFX10K Series, EX9200 Series, MX Series and PTX Series devices with Next-Generation Routing Engine (NG-RE) allows a local authenticated user to read sensitive system files. This issue only affects NFX150 Series and QFX10K…

  • CVE-2019-16511MedSep 19, 2019
    risk 0.36cvss 5.5epss 0.02

    An issue was discovered in DTF in FireGiant WiX Toolset before 3.11.2. Microsoft.Deployment.Compression.Cab.dll and Microsoft.Deployment.Compression.Zip.dll allow directory traversal during CAB or ZIP archive extraction, because the full name of an archive file (even with a ../…

  • CVE-2019-1142MedSep 11, 2019
    risk 0.36cvss 5.5epss 0.01

    An elevation of privilege vulnerability exists when the .NET Framework common language runtime (CLR) allows file creation in arbitrary locations, aka '.NET Framework Elevation of Privilege Vulnerability'.

  • CVE-2019-15517MedAug 23, 2019
    risk 0.36cvss 5.5epss 0.01

    jc21 Nginx Proxy Manager before 2.0.13 allows %2e%2e%2f directory traversal.

  • CVE-2019-10352MedJul 17, 2019
    risk 0.36cvss 6.5epss 0.10

    A path traversal vulnerability in Jenkins 2.185 and earlier, LTS 2.176.1 and earlier in core/src/main/java/hudson/model/FileParameterValue.java allowed attackers with Job/Configure permission to define a file parameter with a file name outside the intended directory, resulting…

  • CVE-2019-11879MedMay 10, 2019
    risk 0.36cvss 5.5epss 0.01

    The WEBrick gem 1.4.2 for Ruby allows directory traversal if the attacker once had local access to create a symlink to a location outside of the web root directory. NOTE: The vendor states that this is analogous to Options FollowSymlinks in the Apache HTTP Server, and therefore…

  • CVE-2019-0191MedMar 21, 2019
    risk 0.36cvss 6.5epss 0.05

    Apache Karaf kar deployer reads .kar archives and extracts the paths from the "repository/" and "resources/" entries in the zip file. It then writes out the content of these paths to the Karaf repo and resources directories. However, it doesn't do any validation on the paths in…

  • CVE-2018-1000997MedJan 23, 2019
    risk 0.36cvss 6.5epss 0.03

    A path traversal vulnerability exists in the Stapler web framework used by Jenkins 2.145 and earlier, LTS 2.138.1 and earlier in core/src/main/java/org/kohsuke/stapler/Facet.java, groovy/src/main/java/org/kohsuke/stapler/jelly/groovy/GroovyFacet.java,…

  • CVE-2018-1000406MedJan 9, 2019
    risk 0.36cvss 6.5epss 0.04

    A path traversal vulnerability exists in Jenkins 2.145 and earlier, LTS 2.138.1 and earlier in core/src/main/java/hudson/model/FileParameterValue.java that allows attackers with Job/Configure permission to define a file parameter with a file name outside the intended directory,…

  • CVE-2018-17828MedOct 1, 2018
    risk 0.36cvss 5.5epss 0.02

    Directory traversal vulnerability in ZZIPlib 0.13.69 allows attackers to overwrite arbitrary files via a .. (dot dot) in a zip file, because of the function unzzip_cat in the bins/unzzipcat-mem.c file.

  • CVE-2018-0659MedSep 7, 2018
    risk 0.36cvss 5.5epss 0.01

    Directory traversal vulnerability in ver.2.8.4.0 and earlier and ver.3.3.0.0 and earlier allows an attacker to create or overwrite existing files via specially crafted ATC file.

  • CVE-2018-1000801MedSep 6, 2018
    risk 0.36cvss 5.5epss 0.02

    okular version 18.08 and earlier contains a Directory Traversal vulnerability in function "unpackDocumentArchive(...)" in "core/document.cpp" that can result in Arbitrary file creation on the user workstation. This attack appear to be exploitable via he victim must open a…

  • CVE-2018-10862MedJul 27, 2018
    risk 0.36cvss 5.5epss 0.01

    WildFly Core before version 6.0.0.Alpha3 does not properly validate file paths in .war archives, allowing for the extraction of crafted .war archives to overwrite arbitrary files. This is an instance of the 'Zip Slip' vulnerability.