VYPR

CWE-22

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')

BaseStableLikelihood: High

Description

The product uses external input to construct a pathname that is intended to identify a file or directory that is located underneath a restricted parent directory, but the product does not properly neutralize special elements within the pathname that can cause the pathname to resolve to a location that is outside of the restricted directory.

Hierarchy (View 1000)

Parents

Children

Related attack patterns (CAPEC)

CAPEC-126 · CAPEC-64 · CAPEC-76 · CAPEC-78 · CAPEC-79

CVEs mapped to this weakness (10,485)

page 338 of 525
  • CVE-2020-12765MedMay 9, 2020
    risk 0.35cvss 5.3epss 0.01

    Solis Miolo 2.0 allows index.php?module=install&action=view&item= Directory Traversal.

  • CVE-2020-12764MedMay 9, 2020
    risk 0.35cvss 5.3epss 0.01

    Gnuteca 3.8 allows file.php?folder=/&file= Directory Traversal.

  • CVE-2020-12448MedMay 7, 2020
    risk 0.35cvss 5.3epss 0.01

    GitLab EE 12.8 and later allows Exposure of Sensitive Information to an Unauthorized Actor via NuGet.

  • CVE-2020-4209MedMay 4, 2020
    risk 0.35cvss 5.4epss 0.01

    IBM Spectrum Protect Plus 10.1.0 through 10.1.5 could allow a remote attacker to traverse directories on the system. An attacker could send a specially-crafted URL request containing "dot dot" sequences (/../) to create arbitrary files on the system. IBM X-Force ID: 175019.

  • CVE-2020-11491MedApr 2, 2020
    risk 0.35cvss 4.9epss 0.08

    Monitoring::Logs in Zen Load Balancer 3.10.1 allows remote authenticated admins to conduct absolute path traversal attacks, as demonstrated by a filelog=/etc/shadow request to index.cgi.

  • CVE-2020-9323MedMar 18, 2020
    risk 0.35cvss 5.3epss 0.02

    Aquaforest TIFF Server 4.0 allows Unauthenticated File and Directory Enumeration via tiffserver/tssp.aspx.

  • CVE-2018-18576MedMar 17, 2020
    risk 0.35cvss 5.3epss 0.01

    The Hustle (aka wordpress-popup) plugin through 6.0.5 for WordPress allows Directory Traversal to obtain a directory listing via the views/admin/dashboard/ URI.

  • CVE-2020-10086MedMar 13, 2020
    risk 0.35cvss 5.3epss 0.01

    GitLab 10.4 through 12.8.1 allows Directory Traversal. A particular endpoint was vulnerable to a directory traversal vulnerability, leading to arbitrary file read.

  • CVE-2020-10387MedMar 12, 2020
    risk 0.35cvss 4.9epss 0.08

    Path Traversal in admin/download.php in Chadha PHPKB Standard Multi-Language 9 allows remote attackers to download files from the server using a dot-dot-slash sequence (../) via the GET parameter file.

  • CVE-2020-2139MedMar 9, 2020
    risk 0.35cvss 6.5epss 0.02

    An arbitrary file write vulnerability in Jenkins Cobertura Plugin 1.15 and earlier allows attackers able to control the coverage report file contents to overwrite any file on the Jenkins master file system.

  • CVE-2020-9364MedMar 4, 2020
    risk 0.35cvss 5.3epss 0.03

    An issue was discovered in helpers/mailer.php in the Creative Contact Form extension 4.6.2 before 2019-12-03 for Joomla!. A directory traversal vulnerability resides in the filename field for uploaded attachments via the creativecontactform_upload parameter. An attacker could…

  • CVE-2014-9609MedFeb 19, 2020
    risk 0.35cvss 5.3epss 0.13

    Directory traversal vulnerability in webadmin/reporter/view_server_log.php in Netsweeper before 3.1.10, 4.0.x before 4.0.9, and 4.1.x before 4.1.2 allows remote attackers to list directory contents via a .. (dot dot) in the log parameter in a stats action.

  • CVE-2020-3717MedJan 29, 2020
    risk 0.35cvss 5.3epss 0.03

    Magento versions 2.3.3 and earlier, 2.2.10 and earlier, 1.14.4.3 and earlier, and 1.9.4.3 and earlier have a path traversal vulnerability. Successful exploitation could lead to sensitive information disclosure.

  • CVE-2020-1606MedJan 15, 2020
    risk 0.35cvss 5.4epss 0.01

    A path traversal vulnerability in the Juniper Networks Junos OS device may allow an authenticated J-web user to read files with 'world' readable permission and delete files with 'world' writeable permission. This issue does not affect system files that can be accessed only by…

  • CVE-2019-19845MedDec 18, 2019
    risk 0.35cvss 5.3epss 0.01

    In Joomla! before 3.9.14, a missing access check in framework files could lead to a path disclosure.

  • CVE-2019-13944MedDec 12, 2019
    risk 0.35cvss 5.3epss 0.02

    A vulnerability has been identified in EN100 Ethernet module DNP3 variant (All versions), EN100 Ethernet module IEC 61850 variant (All versions < V4.37), EN100 Ethernet module IEC104 variant (All versions), EN100 Ethernet module Modbus TCP variant (All versions), EN100 Ethernet…

  • CVE-2015-2060MedNov 29, 2019
    risk 0.35cvss 5.3epss 0.02

    cabextract before 1.6 does not properly check for leading slashes when extracting files, which allows remote attackers to conduct absolute directory traversal attacks via a malformed UTF-8 character that is changed to a UTF-8 encoded slash.

  • CVE-2019-17406MedNov 25, 2019
    risk 0.35cvss 5.3epss 0.01

    Nokia IMPACT < 18A has path traversal that may lead to RCE if chained with CVE-2019-1743

  • CVE-2019-16540MedNov 21, 2019
    risk 0.35cvss 6.5epss 0.02

    A path traversal vulnerability in Jenkins Support Core Plugin 2.63 and earlier allows attackers with Overall/Read permission to delete arbitrary files on the Jenkins master.

  • CVE-2019-3423MedNov 18, 2019
    risk 0.35cvss 5.3epss 0.01

    permission and access control vulnerability, which exists in V2.1.14 and below versions of C520V21 smart camera devices. An attacker can construct a URL for directory traversal and access to other unauthorized files or resources.