VYPR

CWE-22

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')

BaseStableLikelihood: High

Description

The product uses external input to construct a pathname that is intended to identify a file or directory that is located underneath a restricted parent directory, but the product does not properly neutralize special elements within the pathname that can cause the pathname to resolve to a location that is outside of the restricted directory.

Hierarchy (View 1000)

Parents

Children

Related attack patterns (CAPEC)

CAPEC-126 · CAPEC-64 · CAPEC-76 · CAPEC-78 · CAPEC-79

CVEs mapped to this weakness (10,485)

page 387 of 525
  • CVE-2022-30949MedMay 17, 2022
    risk 0.28cvss 5.3epss 0.01

    Jenkins REPO Plugin 1.14.0 and earlier allows attackers able to configure pipelines to check out some SCM repositories stored on the Jenkins controller's file system using local paths as SCM URLs, obtaining limited information about other projects' SCM contents.

  • CVE-2022-29474MedMay 5, 2022
    risk 0.28cvss 4.3epss 0.02

    On F5 BIG-IP 16.1.x versions prior to 16.1.2.2, 15.1.x versions prior to 15.1.5.1, 14.1.x versions prior to 14.1.4.6, 13.1.x versions prior to 13.1.5, and all versions of 12.1.x and 11.6.x, a directory traversal vulnerability exists in iControl SOAP that allows an authenticated…

  • CVE-2022-25266MedMar 23, 2022
    risk 0.28cvss 4.3epss 0.01

    Passwork On-Premise Edition before 4.6.13 allows migration/downloadExportFile Directory Traversal (to read files).

  • CVE-2022-22349MedFeb 24, 2022
    risk 0.28cvss 4.3epss 0.01

    IBM Sterling External Authentication Server 3.4.3.2, 6.0.2.0, and 6.0.3.0 is vulnerable to path traversals, due to not properly validating RESTAPI configuration data. An authorized user could import invalid data which could be used for an attack. IBM X-Force ID: 220144.

  • CVE-2021-45452MedJan 5, 2022
    risk 0.28cvss 5.3epss 0.02

    Storage.save in Django 2.2 before 2.2.26, 3.2 before 3.2.11, and 4.0 before 4.0.1 allows directory traversal if crafted filenames are directly passed to it.

  • CVE-2021-21886MedDec 22, 2021
    risk 0.28cvss 4.3epss 0.02

    A directory traversal vulnerability exists in the Web Manager FSBrowsePage functionality of Lantronix PremierWave 2050 8.9.0.0R4. A specially crafted HTTP request can lead to information disclosure. An attacker can make an authenticated HTTP request to trigger this vulnerability.

  • CVE-2021-43788MedNov 29, 2021
    risk 0.28cvss 5.0epss 0.26

    Nodebb is an open source Node.js based forum software. Prior to v1.18.5, a path traversal vulnerability was present that allowed users to access JSON files outside of the expected `languages/` directory. The vulnerability has been patched as of v1.18.5. Users are advised to…

  • CVE-2021-32061MedNov 29, 2021
    risk 0.28cvss 5.3epss 0.02

    S3Scanner before 2.0.2 allows Directory Traversal via a crafted bucket, as demonstrated by a ../ substring in a ListBucketResult element.

  • CVE-2021-37938MedNov 18, 2021
    risk 0.28cvss 4.3epss 0.01

    It was discovered that on Windows operating systems specifically, Kibana was not validating a user supplied path, which would load .pbf files. Because of this, a malicious user could arbitrarily traverse the Kibana host to load internal files ending in the .pbf extension. Thanks…

  • CVE-2021-34701MedNov 4, 2021
    risk 0.28cvss 4.3epss 0.02

    A vulnerability in the web-based management interface of Cisco Unified Communications Manager (Unified CM), Cisco Unified Communications Manager Session Management Edition (Unified CM SME), Cisco Unified Communications Manager IM & Presence Service (Unified CM IM&P), and…

  • CVE-2021-22868MedSep 24, 2021
    risk 0.28cvss 4.3epss 0.01

    A path traversal vulnerability was identified in GitHub Enterprise Server that could be exploited when building a GitHub Pages site. User-controlled configuration options used by GitHub Pages were not sufficiently restricted and made it possible to read files on the GitHub…

  • CVE-2021-37532MedSep 14, 2021
    risk 0.28cvss 4.3epss 0.01

    SAP Business One version - 10, due to improper input validation, allows an authenticated User to gain access to directory and view the contents of index in the directory, which would otherwise be restricted to high privileged User.

  • CVE-2021-36157MedAug 3, 2021
    risk 0.28cvss 5.3epss 0.01

    An issue was discovered in Grafana Cortex through 1.9.0. The header value X-Scope-OrgID is used to construct file paths for rules files, and if crafted to conduct directory traversal such as ae ../../sensitive/path/in/deployment pathname, then Cortex will attempt to parse a…

  • CVE-2021-37446MedJul 25, 2021
    risk 0.28cvss 4.3epss 0.01

    In NCH Quorum v2.03 and earlier, an authenticated user can use directory traversal via documentprop?file=/.. for file reading.

  • CVE-2021-35968MedJul 19, 2021
    risk 0.28cvss 4.3epss 0.01

    The directory list page parameter of the Orca HCM digital learning platform fails to filter special characters properly. Remote attackers can access the system directory thru Path Traversal with users’ privileges.

  • CVE-2021-33215MedJul 7, 2021
    risk 0.28cvss 4.3epss 0.01

    An issue was discovered in CommScope Ruckus IoT Controller 1.7.1.0 and earlier. The API allows Directory Traversal.

  • CVE-2021-28584MedJun 28, 2021
    risk 0.28cvss 5.4epss 0.02

    Magento versions 2.4.2 (and earlier), 2.4.1-p1 (and earlier) and 2.3.6-p1 (and earlier) are affected by a Path Traversal vulnerability when creating a store with child theme.Successful exploitation could lead to arbitrary file system write by an authenticated attacker. Access to…

  • CVE-2021-34553MedJun 18, 2021
    risk 0.28cvss 4.3epss 0.04

    Sonatype Nexus Repository Manager 3.x before 3.31.0 allows a remote authenticated attacker to get a list of blob files and read the content of a blob file (via a GET request) without having been granted access.

  • CVE-2020-21056MedMay 20, 2021
    risk 0.28cvss 4.3epss 0.01

    Directory Traversal vulnerability exists in FusionPBX 4.5.7, which allows a remote malicious user to create folders via the folder variale to app\edit\foldernew.php.

  • CVE-2020-21590MedApr 2, 2021
    risk 0.28cvss 4.3epss 0.01

    Directory traversal in coreframe/app/template/admin/index.php in WUZHI CMS 4.1.0 allows attackers to list files in arbitrary directories via the dir parameter.