VYPR

CWE-22

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')

BaseStableLikelihood: High

Description

The product uses external input to construct a pathname that is intended to identify a file or directory that is located underneath a restricted parent directory, but the product does not properly neutralize special elements within the pathname that can cause the pathname to resolve to a location that is outside of the restricted directory.

Hierarchy (View 1000)

Parents

Children

Related attack patterns (CAPEC)

CAPEC-126 · CAPEC-64 · CAPEC-76 · CAPEC-78 · CAPEC-79

CVEs mapped to this weakness (10,485)

page 337 of 525
  • CVE-2020-28348MedNov 24, 2020
    risk 0.35cvss 6.5epss 0.02

    HashiCorp Nomad and Nomad Enterprise 0.9.0 up to 0.12.7 client Docker file sandbox feature may be subverted when not explicitly disabled or when using a volume mount type. Fixed in 0.12.8, 0.11.7, and 0.10.8.

  • CVE-2020-15928MedNov 24, 2020
    risk 0.35cvss 5.3epss 0.02

    In Ortus TestBox 2.4.0 through 4.1.0, unvalidated query string parameters to test-browser/index.cfm allow directory traversal.

  • CVE-2020-7762MedNov 5, 2020
    risk 0.35cvss 6.5epss 0.02

    This affects the package jsreport-chrome-pdf before 1.10.0.

  • CVE-2020-27993MedOct 29, 2020
    risk 0.35cvss 5.3epss 0.03

    Hrsale 2.0.0 allows download?type=files&filename=../ directory traversal to read arbitrary files.

  • CVE-2020-26650MedOct 22, 2020
    risk 0.35cvss 5.3epss 0.01

    AtomXCMS 2.0 is affected by Arbitrary File Read via admin/dump.php

  • CVE-2020-3597MedOct 8, 2020
    risk 0.35cvss 5.4epss 0.01

    A vulnerability in the configuration restore feature of Cisco Nexus Data Broker software could allow an unauthenticated, remote attacker to perform a directory traversal attack on an affected device. The vulnerability is due to insufficient validation of configuration backup…

  • CVE-2020-25734MedSep 18, 2020
    risk 0.35cvss 5.3epss 0.02

    webTareas through 2.1 allows files/Default/ Directory Listing.

  • CVE-2020-2254MedSep 16, 2020
    risk 0.35cvss 6.5epss 0.02

    Jenkins Blue Ocean Plugin 1.23.2 and earlier provides an undocumented feature flag that, when enabled, allows an attacker with Job/Configure or Job/Create permission to read arbitrary files on the Jenkins controller file system.

  • CVE-2012-3337MedSep 1, 2020
    risk 0.35cvss 5.3epss 0.02

    IBM InfoSphere Guardium 8.0, 8.01, and 8.2 could allow a remote attacker to traverse directories on the system. An attacker could send a specially-crafted URL request containing "dot dot" sequences (/../) to download arbitrary files on the system. IBM X-Force ID: 78284.

  • CVE-2020-19877MedAug 24, 2020
    risk 0.35cvss 5.3epss 0.02

    DBHcms v1.2.0 has a directory traversal vulnerability as there is no directory control function in directory /dbhcms/. A remote unauthenticated attacker can exploit this vulnerability to obtain server-sensitive information.

  • CVE-2020-5614MedJul 29, 2020
    risk 0.35cvss 5.3epss 0.02

    Directory traversal vulnerability in KonaWiki 3.1.0 and earlier allows remote attackers to read arbitrary files via unspecified vectors.

  • CVE-2020-9663MedJul 22, 2020
    risk 0.35cvss 5.3epss 0.03

    Adobe Reader Mobile versions 20.0.1 and earlier have a directory traversal vulnerability. Successful exploitation could lead to information disclosure.

  • CVE-2017-18874MedJun 19, 2020
    risk 0.35cvss 6.5epss 0.01

    An issue was discovered in Mattermost Server before 4.3.0, 4.2.1, and 4.1.2 when local storage for files is used. A System Admin can achieve directory traversal.

  • CVE-2020-14452MedJun 19, 2020
    risk 0.35cvss 5.3epss 0.01

    An issue was discovered in Mattermost Server before 5.21.0. mmctl allows directory traversal via HTTP, aka MMSA-2020-0014.

  • CVE-2020-13795MedJun 3, 2020
    risk 0.35cvss 5.3epss 0.02

    An issue was discovered in Navigate CMS through 2.8.7. It allows Directory Traversal because lib/packages/templates/template.class.php mishandles ../ and ..\ substrings.

  • CVE-2020-13227MedJun 2, 2020
    risk 0.35cvss 5.3epss 0.02

    An issue was discovered in Sysax Multi Server 6.90. An attacker can determine the username (under which the web server is running) by triggering an invalid path permission error. This bypasses the fakepath protection mechanism.

  • CVE-2014-8939MedJun 1, 2020
    risk 0.35cvss 5.3epss 0.01

    Lexiglot through 2014-11-20 allows remote attackers to obtain sensitive information (full path) via an include/smarty/plugins/modifier.date_format.php request if PHP has a non-recommended configuration that produces warning messages.

  • CVE-2014-7174MedJun 1, 2020
    risk 0.35cvss 5.3epss 0.01

    FarLinX X25 Gateway through 2014-09-25 allows directory traversal via the log-handling feature.

  • CVE-2020-13093MedMay 15, 2020
    risk 0.35cvss 5.3epss 0.01

    iSpyConnect.com Agent DVR before 2.7.1.0 allows directory traversal.

  • CVE-2020-5834MedMay 11, 2020
    risk 0.35cvss 5.3epss 0.02

    Symantec Endpoint Protection Manager, prior to 14.3, may be susceptible to a directory traversal attack that could allow a remote actor to determine the size of files in the directory.