VYPR

CWE-22

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')

BaseStableLikelihood: High

Description

The product uses external input to construct a pathname that is intended to identify a file or directory that is located underneath a restricted parent directory, but the product does not properly neutralize special elements within the pathname that can cause the pathname to resolve to a location that is outside of the restricted directory.

Hierarchy (View 1000)

Parents

Children

Related attack patterns (CAPEC)

CAPEC-126 · CAPEC-64 · CAPEC-76 · CAPEC-78 · CAPEC-79

CVEs mapped to this weakness (10,485)

page 335 of 525
  • CVE-2022-26315MedFeb 28, 2022
    risk 0.35cvss 5.3epss 0.01

    qrcp through 0.8.4, in receive mode, allows ../ Directory Traversal via the file name specified by the uploader.

  • CVE-2022-0665MedFeb 22, 2022
    risk 0.35cvss 6.5epss 0.02

    Path Traversal in GitHub repository pimcore/pimcore prior to 10.3.2.

  • CVE-2021-45286MedFeb 9, 2022
    risk 0.35cvss 5.3epss 0.02

    Directory Traversal vulnerability exists in ZZCMS 2021 via the skin parameter in 1) index.php, 2) bottom.php, and 3) top_index.php.

  • CVE-2021-29398MedFeb 4, 2022
    risk 0.35cvss 5.3epss 0.02

    Directory traversal in /northstar/Common/NorthFileManager/fileManagerObjects.jsp Northstar Technologies Inc NorthStar Club Management 6.3 allows remote unauthenticated users to browse and list the directories across the entire filesystem of the host of the web application.

  • CVE-2021-28377MedJan 12, 2022
    risk 0.35cvss 5.3epss 0.08

    ChronoForums 2.0.11 allows av Directory Traversal to read arbitrary files.

  • CVE-2021-40003MedJan 10, 2022
    risk 0.35cvss 5.3epss 0.01

    HwPCAssistant has a path traversal vulnerability. Successful exploitation of this vulnerability may affect data confidentiality.

  • CVE-2021-40001MedJan 10, 2022
    risk 0.35cvss 5.3epss 0.01

    The CaasKit module has a path traversal vulnerability. Successful exploitation of this vulnerability may cause the MeeTime application to be unavailable.

  • CVE-2021-22404MedOct 28, 2021
    risk 0.35cvss 5.3epss 0.01

    There is a Directory traversal vulnerability in Huawei Smartphone.Successful exploitation of this vulnerability may affect service confidentiality.

  • CVE-2021-37922MedOct 7, 2021
    risk 0.35cvss 5.3epss 0.02

    Zoho ManageEngine ADManager Plus version 7110 and prior is vulnerable to path traversal which allows copying of files from one directory to another.

  • CVE-2021-21683MedOct 6, 2021
    risk 0.35cvss 6.5epss 0.02

    The file browser in Jenkins 2.314 and earlier, LTS 2.303.1 and earlier may interpret some paths to files as absolute on Windows, resulting in a path traversal vulnerability allowing attackers with Overall/Read permission (Windows controller) or Job/Workspace permission (Windows…

  • CVE-2020-15941MedOct 6, 2021
    risk 0.35cvss 5.4epss 0.01

    A path traversal vulnerability [CWE-22] in FortiClientEMS versions 6.4.1 and below; 6.2.8 and below may allow an authenticated attacker to inject directory traversal character sequences to add/delete the files of the server via the name parameter of Deployment Packages.

  • CVE-2021-41596MedOct 4, 2021
    risk 0.35cvss 5.3epss 0.02

    SuiteCRM before 7.10.33 and 7.11.22 allows information disclosure via Directory Traversal. An attacker can partially include arbitrary files via the importFile parameter of the RefreshMapping import functionality.

  • CVE-2021-41595MedOct 4, 2021
    risk 0.35cvss 5.3epss 0.02

    SuiteCRM before 7.10.33 and 7.11.22 allows information disclosure via Directory Traversal. An attacker can partially include arbitrary files via the file_name parameter of the Step3 import functionality.

  • CVE-2021-21706MedOct 4, 2021
    risk 0.35cvss 5.3epss 0.01

    In PHP versions 7.3.x below 7.3.31, 7.4.x below 7.4.24 and 8.0.x below 8.0.11, in Microsoft Windows environment, ZipArchive::extractTo may be tricked into writing a file outside target directory when extracting a ZIP file, thus potentially causing files to be created or…

  • CVE-2021-40349MedSep 27, 2021
    risk 0.35cvss 5.3epss 0.01

    e7d Speed Test (aka speedtest) 0.5.3 allows a path-traversal attack that results in information disclosure via the "GET /.." substring.

  • CVE-2021-3806MedSep 18, 2021
    risk 0.35cvss 5.3epss 0.01

    A path traversal vulnerability on Pardus Software Center's "extractArchive" function could allow anyone on the same network to do a man-in-the-middle and write files on the system.

  • CVE-2021-36717MedSep 7, 2021
    risk 0.35cvss 5.4epss 0.01

    Synerion TimeNet version 9.21 contains a directory traversal vulnerability where, on the "Name" parameter, the attacker can return to the root directory and open the host file. This might give the attacker the ability to view restricted files, which could provide the attacker…

  • CVE-2020-18878MedAug 20, 2021
    risk 0.35cvss 5.3epss 0.02

    Directory Traversal in Skycaiji v1.3 allows remote attackers to obtain sensitive information via the component 'index.php?m=admin&c=Tool&a=log&file=D%3A%5CphpStudy%5CWWW%5Cindex.php'.

  • CVE-2021-36156MedAug 3, 2021
    risk 0.35cvss 5.3epss 0.01

    An issue was discovered in Grafana Loki through 2.2.1. The header value X-Scope-OrgID is used to construct file paths for rules files, and if crafted to conduct directory traversal such as ae ../../sensitive/path/in/deployment pathname, then Loki will attempt to parse a rules…

  • CVE-2021-30483MedJul 30, 2021
    risk 0.35cvss 5.3epss 0.02

    isomorphic-git before 1.8.2 allows Directory Traversal via a crafted repository.