VYPR

CWE-22

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')

BaseStableLikelihood: High

Description

The product uses external input to construct a pathname that is intended to identify a file or directory that is located underneath a restricted parent directory, but the product does not properly neutralize special elements within the pathname that can cause the pathname to resolve to a location that is outside of the restricted directory.

Hierarchy (View 1000)

Parents

Children

Related attack patterns (CAPEC)

CAPEC-126 · CAPEC-64 · CAPEC-76 · CAPEC-78 · CAPEC-79

CVEs mapped to this weakness (10,485)

page 388 of 525
  • CVE-2020-4934MedFeb 2, 2021
    risk 0.28cvss 4.3epss 0.02

    IBM Content Navigator 3.0.CD could allow a remote attacker to traverse directories on the system. An attacker could send a specially-crafted URL request containing "dot dot" sequences (/../) to view arbitrary files on the system. IBM X-Force ID: 191752.

  • CVE-2021-3281MedFeb 2, 2021
    risk 0.28cvss 5.3epss 0.08

    In Django 2.2 before 2.2.18, 3.0 before 3.0.12, and 3.1 before 3.1.6, the django.utils.archive.extract method (used by "startapp --template" and "startproject --template") allows directory traversal via an archive with absolute paths or relative paths with dot segments.

  • CVE-2020-35460MedDec 14, 2020
    risk 0.28cvss 5.3epss 0.02

    common/InputStreamHelper.java in Packwood MPXJ before 8.3.5 allows directory traversal in the zip stream handler flow, leading to the writing of files to arbitrary locations.

  • CVE-2020-7790MedDec 11, 2020
    risk 0.28cvss 5.3epss 0.01

    This affects the package spatie/browsershot from 0.0.0. By specifying a URL in the file:// protocol an attacker is able to include arbitrary files in the resultant PDF.

  • CVE-2020-5605MedSep 18, 2020
    risk 0.28cvss 4.3epss 0.01

    Directory traversal vulnerability in WHR-G54S firmware 1.43 and earlier allows an attacker to access sensitive information such as setting values via unspecified vectors.

  • CVE-2020-7268MedSep 16, 2020
    risk 0.28cvss 4.3epss 0.01

    Path Traversal vulnerability in McAfee McAfee Email Gateway (MEG) prior to 7.6.406 allows remote attackers to traverse the file system to access files or directories that are outside of the restricted directory via external input to construct a path name that should be within a…

  • CVE-2020-3365MedSep 4, 2020
    risk 0.28cvss 4.3epss 0.02

    A vulnerability in the directory permissions of Cisco Enterprise NFV Infrastructure Software (NFVIS) could allow an authenticated, remote attacker to perform a directory traversal attack on a limited set of restricted directories. The vulnerability is due to a flaw in the logic…

  • CVE-2019-4582MedAug 13, 2020
    risk 0.28cvss 4.3epss 0.01

    IBM Maximo Asset Management 7.6.0 and 7.6.1 could allow a remote attacker to traverse directories on the system. An attacker could send a specially-crafted URL request containing "dot dot" sequences (/../) to view arbitrary files on the system. IBM X-Force ID: 167288.

  • CVE-2020-15712MedJul 28, 2020
    risk 0.28cvss 4.3epss 0.02

    rConfig 3.9.5 could allow a remote authenticated attacker to traverse directories on the system. An attacker could send a crafted request to the ajaxGetFileByPath.php script containing hexadecimal encoded "dot dot" sequences (%2f..%2f) in the path parameter to view arbitrary…

  • CVE-2020-13792MedJun 3, 2020
    risk 0.28cvss 4.3epss 0.01

    PlayTube 1.8 allows disclosure of user details via ajax.php?type=../admin-panel/autoload&page=manage-users directory traversal, aka local file inclusion.

  • CVE-2020-7651MedMay 29, 2020
    risk 0.28cvss 4.3epss 0.01

    All versions of snyk-broker before 4.79.0 are vulnerable to Arbitrary File Read. It allows partial file reads for users who have access to Snyk's internal network via patch history from GitHub Commits API.

  • CVE-2019-17572MedMay 14, 2020
    risk 0.28cvss 5.3epss 0.03

    In Apache RocketMQ 4.2.0 to 4.6.0, when the automatic topic creation in the broker is turned on by default, an evil topic like “../../../../topic2020” is sent from rocketmq-client to the broker, a topic folder will be created in the parent directory in brokers, which leads…

  • CVE-2020-7647MedMay 11, 2020
    risk 0.28cvss 5.3epss 0.02

    All versions before 1.6.7 and all versions after 2.0.0 inclusive and before 2.8.2 of io.jooby:jooby and org.jooby:jooby are vulnerable to Directory Traversal via two separate vectors.

  • CVE-2020-8996MedFeb 16, 2020
    risk 0.28cvss 4.3epss 0.01

    AnyShare Cloud 6.0.9 allows authenticated directory traversal to read files, as demonstrated by the interface/downloadwithpath/downloadfile/?filepath=/etc/passwd URI.

  • CVE-2018-12476MedJan 27, 2020
    risk 0.28cvss 4.3epss 0.01

    Relative Path Traversal vulnerability in obs-service-tar_scm of SUSE Linux Enterprise Server 15; openSUSE Factory allows remote attackers with control over a repository to overwrite files on the machine of the local user if a malicious service is executed. This issue affects:…

  • CVE-2019-17404MedNov 25, 2019
    risk 0.28cvss 4.3epss 0.01

    Nokia IMPACT < 18A: allows full path disclosure

  • CVE-2019-18978MedNov 14, 2019
    risk 0.28cvss 5.3epss 0.02

    An issue was discovered in the rack-cors (aka Rack CORS Middleware) gem before 1.0.4 for Ruby. It allows ../ directory traversal to access private resources because resource matching does not ensure that pathnames are in a canonical format.

  • CVE-2019-4400MedOct 25, 2019
    risk 0.28cvss 4.3epss 0.01

    IBM Cloud Orchestrator 2.4 through 2.4.0.5 and 2.5 through 2.5.0.9 could allow a remote attacker to traverse directories on the system. An attacker could send a specially-crafted URL request containing "dot dot" sequences (/../) to view arbitrary files on the system. IBM X-Force…

  • CVE-2019-4442MedSep 17, 2019
    risk 0.28cvss 4.3epss 0.02

    IBM WebSphere Application Server 7.0, 8.0, 8.5, and 9,0 could allow a remote attacker to traverse directories on the file system. An attacker could send a specially-crafted URL request to view arbitrary files on the system but not content. IBM X-Force ID: 163226.

  • CVE-2018-14672MedAug 15, 2019
    risk 0.28cvss 5.3epss 0.02

    In ClickHouse before 18.12.13, functions for loading CatBoost models allowed path traversal and reading arbitrary files through error messages.