VYPR

CWE-22

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')

BaseStableLikelihood: High

Description

The product uses external input to construct a pathname that is intended to identify a file or directory that is located underneath a restricted parent directory, but the product does not properly neutralize special elements within the pathname that can cause the pathname to resolve to a location that is outside of the restricted directory.

Hierarchy (View 1000)

Parents

Children

Related attack patterns (CAPEC)

CAPEC-126 · CAPEC-64 · CAPEC-76 · CAPEC-78 · CAPEC-79

CVEs mapped to this weakness (10,485)

page 334 of 525
  • CVE-2022-40444MedSep 22, 2022
    risk 0.35cvss 5.3epss 0.01

    ZZCMS 2022 was discovered to contain a full path disclosure vulnerability via the page /admin/index.PHP? _server.

  • CVE-2022-40443MedSep 22, 2022
    risk 0.35cvss 5.3epss 0.03

    An absolute path traversal vulnerability in ZZCMS 2022 allows attackers to obtain sensitive information via a crafted GET request sent to /one/siteinfo.php.

  • CVE-2022-2531MedAug 5, 2022
    risk 0.35cvss 5.3epss 0.01

    An issue has been discovered in GitLab EE affecting all versions starting from 12.5 before 15.0.5, all versions starting from 15.1 before 15.1.4, all versions starting from 15.2 before 15.2.1. GitLab was not performing correct authentication on Grafana API under specific…

  • CVE-2022-35918MedAug 1, 2022
    risk 0.35cvss 6.5epss 0.02

    Streamlit is a data oriented application development framework for python. Users hosting Streamlit app(s) that use custom components are vulnerable to a directory traversal attack that could leak data from their web server file-system such as: server logs, world readable files,…

  • CVE-2022-27611MedJul 28, 2022
    risk 0.35cvss 5.4epss 0.01

    Improper limitation of a pathname to a restricted directory ('Path Traversal') vulnerability in webapi component in Synology Audio Station before 6.5.4-3367 allows remote authenticated users to delete arbitrary files via unspecified vectors.

  • CVE-2022-36894MedJul 27, 2022
    risk 0.35cvss 6.5epss 0.01

    An arbitrary file write vulnerability in Jenkins CLIF Performance Testing Plugin 64.vc0d66de1dfb_f and earlier allows attackers with Overall/Read permission to create or replace arbitrary files on the Jenkins controller file system with attacker-specified content.

  • CVE-2017-20105MedJun 28, 2022
    risk 0.35cvss 5.4epss 0.01

    A vulnerability was found in Simplessus 3.7.7. It has been rated as critical. This issue affects some unknown processing. The manipulation of the argument path with the input ..%2f..%2f..%2f..%2f..%2f..%2f..%2f..%2f..%2f..%2f..%2f..%2f..%2f..%2f..%2f..%2fetc%2fpasswd leads to…

  • CVE-2022-34173MedJun 23, 2022
    risk 0.35cvss 5.4epss 0.01

    In Jenkins 2.340 through 2.355 (both inclusive) the tooltip of the build button in list views supports HTML without escaping the job display name, resulting in a cross-site scripting (XSS) vulnerability exploitable by attackers with Job/Configure permission.

  • CVE-2022-34172MedJun 23, 2022
    risk 0.35cvss 5.4epss 0.01

    In Jenkins 2.340 through 2.355 (both inclusive) symbol-based icons unescape previously escaped values of 'tooltip' parameters, resulting in a cross-site scripting (XSS) vulnerability.

  • CVE-2022-34171MedJun 23, 2022
    risk 0.35cvss 5.4epss 0.01

    In Jenkins 2.321 through 2.355 (both inclusive) and LTS 2.332.1 through LTS 2.332.3 (both inclusive) the HTML output generated for new symbol-based SVG icons includes the 'title' attribute of 'l:ionicon' (until Jenkins 2.334) and 'alt' attribute of 'l:icon' (since Jenkins 2.335)…

  • CVE-2022-30058MedMay 11, 2022
    risk 0.35cvss 5.3epss 0.01

    Shopwind <=v3.4.2 was discovered to contain a Arbitrary File Download vulnerability via the neirong parameter at \backend\controllers\DbController.php.

  • CVE-2021-38693MedMay 5, 2022
    risk 0.35cvss 5.3epss 0.01

    A path traversal vulnerability has been reported to affect QNAP device running QuTScloud, QuTS hero, QTS, QVR Pro Appliance. If exploited, this vulnerability allows attackers to read the contents of unexpected files and expose sensitive data. We have already fixed this…

  • CVE-2022-1166MedApr 4, 2022
    risk 0.35cvss 5.3epss 0.02

    The JobMonster Theme was vulnerable to Directory Listing in the /wp-content/uploads/jobmonster/ folder, as it did not include a default PHP file, or .htaccess file. This could expose personal data such as people's resumes. Although Directory Listing can be prevented by securely…

  • CVE-2022-28146MedMar 29, 2022
    risk 0.35cvss 6.5epss 0.02

    Jenkins Continuous Integration with Toad Edge Plugin 2.3 and earlier allows attackers with Item/Configure permission to read arbitrary files on the Jenkins controller by specifying an input folder on the Jenkins controller as a parameter to its build steps.

  • CVE-2022-0959MedMar 16, 2022
    risk 0.35cvss 6.5epss 0.01

    A malicious, but authorised and authenticated user can construct an HTTP request using their existing CSRF token and session cookie to manually upload files to any location that the operating system user account under which pgAdmin is running has permission to write.

  • CVE-2021-29134MedMar 15, 2022
    risk 0.35cvss 5.3epss 0.01

    The avatar middleware in Gitea before 1.13.6 allows Directory Traversal via a crafted URL.

  • CVE-2022-26276MedMar 12, 2022
    risk 0.35cvss 5.3epss 0.01

    An issue in index.php of OneNav v0.9.14 allows attackers to perform directory traversal.

  • CVE-2022-26652MedMar 10, 2022
    risk 0.35cvss 6.5epss 0.02

    NATS nats-server before 2.7.4 allows Directory Traversal (with write access) via an element in a ZIP archive for JetStream streams. nats-streaming-server before 0.24.3 is also affected.

  • CVE-2021-42857MedMar 10, 2022
    risk 0.35cvss 5.3epss 0.01

    It was discovered that the SteelCentral AppInternals Dynamic Sampling Agent's (DSA) AgentDaServlet has directory traversal vulnerabilities at the "/api/appInternals/1.0/agent/da/pcf" API. The affected endpoint does not have any validation of the user's input that allows a…

  • CVE-2021-43070MedMar 2, 2022
    risk 0.35cvss 5.4epss 0.01

    Multiple relative path traversal vulnerabilities [CWE-23] in FortiWLM management interface 8.6.2 and below, 8.5.2 and below, 8.4.2 and below, 8.3.3 and below, 8.2.2 may allow an authenticated attacker to retrieve arbitrary files from the underlying filesystem via specially…