VYPR

CWE-22

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')

BaseStableLikelihood: High

Description

The product uses external input to construct a pathname that is intended to identify a file or directory that is located underneath a restricted parent directory, but the product does not properly neutralize special elements within the pathname that can cause the pathname to resolve to a location that is outside of the restricted directory.

Hierarchy (View 1000)

Parents

Children

Related attack patterns (CAPEC)

CAPEC-126 · CAPEC-64 · CAPEC-76 · CAPEC-78 · CAPEC-79

CVEs mapped to this weakness (10,485)

page 363 of 525
  • CVE-2021-20511MedJul 15, 2021
    risk 0.32cvss 4.9epss 0.02

    IBM Security Verify Access Docker 10.0.0 could allow a remote attacker to traverse directories on the system. An attacker could send a specially-crafted URL request containing "dot dot" sequences (/../) to view arbitrary files on the system. IBM X-Force ID: 198300.

  • CVE-2020-4993MedMay 5, 2021
    risk 0.32cvss 4.9epss 0.01

    IBM QRadar SIEM 7.3 and 7.4 when decompressing or verifying signature of zip files processes data in a way that may be vulnerable to path traversal attacks. IBM X-Force ID: 192905.

  • CVE-2021-29425MedApr 13, 2021
    risk 0.32cvss 4.8epss 0.11

    In Apache Commons IO before 2.7, When invoking the method FileNameUtils.normalize with an improper input string, like "//../foo", or "\\..\foo", the result would be the same value, thus possibly providing access to files in the parent directory, but not further above (thus…

  • CVE-2021-28209MedApr 6, 2021
    risk 0.32cvss 4.9epss 0.02

    The specific function in ASUS BMC’s firmware Web management page (Delete video file function) does not filter the specific parameter. As obtaining the administrator permission, remote attackers can use the means of path traversal to access system files.

  • CVE-2021-28208MedApr 6, 2021
    risk 0.32cvss 4.9epss 0.02

    The specific function in ASUS BMC’s firmware Web management page (Get video file function) does not filter the specific parameter. As obtaining the administrator permission, remote attackers can use the means of path traversal to access system files.

  • CVE-2021-28207MedApr 6, 2021
    risk 0.32cvss 4.9epss 0.02

    The specific function in ASUS BMC’s firmware Web management page (Get Help file function) does not filter the specific parameter. As obtaining the administrator permission, remote attackers can use the means of path traversal to access system files.

  • CVE-2021-28206MedApr 6, 2021
    risk 0.32cvss 4.9epss 0.02

    The specific function in ASUS BMC’s firmware Web management page (Record video file function) does not filter the specific parameter. As obtaining the administrator permission, remote attackers can use the means of path traversal to access system files.

  • CVE-2021-28205MedApr 6, 2021
    risk 0.32cvss 4.9epss 0.02

    The specific function in ASUS BMC’s firmware Web management page (Delete SOL video file function) does not filter the specific parameter. As obtaining the administrator permission, remote attackers can use the means of path traversal to access system files.

  • CVE-2021-21514MedMar 2, 2021
    risk 0.32cvss 4.9epss 0.05

    Dell EMC OpenManage Server Administrator (OMSA) versions 9.5 and prior contain a path traversal vulnerability. A remote user with admin privileges could potentially exploit this vulnerability to view arbitrary files on the target system by sending a specially crafted URL request.

  • CVE-2020-8567MedJan 21, 2021
    risk 0.32cvss 4.9epss 0.01

    Kubernetes Secrets Store CSI Driver Vault Plugin prior to v0.0.6, Azure Plugin prior to v0.0.10, and GCP Plugin prior to v0.2.0 allow an attacker who can create specially-crafted SecretProviderClass objects to write to arbitrary file paths on the host filesystem, including…

  • CVE-2020-35709MedDec 25, 2020
    risk 0.32cvss 4.9epss 0.01

    bloofoxCMS 0.5.2.1 allows admins to upload arbitrary .php files (with "Content-Type: application/octet-stream") to ../media/images/ via the admin/index.php?mode=tools&page=upload URI, aka directory traversal.

  • CVE-2020-21244MedSep 30, 2020
    risk 0.32cvss 4.9epss 0.01

    An issue was discovered in FrontAccounting 2.4.7. There is a Directory Traversal vulnerability that can empty folder via admin/inst_lang.php.

  • CVE-2020-3490MedAug 26, 2020
    risk 0.32cvss 4.9epss 0.03

    A vulnerability in the web-based management interface of Cisco Vision Dynamic Signage Director could allow an authenticated, remote attacker with administrative privileges to conduct directory traversal attacks and obtain read access to sensitive files on an affected system. The…

  • CVE-2020-8221MedJul 30, 2020
    risk 0.32cvss 4.9epss 0.02

    A path traversal vulnerability exists in Pulse Connect Secure <9.1R8 which allows an authenticated attacker to read arbitrary files via the administrator web interface.

  • CVE-2020-5588MedJun 30, 2020
    risk 0.32cvss 4.9epss 0.01

    Path traversal vulnerability in Cybozu Garoon 5.0.0 to 5.0.1 allows attacker with administrator rights to obtain unintended information via unspecified vectors.

  • CVE-2020-15026MedJun 24, 2020
    risk 0.32cvss 4.9epss 0.01

    Bludit 3.12.0 allows admins to use a /plugin-backup-download?file=../ directory traversal approach for arbitrary file download via backup/plugin.php.

  • CVE-2020-14946MedJun 22, 2020
    risk 0.32cvss 4.3epss 0.08

    downloadFile.ashx in the Administrator section of the Surveillance module in Global RADAR BSA Radar 1.6.7234.24750 and earlier allows users to download transaction files. When downloading the files, a user is able to view local files on the web server by manipulating the…

  • CVE-2020-5744MedMay 7, 2020
    risk 0.32cvss 4.9epss 0.01

    Relative Path Traversal in TCExam 14.2.2 allows a remote, authenticated attacker to read the contents of arbitrary files on disk.

  • CVE-2020-5284MedMar 30, 2020
    risk 0.32cvss 4.4epss 0.45

    Next.js versions before 9.3.2 have a directory traversal vulnerability. Attackers could craft special requests to access files in the dist directory (.next). This does not affect files outside of the dist directory (.next). In general, the dist directory only holds build assets…

  • CVE-2019-4674MedFeb 4, 2020
    risk 0.32cvss 4.9epss 0.02

    IBM Security Identity Manager 7.0.1 could allow a remote attacker to traverse directories on the system. An attacker could send a specially-crafted URL request containing "dot dot" sequences (/../) to view arbitrary files on the system. IBM X-Force ID: 171510.