VYPR

CWE-22

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')

BaseStableLikelihood: High

Description

The product uses external input to construct a pathname that is intended to identify a file or directory that is located underneath a restricted parent directory, but the product does not properly neutralize special elements within the pathname that can cause the pathname to resolve to a location that is outside of the restricted directory.

Hierarchy (View 1000)

Parents

Children

Related attack patterns (CAPEC)

CAPEC-126 · CAPEC-64 · CAPEC-76 · CAPEC-78 · CAPEC-79

CVEs mapped to this weakness (10,485)

page 340 of 525
  • CVE-2019-5447MedJul 15, 2019
    risk 0.35cvss 5.3epss 0.01

    A path traversal vulnerability in <= v0.2.6 of http-file-server npm module allows attackers to list files in arbitrary folders.

  • CVE-2019-5444MedJul 10, 2019
    risk 0.35cvss 5.3epss 0.01

    Path traversal vulnerability in version up to v1.1.3 in serve-here.js npm module allows attackers to list any file in arbitrary folder.

  • CVE-2018-18876MedJun 18, 2019
    risk 0.35cvss 5.3epss 0.02

    In firmware version MS_2.6.9900 of Columbia Weather MicroServer, a readouts_rd.php directory traversal issue makes it possible to read any file present on the underlying operating system.

  • CVE-2019-12143MedJun 11, 2019
    risk 0.35cvss 5.3epss 0.02

    A Directory Traversal issue was discovered in SSHServerAPI.dll in Progress ipswitch WS_FTP Server 2018 before 8.6.1. An attacker can supply a string using special patterns via the SCP protocol to disclose WS_FTP usernames as well as filenames.

  • CVE-2019-12459MedMay 30, 2019
    risk 0.35cvss 5.3epss 0.02

    FileRun 2019.05.21 allows customizables/plugins/audio_player Directory Listing. This issue has been fixed in FileRun 2019.06.01.

  • CVE-2019-12458MedMay 30, 2019
    risk 0.35cvss 5.3epss 0.02

    FileRun 2019.05.21 allows css/ext-ux Directory Listing. This issue has been fixed in FileRun 2019.06.01.

  • CVE-2019-12457MedMay 30, 2019
    risk 0.35cvss 5.3epss 0.02

    FileRun 2019.05.21 allows images/extjs Directory Listing. This issue has been fixed in FileRun 2019.06.01.

  • CVE-2019-5936MedMay 17, 2019
    risk 0.35cvss 5.4epss 0.02

    Directory traversal vulnerability in Cybozu Garoon 4.0.0 to 4.10.1 allows remote authenticated attackers to obtain files without access privileges via the application 'Work Flow'.

  • CVE-2018-17180MedMay 17, 2019
    risk 0.35cvss 5.3epss 0.02

    An issue was discovered in OpenEMR before 5.0.1 Patch 7. Directory Traversal exists via docid=../ to /portal/lib/download_template.php.

  • CVE-2019-5438MedMay 10, 2019
    risk 0.35cvss 5.3epss 0.01

    Path traversal using symlink in npm harp module versions <= 0.29.0.

  • CVE-2019-10242MedApr 9, 2019
    risk 0.35cvss 5.3epss 0.02

    In Eclipse Kura versions up to 4.0.0, the SkinServlet did not checked the path passed during servlet call, potentially allowing path traversal in get requests for a limited number of file types.

  • CVE-2018-20631MedMar 21, 2019
    risk 0.35cvss 5.3epss 0.02

    PHP Scripts Mall Website Seller Script 2.0.5 allows full Path Disclosure via a request for an arbitrary image URL such as a .png file.

  • CVE-2018-20630MedMar 21, 2019
    risk 0.35cvss 5.3epss 0.02

    PHP Scripts Mall Advance Crowdfunding Script 2.0.3 has directory traversal via a direct request for a listing of an uploads directory such as the wp-content/uploads/2018/12 directory.

  • CVE-2018-20629MedMar 21, 2019
    risk 0.35cvss 5.3epss 0.02

    PHP Scripts Mall Charity Donation Script readymadeb2bscript has directory traversal via a direct request for a listing of an uploads directory such as the wp-content/uploads/2018/12 directory.

  • CVE-2019-9607MedMar 6, 2019
    risk 0.35cvss 5.3epss 0.02

    PHP Scripts Mall Medical Store Script 3.0.3 allows Path Traversal by navigating to the parent directory of a jpg or png file.

  • CVE-2019-9064MedFeb 23, 2019
    risk 0.35cvss 5.3epss 0.02

    PHP Scripts Mall Cab Booking Script 1.0.3 allows Directory Traversal into the parent directory of a jpg or png file.

  • CVE-2013-2565MedFeb 15, 2019
    risk 0.35cvss 5.3epss 0.02

    A vulnerability in Mambo CMS v4.6.5 where the scripts thumbs.php, editorFrame.php, editor.php, images.php, manager.php discloses the root path of the webserver.

  • CVE-2015-9275MedJan 7, 2019
    risk 0.35cvss 5.3epss 0.02

    ARC 5.21q allows directory traversal via a full pathname in an archive file.

  • CVE-2018-20566MedDec 28, 2018
    risk 0.35cvss 5.3epss 0.01

    An issue was discovered in DouCo DouPHP 1.5 20181221. It allows full path disclosure in "Smarty error: unable to read resource" error messages for a crafted installation page.

  • CVE-2018-19859MedDec 5, 2018
    risk 0.35cvss 6.5epss 0.02

    OpenRefine before 3.2 beta allows directory traversal via a relative pathname in a ZIP archive.