VYPR

CWE-22

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')

BaseStableLikelihood: High

Description

The product uses external input to construct a pathname that is intended to identify a file or directory that is located underneath a restricted parent directory, but the product does not properly neutralize special elements within the pathname that can cause the pathname to resolve to a location that is outside of the restricted directory.

Hierarchy (View 1000)

Parents

Children

Related attack patterns (CAPEC)

CAPEC-126 · CAPEC-64 · CAPEC-76 · CAPEC-78 · CAPEC-79

CVEs mapped to this weakness (10,485)

page 332 of 525
  • CVE-2024-25620MedFeb 15, 2024
    risk 0.35cvss 6.4epss 0.01

    Helm is a tool for managing Charts. Charts are packages of pre-configured Kubernetes resources. When either the Helm client or SDK is used to save a chart whose name within the `Chart.yaml` file includes a relative path change, the chart would be saved outside its expected…

  • CVE-2024-24938MedFeb 6, 2024
    risk 0.35cvss 5.3epss 0.01

    In JetBrains TeamCity before 2023.11.2 limited directory traversal was possible in the Kotlin DSL documentation

  • CVE-2023-7216MedFeb 5, 2024
    risk 0.35cvss 5.3epss 0.01

    A path traversal vulnerability was found in the CPIO utility. This issue could allow a remote unauthenticated attacker to trick a user into opening a specially crafted archive. During the extraction process, the archiver could follow symlinks outside of the intended directory,…

  • CVE-2024-0989MedJan 29, 2024
    risk 0.35cvss 5.4epss 0.01

    A vulnerability, which was classified as problematic, has been found in Sichuan Yougou Technology KuERP up to 1.0.4. Affected by this issue is the function del_sn_db of the file /application/index/controller/Service.php. The manipulation of the argument file leads to path…

  • CVE-2024-23899MedJan 24, 2024
    risk 0.35cvss 6.5epss 0.01

    Jenkins Git server Plugin 99.va_0826a_b_cdfa_d and earlier does not disable a feature of its command parser that replaces an '@' character followed by a file path in an argument with the file's contents, allowing attackers with Overall/Read permission to read content from…

  • CVE-2023-35020MedJan 19, 2024
    risk 0.35cvss 5.4epss 0.01

    IBM Sterling Control Center 6.3.0 could allow a remote attacker to traverse directories on the system. An attacker could send a specially crafted URL request containing "dot dot" sequences (/../) to view arbitrary files on the system. IBM X-Force ID: 257874.

  • CVE-2024-0354MedJan 10, 2024
    risk 0.35cvss 5.3epss 0.01

    A vulnerability, which was classified as critical, has been found in unknown-o download-station up to 1.1.8. This issue affects some unknown processing of the file index.php. The manipulation of the argument f leads to path traversal: '../filedir'. The attack may be initiated…

  • CVE-2023-47440MedDec 7, 2023
    risk 0.35cvss 6.5epss 0.01

    Gladys Assistant v4.27.0 and prior is vulnerable to Directory Traversal. The patch of CVE-2023-43256 was found to be incomplete, allowing authenticated attackers to extract sensitive files in the host machine.

  • CVE-2021-35975MedNov 30, 2023
    risk 0.35cvss 5.3epss 0.01

    Absolute path traversal vulnerability in the Systematica SMTP Adapter component (up to v2.0.1.101) in Systematica Radius (up to v.3.9.256.777) allows remote attackers to read arbitrary files via a full pathname in GET parameter "file" in URL. Also: affected components in same…

  • CVE-2023-6352MedNov 30, 2023
    risk 0.35cvss 5.3epss 0.01

    The default configuration of Aquaforest TIFF Server allows access to arbitrary file paths, subject to any restrictions imposed by Internet Information Services (IIS) or Microsoft Windows. Depending on how a web application uses and configures TIFF Server, a remote attacker may…

  • CVE-2023-47313MedNov 22, 2023
    risk 0.35cvss 5.4epss 0.01

    Headwind MDM Web panel 5.22.1 is vulnerable to Directory Traversal. The application uses an API call to move the uploaded temporary file to the file directory during the file upload process. This API call receives two input parameters, such as path and localPath. The first one…

  • CVE-2023-46864MedOct 30, 2023
    risk 0.35cvss 5.3epss 0.01

    Peppermint Ticket Management through 0.2.4 allows remote attackers to read arbitrary files via a /api/v1/ticket/1/file/download?filepath=../ POST request.

  • CVE-2023-46655MedOct 25, 2023
    risk 0.35cvss 6.5epss 0.01

    Jenkins CloudBees CD Plugin 1.1.32 and earlier follows symbolic links to locations outside of the directory from which artifacts are published during the 'CloudBees CD - Publish Artifact' post-build step, allowing attackers able to configure jobs to publish arbitrary files from…

  • CVE-2021-46897MedOct 22, 2023
    risk 0.35cvss 6.5epss 0.01

    views.py in Wagtail CRX CodeRed Extensions (formerly CodeRed CMS or coderedcms) before 0.22.3 allows upward protected/..%2f..%2f path traversal when serving protected media.

  • CVE-2023-43044MedSep 28, 2023
    risk 0.35cvss 5.3epss 0.01

    IBM License Metric Tool 9.2 could allow a remote attacker to traverse directories on the system. An attacker could send a specially crafted URL request containing "dot dot" sequences (/../) to view arbitrary files on the system. IBM X-Force ID: 266893.

  • CVE-2023-41599MedSep 19, 2023
    risk 0.35cvss 5.3epss 0.12

    An issue in the component /common/DownController.java of JFinalCMS v5.0.0 allows attackers to execute a directory traversal.

  • CVE-2023-32003MedAug 15, 2023
    risk 0.35cvss 5.3epss 0.01

    `fs.mkdtemp()` and `fs.mkdtempSync()` can be used to bypass the permission model check using a path traversal attack. This flaw arises from a missing check in the fs.mkdtemp() API and the impact is a malicious actor could create an arbitrary directory. This vulnerability…

  • CVE-2023-39525MedAug 7, 2023
    risk 0.35cvss 6.5epss 0.01

    PrestaShop is an open source e-commerce web application. Prior to version 8.1.1, in the back office, files can be compromised using path traversal by replaying the import file deletion query with a specified file path that uses the traversal path. Version 8.1.1 contains a patch…

  • CVE-2023-38695MedAug 4, 2023
    risk 0.35cvss 6.5epss 0.01

    cypress-image-snapshot shows visual regressions in Cypress with jest-image-snapshot. Prior to version 8.0.2, it's possible for a user to pass a relative file path for the snapshot name and reach outside of the project directory into the machine running the test. This issue has…

  • CVE-2022-42182MedJul 31, 2023
    risk 0.35cvss 5.3epss 0.01

    Precisely Spectrum Spatial Analyst 20.01 is vulnerable to Directory Traversal.