VYPR

CWE-22

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')

BaseStableLikelihood: High

Description

The product uses external input to construct a pathname that is intended to identify a file or directory that is located underneath a restricted parent directory, but the product does not properly neutralize special elements within the pathname that can cause the pathname to resolve to a location that is outside of the restricted directory.

Hierarchy (View 1000)

Parents

Children

Related attack patterns (CAPEC)

CAPEC-126 · CAPEC-64 · CAPEC-76 · CAPEC-78 · CAPEC-79

CVEs mapped to this weakness (10,485)

page 361 of 525
  • CVE-2023-20087MedMay 18, 2023
    risk 0.32cvss 4.9epss 0.01

    Multiple vulnerabilities in the web-based management interface of Cisco Identity Services Engine (ISE) could allow an authenticated, remote attacker to download arbitrary files from the filesystem of an affected device. These vulnerabilities are due to insufficient input…

  • CVE-2023-20077MedMay 18, 2023
    risk 0.32cvss 4.9epss 0.01

    Multiple vulnerabilities in the web-based management interface of Cisco Identity Services Engine (ISE) could allow an authenticated, remote attacker to download arbitrary files from the filesystem of an affected device. These vulnerabilities are due to insufficient input…

  • CVE-2023-30509MedMay 16, 2023
    risk 0.32cvss 4.9epss 0.01

    Multiple authenticated path traversal vulnerabilities exist in the Aruba EdgeConnect Enterprise command line interface. Successful exploitation of these vulnerabilities result in the ability to read arbitrary files on the underlying operating system, including sensitive system…

  • CVE-2023-30508MedMay 16, 2023
    risk 0.32cvss 4.9epss 0.01

    Multiple authenticated path traversal vulnerabilities exist in the Aruba EdgeConnect Enterprise command line interface. Successful exploitation of these vulnerabilities result in the ability to read arbitrary files on the underlying operating system, including sensitive system…

  • CVE-2023-30507MedMay 16, 2023
    risk 0.32cvss 4.9epss 0.01

    Multiple authenticated path traversal vulnerabilities exist in the Aruba EdgeConnect Enterprise command line interface. Successful exploitation of these vulnerabilities result in the ability to read arbitrary files on the underlying operating system, including sensitive system…

  • CVE-2023-22901MedApr 27, 2023
    risk 0.32cvss 4.9epss 0.01

    ChangingTec MOTP system has a path traversal vulnerability. A remote attacker with administrator’s privilege can exploit this vulnerability to access arbitrary system files.

  • CVE-2022-47595MedMar 14, 2023
    risk 0.32cvss 4.9epss 0.01

    Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in WP Go Maps (formerly WP Google Maps) plugin <= 9.0.15 versions.

  • CVE-2023-23760MedMar 8, 2023
    risk 0.32cvss 4.9epss 0.01

    A path traversal vulnerability was identified in GitHub Enterprise Server that allowed remote code execution when building a GitHub Pages site. To exploit this vulnerability, an attacker would need permission to create and build a GitHub Pages site on the GitHub Enterprise…

  • CVE-2023-22776MedMar 1, 2023
    risk 0.32cvss 4.9epss 0.01

    An authenticated path traversal vulnerability exists in the ArubaOS command line interface. Successful exploitation of this vulnerability results in the ability to read arbitrary files on the underlying operating system, including sensitive system files.

  • CVE-2022-44299MedFeb 16, 2023
    risk 0.32cvss 4.9epss 0.01

    SiteServerCMS 7.1.3 sscms has a file read vulnerability.

  • CVE-2023-23778MedFeb 16, 2023
    risk 0.32cvss 4.9epss 0.01

    A relative path traversal vulnerability [CWE-23] in FortiWeb version 7.0.1 and below, 6.4 all versions, 6.3 all versions, 6.2 all versions may allow an authenticated user to obtain unauthorized access to files and data via specifically crafted web requests.

  • CVE-2022-44532MedDec 12, 2022
    risk 0.32cvss 4.9epss 0.01

    An authenticated path traversal vulnerability exists in the Aruba EdgeConnect Enterprise command line interface. Successful exploitation of this vulnerability results in the ability to read arbitrary files on the underlying operating system, including sensitive system files in…

  • CVE-2022-43518MedDec 12, 2022
    risk 0.32cvss 4.9epss 0.01

    An authenticated path traversal vulnerability exists in the Aruba EdgeConnect Enterprise web interface. Successful exploitation of this vulnerability results in the ability to read arbitrary files on the underlying operating system, including sensitive system files in Aruba…

  • CVE-2022-42706MedDec 5, 2022
    risk 0.32cvss 4.9epss 0.01

    An issue was discovered in Sangoma Asterisk through 16.28, 17 and 18 through 18.14, 19 through 19.6, and certified through 18.9-cert1. GetConfig, via Asterisk Manager Interface, allows a connected application to access files outside of the asterisk configuration directory, aka…

  • CVE-2022-41212MedNov 8, 2022
    risk 0.32cvss 4.9epss 0.01

    Due to insufficient input validation, SAP NetWeaver Application Server ABAP and ABAP Platform allows an attacker with high level privileges to use a remote enabled function to read a file which is otherwise restricted. On successful exploitation an attacker can completely…

  • CVE-2022-2554MedOct 10, 2022
    risk 0.32cvss 4.9epss 0.01

    The Enable Media Replace WordPress plugin before 4.0.0 does not ensure that renamed files are moved to the Upload folder, which could allow high privilege users such as admin to move them outside to the web root directory via a path traversal attack for example

  • CVE-2022-2926MedSep 26, 2022
    risk 0.32cvss 4.9epss 0.02

    The Download Manager WordPress plugin before 3.2.55 does not validate one of its settings, which could allow high privilege users such as admin to list and read arbitrary files and folders outside of the blog directory

  • CVE-2022-2945MedSep 6, 2022
    risk 0.32cvss 4.9epss 0.02

    The WordPress Infinite Scroll – Ajax Load More plugin for WordPress is vulnerable to Directory Traversal in versions up to, and including, 5.5.3 via the 'type' parameter found in the alm_get_layout() function. This makes it possible for authenticated attackers, with…

  • CVE-2022-2943MedSep 6, 2022
    risk 0.32cvss 4.9epss 0.02

    The WordPress Infinite Scroll – Ajax Load More plugin for Wordpress is vulnerable to arbitrary file reading in versions up to, and including, 5.5.3 due to insufficient file path validation on the alm_repeaters_export() function. This makes it possible for authenticated…

  • CVE-2022-35235MedAug 23, 2022
    risk 0.32cvss 4.9epss 0.01

    Authenticated (admin+) Arbitrary File Read vulnerability in XplodedThemes WPide plugin <= 2.6 at WordPress.