VYPR

CWE-22

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')

BaseStableLikelihood: High

Description

The product uses external input to construct a pathname that is intended to identify a file or directory that is located underneath a restricted parent directory, but the product does not properly neutralize special elements within the pathname that can cause the pathname to resolve to a location that is outside of the restricted directory.

Hierarchy (View 1000)

Parents

Children

Related attack patterns (CAPEC)

CAPEC-126 · CAPEC-64 · CAPEC-76 · CAPEC-78 · CAPEC-79

CVEs mapped to this weakness (10,485)

page 350 of 525
  • CVE-2024-3737MedApr 13, 2024
    risk 0.34cvss 6.3epss 0.01

    A vulnerability was found in cym1102 nginxWebUI up to 3.9.9. It has been rated as critical. Affected by this issue is the function findCountByQuery of the file /adminPage/www/addOver. The manipulation of the argument dir leads to path traversal. The attack may be launched…

  • CVE-2024-31462MedApr 12, 2024
    risk 0.34cvss 6.3epss 0.01

    stable-diffusion-webui is a web interface for Stable Diffusion, implemented using Gradio library. Stable-diffusion-webui 1.7.0 is vulnerable to a limited file write affecting Windows systems. The create_ui method (Backup/Restore tab) in modules/ui_extensions.py takes user input…

  • CVE-2024-23540MedApr 3, 2024
    risk 0.34cvss 5.3epss 0.01

    The HCL BigFix Inventory server is vulnerable to path traversal which enables an attacker to read internal application files from the Inventory server. The BigFix Inventory server does not properly restrict the served static file.

  • CVE-2023-35812MedApr 3, 2024
    risk 0.34cvss 5.3epss 0.00

    An issue was discovered in the Amazon Linux packages of OpenSSH 7.4 for Amazon Linux 1 and 2, because of an incomplete fix for CVE-2019-6111 within these specific packages. The fix had only covered cases where an absolute path is passed to scp. When a relative path is used,…

  • CVE-2024-25154MedMar 13, 2024
    risk 0.34cvss 5.3epss 0.00

    Improper URL validation leads to path traversal in FileCatalyst Direct 3.8.8 and earlier allowing an encoded payload to cause the web server to return files located outside of the web root which may lead to data leakage.  

  • CVE-2023-5390MedJan 31, 2024
    risk 0.34cvss 5.3epss 0.01

    An attacker could potentially exploit this vulnerability, leading to files being read from the Honeywell Experion ControlEdge VirtualUOC and ControlEdge UOC. This exploit could be used to read files from the controller that may expose limited information from the device.…

  • CVE-2023-5115MedDec 18, 2023
    risk 0.34cvss 6.3epss 0.01

    An absolute path traversal attack exists in the Ansible automation platform. This flaw allows an attacker to craft a malicious Ansible role and make the victim execute the role. A symlink can be used to overwrite a file outside of the extraction path.

  • CVE-2023-6893MedDec 17, 2023
    risk 0.34cvss 4.3epss 0.70

    A vulnerability was found in Hikvision Intercom Broadcasting System 3.0.3_20201113_RELEASE(HIK) and classified as problematic. Affected by this issue is some unknown functionality of the file /php/exportrecord.php. The manipulation of the argument downname with the input…

  • CVE-2023-6407MedDec 14, 2023
    risk 0.34cvss 5.3epss 0.00

    A CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability exists that could cause arbitrary file deletion upon service restart when accessed by a local and low-privileged attacker.

  • CVE-2023-6032MedNov 15, 2023
    risk 0.34cvss 5.3epss 0.01

    A CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability exists that could cause a file system enumeration and file download when an attacker navigates to the Network Management Card via HTTPS.

  • CVE-2023-41888MedSep 27, 2023
    risk 0.34cvss 5.3epss 0.00

    GLPI stands for Gestionnaire Libre de Parc Informatique is a Free Asset and IT Management Software package, that provides ITIL Service Desk features, licenses tracking and software auditing. The lack of path filtering on the GLPI URL may allow an attacker to transmit a malicious…

  • CVE-2023-4782MedSep 8, 2023
    risk 0.34cvss 6.3epss 0.00

    Terraform version 1.0.8 through 1.5.6 allows arbitrary file write during the `init` operation if run on maliciously crafted Terraform configuration. This vulnerability is fixed in Terraform 1.5.7.

  • CVE-2023-39559MedAug 29, 2023
    risk 0.34cvss 5.3epss 0.01

    AudimexEE 15.0 was discovered to contain a full path disclosure vulnerability.

  • CVE-2023-38708MedAug 4, 2023
    risk 0.34cvss 6.3epss 0.01

    Pimcore is an Open Source Data & Experience Management Platform: PIM, MDM, CDP, DAM, DXP/CMS & Digital Commerce. A path traversal vulnerability exists in the `AssetController::importServerFilesAction`, which allows an attacker to overwrite or modify sensitive files by…

  • CVE-2023-27311MedMay 26, 2023
    risk 0.34cvss 5.3epss 0.01

    NetApp Blue XP Connector versions prior to 3.9.25 expose information via a directory listing. A new Connector architecture resolves this issue - obtaining the fix requires redeploying a fresh Connector.

  • CVE-2015-10105MedMay 1, 2023
    risk 0.34cvss 6.3epss 0.01

    A vulnerability, which was classified as critical, was found in IP Blacklist Cloud Plugin up to 3.42 on WordPress. This affects the function valid_js_identifier of the file ip_blacklist_cloud.php of the component CSV File Import. The manipulation of the argument filename leads…

  • CVE-2022-48361MedMar 27, 2023
    risk 0.34cvss 5.3epss 0.00

    The Always On Display (AOD) has a path traversal vulnerability in theme files. Successful exploitation of this vulnerability may cause a failure in reading AOD theme resources.

  • CVE-2017-20181MedMar 7, 2023
    risk 0.34cvss 5.3epss 0.00

    A vulnerability classified as critical was found in hgzojer Vocable Trainer up to 1.3.0 on Android. This vulnerability affects unknown code of the file src/at/hgz/vocabletrainer/VocableTrainerProvider.java. The manipulation leads to path traversal. Attacking locally is a…

  • CVE-2023-26265MedFeb 21, 2023
    risk 0.34cvss 5.3epss 0.01

    The Borg theme before 1.1.19 for Backdrop CMS does not sufficiently sanitize path arguments that are passed in via a URL. The function borg_preprocess_page in the file template.php does not properly sanitize incoming path arguments before using them.

  • CVE-2022-30299MedFeb 16, 2023
    risk 0.34cvss 5.3epss 0.00

    A path traversal vulnerability [CWE-23] in the API of FortiWeb 7.0.0 through 7.0.1, 6.3.0 through 6.3.19, 6.4 all versions, 6.2 all versions, 6.1 all versions, 6.0 all versions may allow an authenticated attacker to retrieve specific parts of files from the underlying file…