VYPR

CWE-22

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')

BaseStableLikelihood: High

Description

The product uses external input to construct a pathname that is intended to identify a file or directory that is located underneath a restricted parent directory, but the product does not properly neutralize special elements within the pathname that can cause the pathname to resolve to a location that is outside of the restricted directory.

Hierarchy (View 1000)

Parents

Children

Related attack patterns (CAPEC)

CAPEC-126 · CAPEC-64 · CAPEC-76 · CAPEC-78 · CAPEC-79

CVEs mapped to this weakness (10,485)

page 375 of 525
  • CVE-2020-36629MedDec 25, 2022
    risk 0.29cvss 5.5epss 0.01

    A vulnerability classified as critical was found in SimbCo httpster. This vulnerability affects the function fs.realpathSync of the file src/server.coffee. The manipulation leads to path traversal. The exploit has been disclosed to the public and may be used. The name of the…

  • CVE-2020-36628MedDec 25, 2022
    risk 0.29cvss 5.5epss 0.01

    A vulnerability classified as critical has been found in Calsign APDE. This affects the function handleExtract of the file APDE/src/main/java/com/calsignlabs/apde/build/dag/CopyBuildTask.java of the component ZIP File Handler. The manipulation leads to path traversal. Upgrading…

  • CVE-2022-20449MedDec 13, 2022
    risk 0.29cvss 4.4epss 0.00

    In writeApplicationRestrictionsLAr of UserManagerService.java, there is a possible overwrite of system files due to a path traversal error. This could lead to local denial of service with System execution privileges needed. User interaction is not needed for…

  • CVE-2022-4065MedNov 19, 2022
    risk 0.29cvss 5.5epss 0.01

    A vulnerability was found in cbeust testng 7.5.0/7.6.0/7.6.1/7.7.0. It has been declared as critical. Affected by this vulnerability is the function testngXmlExistsInJar of the file testng-core/src/main/java/org/testng/JarFileUtils.java of the component XML File Parser. The…

  • CVE-2017-20102MedJun 27, 2022
    risk 0.29cvss 4.4epss 0.00

    A vulnerability was found in Album Lock 4.0 and classified as critical. Affected by this issue is some unknown functionality of the file /getImage. The manipulation of the argument filePaht leads to path traversal. Attacking locally is a requirement. The exploit has been…

  • CVE-2022-0436MedApr 12, 2022
    risk 0.29cvss 5.5epss 0.01

    Path Traversal in GitHub repository gruntjs/grunt prior to 1.5.2.

  • CVE-2022-23409MedJan 31, 2022
    risk 0.29cvss 4.9epss 0.14

    The Logs plugin before 3.0.4 for Craft CMS allows remote attackers to read arbitrary files via input to actionStream in Controller.php.

  • CVE-2021-41087MedSep 21, 2021
    risk 0.29cvss 5.6epss 0.00

    in-toto-golang is a go implementation of the in-toto framework to protect software supply chain integrity. In affected versions authenticated attackers posing as functionaries (i.e., within a trusted set of users for a layout) are able to create attestations that may bypass…

  • CVE-2021-25450MedSep 9, 2021
    risk 0.29cvss 4.5epss 0.00

    Path traversal vulnerability in FactoryAirCommnadManger prior to SMR Sep-2021 Release 1 allows attackers to write file as system uid via remote socket.

  • CVE-2021-23423MedAug 16, 2021
    risk 0.29cvss 5.5epss 0.01

    This affects the package bikeshed before 3.0.0. This can occur when an untrusted source file containing include, include-code or include-raw block is processed. The contents of arbitrary files could be disclosed in the HTML output.

  • CVE-2021-1436MedMar 24, 2021
    risk 0.29cvss 4.4epss 0.00

    A vulnerability in the CLI of Cisco IOS XE SD-WAN Software could allow an authenticated, local attacker to conduct path traversal attacks and obtain read access to sensitive files on an affected system. This vulnerability is due to insufficient validation of user-supplied input.…

  • CVE-2021-26028MedMar 4, 2021
    risk 0.29cvss 5.5epss 0.01

    An issue was discovered in Joomla! 3.0.0 through 3.9.24. Extracting an specifilcy crafted zip package could write files outside of the intended path.

  • CVE-2020-36241MedFeb 5, 2021
    risk 0.29cvss 5.5epss 0.01

    autoar-extractor.c in GNOME gnome-autoar through 0.2.4, as used by GNOME Shell, Nautilus, and other software, allows Directory Traversal during extraction because it lacks a check of whether a file's parent is a symlink to a directory outside of the intended extraction location.

  • CVE-2019-10743MedOct 29, 2019
    risk 0.29cvss 5.5epss 0.06

    All versions of archiver allow attacker to perform a Zip Slip attack via the "unarchive" functions. It is exploited using a specially crafted zip archive, that holds path traversal filenames. When exploited, a filename in a malicious archive is concatenated to the target…

  • CVE-2019-18393MedOct 24, 2019
    risk 0.29cvss 5.3epss 0.14

    PluginServlet.java in Ignite Realtime Openfire through 4.4.2 does not ensure that retrieved files are located under the Openfire home directory, aka a directory traversal vulnerability.

  • CVE-2019-15266MedOct 16, 2019
    risk 0.29cvss 4.4epss 0.01

    A vulnerability in the CLI of Cisco Wireless LAN Controller (WLC) Software could allow an authenticated, local attacker to view system files that should be restricted. This vulnerability is due to improper sanitization of user-supplied input in command-line parameters that…

  • CVE-2019-1835MedApr 18, 2019
    risk 0.29cvss 4.4epss 0.01

    A vulnerability in the CLI of Cisco Aironet Access Points (APs) could allow an authenticated, local attacker to access sensitive information stored in an AP. The vulnerability is due to improper sanitization of user-supplied input in specific CLI commands. An attacker could…

  • CVE-2018-1002207MedJul 25, 2018
    risk 0.29cvss 5.5epss 0.03

    mholt/archiver golang package before e4ef56d48eb029648b0e895bb0b6a393ef0829c3 is vulnerable to directory traversal, allowing attackers to write to arbitrary files via a ../ (dot dot slash) in an archive entry that is mishandled during extraction. This vulnerability is also known…

  • CVE-2018-1002206MedJul 25, 2018
    risk 0.29cvss 5.5epss 0.09

    SharpCompress before 0.21.0 is vulnerable to directory traversal, allowing attackers to write to arbitrary files via a ../ (dot dot slash) in a Zip archive entry that is mishandled during extraction. This vulnerability is also known as 'Zip-Slip'.

  • CVE-2018-8008MedJun 5, 2018
    risk 0.29cvss 5.5epss 0.02

    Apache Storm version 1.0.6 and earlier, 1.2.1 and earlier, and version 1.1.2 and earlier expose an arbitrary file write vulnerability, that can be achieved using a specially crafted zip archive (affects other archives as well, bzip2, tar, xz, war, cpio, 7z), that holds path…