VYPR

CWE-22

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')

BaseStableLikelihood: High

Description

The product uses external input to construct a pathname that is intended to identify a file or directory that is located underneath a restricted parent directory, but the product does not properly neutralize special elements within the pathname that can cause the pathname to resolve to a location that is outside of the restricted directory.

Hierarchy (View 1000)

Parents

Children

Related attack patterns (CAPEC)

CAPEC-126 · CAPEC-64 · CAPEC-76 · CAPEC-78 · CAPEC-79

CVEs mapped to this weakness (10,485)

page 336 of 525
  • CVE-2021-35967MedJul 19, 2021
    risk 0.35cvss 5.3epss 0.01

    The directory page parameter of the Orca HCM digital learning platform does not filter special characters. Remote attackers can access the system directory thru Path Traversal without logging in.

  • CVE-2021-24447MedJul 19, 2021
    risk 0.35cvss 5.3epss 0.01

    The WP Image Zoom WordPress plugin before 1.47 did not validate its tab parameter before using it in the include_once() function, leading to a local file inclusion issue in the admin dashboard

  • CVE-2021-32746MedJul 12, 2021
    risk 0.35cvss 5.3epss 0.01

    Icinga Web 2 is an open source monitoring web interface, framework and command-line interface. Between versions 2.3.0 and 2.8.2, the `doc` module of Icinga Web 2 allows to view documentation directly in the UI. It must be enabled manually by an administrator and users need…

  • CVE-2020-18665MedJun 24, 2021
    risk 0.35cvss 5.3epss 0.02

    Directory Traversal vulnerability in WebPort <=1.19.1 in tags of system settings.

  • CVE-2020-22200MedJun 16, 2021
    risk 0.35cvss 5.3epss 0.01

    Directory Traversal vulnerability in phpCMS 9.1.13 via the q parameter to public_get_suggest_keyword.

  • CVE-2021-33896MedJun 7, 2021
    risk 0.35cvss 5.3epss 0.02

    Dino before 0.1.2 and 0.2.x before 0.2.1 allows Directory Traversal (only for creation of new files) via URI-encoded path separators.

  • CVE-2021-32662MedJun 3, 2021
    risk 0.35cvss 6.5epss 0.01

    Backstage is an open platform for building developer portals, and techdocs-common contains common functionalities for Backstage's TechDocs. In `@backstage/techdocs-common` versions prior to 0.6.3, a malicious actor could read sensitive files from the environment where TechDocs…

  • CVE-2021-32062MedMay 6, 2021
    risk 0.35cvss 5.3epss 0.02

    MapServer before 7.0.8, 7.1.x and 7.2.x before 7.2.3, 7.3.x and 7.4.x before 7.4.5, and 7.5.x and 7.6.x before 7.6.3 does not properly enforce the MS_MAP_NO_PATH and MS_MAP_PATTERN restrictions that are intended to control the locations from which a mapfile may be loaded (with…

  • CVE-2021-30048MedApr 29, 2021
    risk 0.35cvss 5.3epss 0.02

    Directory Traversal in the fileDownload function in com/java2nb/common/controller/FileController.java in Novel-plus (小说精品屋-plus) 3.5.1 allows attackers to read arbitrary files via the filePath parameter.

  • CVE-2021-30635MedApr 27, 2021
    risk 0.35cvss 5.3epss 0.02

    Sonatype Nexus Repository Manager 3.x before 3.30.1 allows a remote attacker to get a list of files and directories that exist in a UI-related folder via directory traversal (no customer-specific data is exposed).

  • CVE-2020-24137MedApr 7, 2021
    risk 0.35cvss 5.3epss 0.01

    Directory traversal vulnerability in Wcms 0.3.2 allows an attacker to read arbitrary files on the server that is running an application via the path parameter to wex/cssjs.php.

  • CVE-2020-13419MedApr 6, 2021
    risk 0.35cvss 5.3epss 0.01

    OpenIAM before 4.2.0.3 allows Directory Traversal in the Batch task.

  • CVE-2021-28658MedApr 6, 2021
    risk 0.35cvss 5.3epss 0.04

    In Django 2.2 before 2.2.20, 3.0 before 3.0.14, and 3.1 before 3.1.8, MultiPartParser allowed directory traversal via uploaded files with suitably crafted file names. Built-in upload handlers were not affected by this vulnerability.

  • CVE-2021-22114MedMar 1, 2021
    risk 0.35cvss 5.3epss 0.01

    Addresses partial fix in CVE-2018-1263. Spring-integration-zip, versions prior to 1.0.4, exposes an arbitrary file write vulnerability, that can be achieved using a specially crafted zip archive (affects other archives as well, bzip2, tar, xz, war, cpio, 7z), that holds path…

  • CVE-2021-3152MedJan 26, 2021
    risk 0.35cvss 5.3epss 0.02

    Home Assistant before 2021.1.3 does not have a protection layer that can help to prevent directory-traversal attacks against custom integrations. NOTE: the vendor's perspective is that the vulnerability itself is in custom integrations written by third parties, not in Home…

  • CVE-2021-23242MedJan 7, 2021
    risk 0.35cvss 5.3epss 0.02

    MERCUSYS Mercury X18G 1.0.5 devices allow Directory Traversal via ../ to the UPnP server, as demonstrated by the /../../conf/template/uhttpd.json URI.

  • CVE-2020-27534MedDec 30, 2020
    risk 0.35cvss 5.3epss 0.02

    util/binfmt_misc/check.go in Builder in Docker Engine before 19.03.9 calls os.OpenFile with a potentially unsafe qemu-check temporary pathname, constructed with an empty first argument in an ioutil.TempDir call.

  • CVE-2020-35176MedDec 12, 2020
    risk 0.35cvss 5.3epss 0.02

    In AWStats through 7.8, cgi-bin/awstats.pl?config= accepts a partial absolute pathname (omitting the initial /etc), even though it was intended to only read a file in the /etc/awstats/awstats.conf format. NOTE: this issue exists because of an incomplete fix for CVE-2017-1000501…

  • CVE-2019-19877MedNov 27, 2020
    risk 0.35cvss 5.3epss 0.01

    An issue was discovered in B&R Industrial Automation APROL before R4.2 V7.08. An attacker can get access to sensitive information outside the working directory via Directory Traversal attacks against AprolSqlServer, a different vulnerability than CVE-2019-16357.

  • CVE-2020-13886MedNov 26, 2020
    risk 0.35cvss 5.3epss 0.05

    Intelbras TIP 200 60.61.75.15, TIP 200 LITE 60.61.75.15, and TIP 300 65.61.75.22 devices allow cgi-bin/cgiServer.exx?page=../ Directory Traversal.