VYPR

CWE-22

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')

BaseStableLikelihood: High

Description

The product uses external input to construct a pathname that is intended to identify a file or directory that is located underneath a restricted parent directory, but the product does not properly neutralize special elements within the pathname that can cause the pathname to resolve to a location that is outside of the restricted directory.

Hierarchy (View 1000)

Parents

Children

Related attack patterns (CAPEC)

CAPEC-126 · CAPEC-64 · CAPEC-76 · CAPEC-78 · CAPEC-79

CVEs mapped to this weakness (10,395)

page 38 of 520
  • CVE-2022-31514CriJul 11, 2022
    risk 0.61cvss 9.3epss 0.01

    The Caoyongqi912/Fan_Platform repository through 2021-04-20 on GitHub allows absolute path traversal because the Flask send_file function is used unsafely.

  • CVE-2022-31513CriJul 11, 2022
    risk 0.61cvss 9.3epss 0.01

    The BolunHan/Krypton repository through 2021-06-03 on GitHub allows absolute path traversal because the Flask send_file function is used unsafely.

  • CVE-2022-31512CriJul 11, 2022
    risk 0.61cvss 9.3epss 0.01

    The Atom02/flask-mvc repository through 2020-09-14 on GitHub allows absolute path traversal because the Flask send_file function is used unsafely.

  • CVE-2022-31511CriJul 11, 2022
    risk 0.61cvss 9.3epss 0.01

    The AFDudley/equanimity repository through 2014-04-23 on GitHub allows absolute path traversal because the Flask send_file function is used unsafely.

  • CVE-2022-31509CriJul 11, 2022
    risk 0.61cvss 9.3epss 0.01

    The iedadata/usap-dc-website repository through 1.0.1 on GitHub allows absolute path traversal because the Flask send_file function is used unsafely.

  • CVE-2022-31505CriJul 11, 2022
    risk 0.61cvss 9.3epss 0.01

    The cheo0/MercadoEnLineaBack repository through 2022-05-04 on GitHub allows absolute path traversal because the Flask send_file function is used unsafely.

  • CVE-2021-42787CriMar 10, 2022
    risk 0.61cvss 9.4epss 0.01

    It was discovered that the SteelCentral AppInternals Dynamic Sampling Agent's (DSA) AgentConfigurationServlet has directory traversal vulnerabilities at the "/api/appInternals/1.0/agent/configuration" API. The affected endpoint does not have any input validation of the user's…

  • CVE-2022-23357CriFeb 3, 2022
    risk 0.61cvss 9.1epss 0.20

    mozilo2.0 was discovered to be vulnerable to directory traversal attacks via the parameter curent_dir.

  • CVE-2020-4000HigNov 24, 2020
    risk 0.61cvss 8.8epss 0.43

    The SD-WAN Orchestrator 3.3.2 prior to 3.3.2 P3, 3.4.x prior to 3.4.4, and 4.0.x prior to 4.0.1 allows for executing files through directory traversal. An authenticated SD-WAN Orchestrator user is able to traversal directories which may lead to code execution of files.

  • CVE-2019-7483HigKEVDec 19, 2019
    risk 0.61cvss 7.5epss 0.04

    In SonicWall SMA100, an unauthenticated Directory Traversal vulnerability in the handleWAFRedirect CGI allows the user to test for the presence of a file on the server.

  • CVE-2019-6274HigMar 21, 2019
    risk 0.61cvss 8.8epss 0.11

    Directory traversal vulnerability in storage_cgi in GL.iNet GL-AR300M-Lite devices with firmware 2.27 allows remote attackers to have unspecified impact via directory traversal sequences.

  • CVE-2018-19365CriMar 21, 2019
    risk 0.61cvss 9.1epss 0.22

    The REST API in Wowza Streaming Engine 4.7.4.01 allows traversal of the directory structure and retrieval of a file via a remote, specifically crafted HTTP request.

  • CVE-2018-18809MedKEVMar 7, 2019
    risk 0.61cvss 6.5epss 0.79

    The default server implementation of TIBCO Software Inc.'s TIBCO JasperReports Library, TIBCO JasperReports Library Community Edition, TIBCO JasperReports Library for ActiveMatrix BPM, TIBCO JasperReports Server, TIBCO JasperReports Server Community Edition, TIBCO JasperReports…

  • CVE-2018-14364CriJul 18, 2018
    risk 0.61cvss 9.8epss 0.50

    GitLab Community and Enterprise Edition before 10.7.7, 10.8.x before 10.8.6, and 11.x before 11.0.4 allows Directory Traversal with write access and resultant remote code execution via the GitLab projects import component.

  • CVE-2017-5261HigDec 20, 2017
    risk 0.61cvss 8.8epss 0.09

    In versions 4.3.2-R4 and prior of Cambium Networks cnPilot firmware, the 'ping' and 'traceroute' functions of the web administrative console expose a file path traversal vulnerability, accessible to all authenticated users.

  • CVE-2017-15276HigOct 13, 2017
    risk 0.61cvss 8.8epss 0.09

    OpenText Documentum Content Server (formerly EMC Documentum Content Server) through 7.3 contains the following design gap, which allows an authenticated user to gain superuser privileges: Content Server allows uploading content using batches (TAR archives). When unpacking TAR…

  • CVE-2016-4532CriJun 9, 2016
    risk 0.61cvss 9.1epss 0.28

    Directory traversal vulnerability in the WAP interface in Trihedral VTScada (formerly VTS) 8.x through 11.x before 11.2.02 allows remote attackers to read arbitrary files via a crafted pathname.

  • CVE-2013-3993MedKEVJul 7, 2014
    risk 0.61cvss 6.5epss 0.05

    IBM InfoSphere BigInsights before 2.1.0.3 allows remote authenticated users to bypass intended file and directory restrictions, or access untrusted data or code, via crafted parameters in unspecified API calls.

  • CVE-2026-70009CriSep 17, 2026
    risk 0.60cvss 9.3epss 0.00

    Improper limitation of a pathname to a restricted directory ('path traversal') in Azure Arc allows an unauthorized attacker to elevate privileges over a network.

  • CVE-2026-87984CriSep 11, 2026
    risk 0.60cvss —epss 0.00

    An arbitrary file write vulnerability in Mistral Vibe, introduced in version 1.3.4, allows an attacker to create or overwrite files outside the active workspace without user approval. Shell redirection destinations are omitted from permission checks, enabling otherwise…