VYPR

CWE-22

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')

BaseStableLikelihood: High

Description

The product uses external input to construct a pathname that is intended to identify a file or directory that is located underneath a restricted parent directory, but the product does not properly neutralize special elements within the pathname that can cause the pathname to resolve to a location that is outside of the restricted directory.

Hierarchy (View 1000)

Parents

Children

Related attack patterns (CAPEC)

CAPEC-126 · CAPEC-64 · CAPEC-76 · CAPEC-78 · CAPEC-79

CVEs mapped to this weakness (10,485)

page 339 of 525
  • CVE-2019-18924MedNov 12, 2019
    risk 0.35cvss 5.3epss 0.01

    Systematic IRIS WebForms 5.4 is vulnerable to directory traversal. By manipulating variables that reference files with ../ (and variations), it is possible to list all the directories and check if a particular file exists.

  • CVE-2019-15003MedNov 7, 2019
    risk 0.35cvss 5.3epss 0.02

    The Customer Context Filter in Atlassian Jira Service Desk Server and Jira Service Desk Data Center before 3.9.17, from 3.10.0 before 3.16.10, from 4.0.0 before 4.2.6, from 4.3.0 before 4.3.5, from 4.4.0 before 4.4.3, and from 4.5.0 before 4.5.1 allows remote attackers with…

  • CVE-2019-17224MedOct 28, 2019
    risk 0.35cvss 5.3epss 0.01

    The web interface of the Compal Broadband CH7465LG modem (version CH7465LG-NCIP-6.12.18.25-2p6-NOSH) is vulnerable to a /%2f/ path traversal attack, which can be exploited in order to test for the existence of a file pathname outside of the web root directory. If a file exists…

  • CVE-2019-18212MedOct 23, 2019
    risk 0.35cvss 6.5epss 0.03

    XMLLanguageService.java in XML Language Server (aka lsp4xml) before 0.9.1, as used in Red Hat XML Language Support (aka vscode-xml) before 0.9.1 for Visual Studio and other products, allows a remote attacker to write to arbitrary files via Directory Traversal.

  • CVE-2019-16986MedOct 21, 2019
    risk 0.35cvss 6.5epss 0.01

    In FusionPBX up to v4.5.7, the file resources\download.php uses an unsanitized "f" variable coming from the URL, which takes any pathname and allows a download of it. (resources\secure_download.php is also affected.)

  • CVE-2019-16985MedOct 21, 2019
    risk 0.35cvss 6.5epss 0.01

    In FusionPBX up to v4.5.7, the file app\xml_cdr\xml_cdr_delete.php uses an unsanitized "rec" variable coming from the URL, which is base64 decoded and allows deletion of any file of the system.

  • CVE-2019-16990MedOct 21, 2019
    risk 0.35cvss 6.5epss 0.01

    In FusionPBX up to v4.5.7, the file app/music_on_hold/music_on_hold.php uses an unsanitized "file" variable coming from the URL, which takes any pathname (base64 encoded) and allows a download of it.

  • CVE-2019-10436MedOct 16, 2019
    risk 0.35cvss 6.5epss 0.01

    An arbitrary file read vulnerability in Jenkins Google OAuth Credentials Plugin 0.9 and earlier allowed attackers able to configure jobs and credentials in Jenkins to obtain the contents of any file on the Jenkins master.

  • CVE-2019-17109MedOct 9, 2019
    risk 0.35cvss 6.5epss 0.03

    Koji through 1.18.0 allows remote Directory Traversal, with resultant Privilege Escalation.

  • CVE-2019-4423MedSep 30, 2019
    risk 0.35cvss 5.3epss 0.03

    IBM Sterling File Gateway 2.2.0.0 through 6.0.1.0 could allow a remote attacker to traverse directories on the system. An attacker could send a specially-crafted URL request containing "dot dot" sequences (/../) to view arbitrary files on the system. IBM X-Force ID: 162769.

  • CVE-2019-16903MedSep 26, 2019
    risk 0.35cvss 5.3epss 0.02

    Platinum UPnP SDK 1.2.0 allows Directory Traversal in Core/PltHttpServer.cpp because it checks for /.. where it should be checking for ../ instead.

  • CVE-2019-16679MedSep 21, 2019
    risk 0.35cvss 4.9epss 0.07

    Gila CMS before 1.11.1 allows admin/fm/?f=../ directory traversal, leading to Local File Inclusion.

  • CVE-2019-4268MedSep 17, 2019
    risk 0.35cvss 5.3epss 0.03

    IBM WebSphere Application Server 7.0, 8.0, 8.5, and 9.0 could allow a remote attacker to traverse directories on the system. An attacker could send a specially-crafted URL containing "dot dot" sequences (/../) to view arbitrary files on the system. IBM X-Force ID: 160201.

  • CVE-2019-5480MedSep 3, 2019
    risk 0.35cvss 5.3epss 0.02

    A path traversal vulnerability in <= v0.9.7 of statichttpserver npm module allows attackers to list files in arbitrary folders.

  • CVE-2019-15714MedAug 28, 2019
    risk 0.35cvss 5.3epss 0.02

    cli/lib/main.js in Entropic before 2019-06-13 does not reject / and \ in command names, which might allow a directory traversal attack in unusual situations.

  • CVE-2019-15520MedAug 23, 2019
    risk 0.35cvss 5.3epss 0.02

    comelz Quark before 2019-03-26 allows directory traversal to locations outside of the project directory.

  • CVE-2019-15518MedAug 23, 2019
    risk 0.35cvss 5.3epss 0.02

    Swoole before 4.2.13 allows directory traversal in swPort_http_static_handler.

  • CVE-2017-18448MedAug 2, 2019
    risk 0.35cvss 5.3epss 0.01

    cPanel before 64.0.21 allows certain file-read operations via a Serverinfo_manpage API call (SEC-252).

  • CVE-2019-14362MedJul 28, 2019
    risk 0.35cvss 5.4epss 0.02

    Openbravo ERP before 3.0PR19Q1.3 is affected by Directory Traversal. This vulnerability could allow remote authenticated attackers to replace a file on the server via the getAttachmentDirectoryForNewAttachment inpKey value.

  • CVE-2019-13584MedJul 17, 2019
    risk 0.35cvss 5.3epss 0.03

    The remote admin webserver on FANUC Robotics Virtual Robot Controller 8.23 allows Directory Traversal via a forged HTTP request.