VYPR

CWE-22

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')

BaseStableLikelihood: High

Description

The product uses external input to construct a pathname that is intended to identify a file or directory that is located underneath a restricted parent directory, but the product does not properly neutralize special elements within the pathname that can cause the pathname to resolve to a location that is outside of the restricted directory.

Hierarchy (View 1000)

Parents

Children

Related attack patterns (CAPEC)

CAPEC-126 · CAPEC-64 · CAPEC-76 · CAPEC-78 · CAPEC-79

CVEs mapped to this weakness (10,485)

page 364 of 525
  • CVE-2019-20354MedJan 6, 2020
    risk 0.32cvss 4.3epss 0.09

    The web application component of piSignage before 2.6.4 allows a remote attacker (authenticated as a low-privilege user) to download arbitrary files from the Raspberry Pi via api/settings/log?file=../ path traversal. In other words, this issue is in the player API for log…

  • CVE-2014-9014MedNov 6, 2019
    risk 0.32cvss 4.3epss 0.12

    Directory traversal vulnerability in the ajaxinit function in wpmarketplace/libs/cart.php in the WP Marketplace plugin before 2.4.1 for WordPress allows remote authenticated users to download arbitrary files via a .. (dot dot) in the file parameter.

  • CVE-2019-12691MedOct 2, 2019
    risk 0.32cvss 4.9epss 0.05

    A vulnerability in the web-based management interface of Cisco Firepower Management Center (FMC) Software could allow an authenticated, remote attacker to perform a directory traversal attack on an affected device. The vulnerability is due to insufficient input validation by the…

  • CVE-2019-11327MedSep 20, 2019
    risk 0.32cvss 4.9epss 0.01

    An issue was discovered on Topcon Positioning Net-G5 GNSS Receiver devices with firmware 5.2.2. The web interface of the product has a local file inclusion vulnerability. An attacker with administrative privileges can craft a special URL to read arbitrary files from the device's…

  • CVE-2019-16105MedSep 8, 2019
    risk 0.32cvss 4.9epss 0.02

    Silver Peak EdgeConnect SD-WAN before 8.1.7.x allows ..%2f directory traversal via a rest/json/configdb/download/ URI.

  • CVE-2019-13237MedAug 27, 2019
    risk 0.32cvss 4.3epss 0.07

    In Alkacon OpenCms 10.5.4 and 10.5.5, there are multiple resources vulnerable to Local File Inclusion that allow an attacker to access server resources: clearhistory.jsp, convertxml.jsp, group_new.jsp, loginmessage.jsp, xmlcontentrepair.jsp, and…

  • CVE-2019-14798MedAug 9, 2019
    risk 0.32cvss 4.9epss 0.04

    The 10Web Photo Gallery plugin before 1.5.25 for WordPress has Authenticated Local File Inclusion via directory traversal in the wp-admin/admin-ajax.php?action=shortcode_bwg tagtext parameter.

  • CVE-2019-12309MedMay 23, 2019
    risk 0.32cvss 4.9epss 0.01

    dotCMS before 5.1.0 has a path traversal vulnerability exploitable by an administrator to create files. The vulnerability is caused by the insecure extraction of a ZIP archive.

  • CVE-2019-8925MedMay 17, 2019
    risk 0.32cvss 4.3epss 0.12

    An issue was discovered in Zoho ManageEngine Netflow Analyzer Professional 7.0.0.2. An Absolute Path Traversal vulnerability in the Administration zone, in /netflow/servlet/CReportPDFServlet (via the parameter schFilePath), allows remote authenticated users to bypass intended…

  • CVE-2019-11624MedApr 30, 2019
    risk 0.32cvss 4.9epss 0.02

    doorGets 7.0 has an arbitrary file deletion vulnerability in /doorgets/app/requests/user/configurationRequest.php. A remote background administrator privilege user can exploit this vulnerability to delete arbitrary files.

  • CVE-2019-3720MedApr 25, 2019
    risk 0.32cvss 4.9epss 0.03

    Dell EMC Open Manage System Administrator (OMSA) versions prior to 9.3.0 contain a Directory Traversal Vulnerability. A remote authenticated malicious user with admin privileges could potentially exploit this vulnerability to gain unauthorized access to the file system by…

  • CVE-2019-11515MedApr 25, 2019
    risk 0.32cvss 4.9epss 0.02

    core/classes/db_backup.php in Gila CMS 1.10.1 allows admin/db_backup?download= absolute path traversal to read arbitrary files.

  • CVE-2018-2006MedFeb 21, 2019
    risk 0.32cvss 4.9epss 0.02

    IBM Robotic Process Automation with Automation Anywhere 11 could allow a remote attacker to traverse directories on the system. An attacker could send a specially-crafted URL request containing "dot dot" sequences (/../) to upload arbitrary files to the system. IBM X-Force ID:…

  • CVE-2019-7403MedFeb 5, 2019
    risk 0.32cvss 4.9epss 0.02

    An issue was discovered in PHPMyWind 5.5. It allows remote attackers to delete arbitrary folders via an admin/database_backup.php?action=import&dopost=deldir&tbname=../ URI.

  • CVE-2018-20610MedDec 30, 2018
    risk 0.32cvss 4.9epss 0.02

    imcat 4.4 allows directory traversal via the root/run/adm.php efile parameter.

  • CVE-2018-20604MedDec 30, 2018
    risk 0.32cvss 4.9epss 0.01

    Lei Feng TV CMS (aka LFCMS) 3.8.6 allows Directory Traversal via crafted use of ..* in Template/edit/path URIs, as demonstrated by the admin.php?s=/Template/edit/path/*web*..*..*..*..*1.txt.html URI to read the 1.txt file.

  • CVE-2018-19329MedNov 17, 2018
    risk 0.32cvss 4.9epss 0.02

    GreenCMS v2.3.0603 allows remote authenticated administrators to delete arbitrary files by modifying a base64-encoded pathname in an m=admin&c=media&a=delfilehandle&id= call, related to the m=admin&c=media&a=restorefile delete button.

  • CVE-2018-19197MedNov 12, 2018
    risk 0.32cvss 4.9epss 0.01

    An issue was discovered in XiaoCms 20141229. admin\controller\database.php allows arbitrary directory deletion via admin/index.php?c=database&a=import&paths[]=../ directory traversal.

  • CVE-2018-11762MedSep 19, 2018
    risk 0.32cvss 5.9epss 0.05

    In Apache Tika 0.9 to 1.18, in a rare edge case where a user does not specify an extract directory on the commandline (--extract-dir=) and the input file has an embedded file with an absolute path, such as "C:/evil.bat", tika-app would overwrite that file.

  • CVE-2018-16819MedSep 18, 2018
    risk 0.32cvss 4.9epss 0.01

    admin/index.php in Monstra CMS 3.0.4 allows arbitrary file deletion via id=filesmanager&path=uploads/.......//./.......//./&delete_file= requests.