VYPR

CWE-22

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')

BaseStableLikelihood: High

Description

The product uses external input to construct a pathname that is intended to identify a file or directory that is located underneath a restricted parent directory, but the product does not properly neutralize special elements within the pathname that can cause the pathname to resolve to a location that is outside of the restricted directory.

Hierarchy (View 1000)

Parents

Children

Related attack patterns (CAPEC)

CAPEC-126 · CAPEC-64 · CAPEC-76 · CAPEC-78 · CAPEC-79

CVEs mapped to this weakness (10,485)

page 389 of 525
  • CVE-2019-13385MedJul 26, 2019
    risk 0.28cvss 4.3epss 0.02

    In CentOS-WebPanel.com (aka CWP) CentOS Web Panel 0.9.8.840, File and Directory Information Exposure in filemanager allows attackers to enumerate users and check for active users of the application by reading /tmp/login.log.

  • CVE-2019-11822MedJun 30, 2019
    risk 0.28cvss 4.3epss 0.01

    Relative path traversal vulnerability in SYNO.PhotoStation.File in Synology Photo Station before 6.8.11-3489 and before 6.3-2977 allows remote attackers to upload arbitrary files via the uploadphoto parameter.

  • CVE-2019-4384MedJun 19, 2019
    risk 0.28cvss 4.3epss 0.02

    IBM Campaign 9.1.2 and 10.1 could allow a remote attacker to traverse directories on the system. An attacker could send a specially-crafted URL request containing "dot dot" sequences (/../) to view arbitrary files on the system. IBM X-Force ID: 162172.

  • CVE-2019-3880MedApr 9, 2019
    risk 0.28cvss 5.4epss 0.03

    A flaw was found in the way samba implemented an RPC endpoint emulating the Windows registry service API. An unprivileged attacker could use this flaw to create a new registry hive file anywhere they have unix permissions which could lead to creation of a new file in the Samba…

  • CVE-2018-13299MedApr 1, 2019
    risk 0.28cvss 4.3epss 0.01

    Relative path traversal vulnerability in Attachment Uploader in Synology Calendar before 2.2.2-0532 allows remote authenticated users to upload arbitrary files via the filename parameter.

  • CVE-2018-20635MedMar 21, 2019
    risk 0.28cvss 4.3epss 0.01

    PHP Scripts Mall Advance B2B Script 2.1.4 has directory traversal via a direct request for a listing of an image directory such as an assets/ directory.

  • CVE-2019-9610MedMar 6, 2019
    risk 0.28cvss 4.3epss 0.01

    An issue was discovered in OFCMS before 1.1.3. It has admin/cms/template/getTemplates.html?res_path=res&up_dir=../ directory traversal, related to the getTemplates function in TemplateController.java.

  • CVE-2018-15750MedOct 24, 2018
    risk 0.28cvss 5.3epss 0.04

    Directory Traversal vulnerability in salt-api in SaltStack Salt before 2017.7.8 and 2018.3.x before 2018.3.3 allows remote attackers to determine which files exist on the server.

  • CVE-2018-8041MedSep 17, 2018
    risk 0.28cvss 5.3epss 0.10

    Apache Camel's Mail 2.20.0 through 2.20.3, 2.21.0 through 2.21.1 and 2.22.0 is vulnerable to path traversal.

  • CVE-2018-14355MedJul 17, 2018
    risk 0.28cvss 5.3epss 0.03

    An issue was discovered in Mutt before 1.10.1 and NeoMutt before 2018-07-16. imap/util.c mishandles ".." directory traversal in a mailbox name.

  • CVE-2018-14056MedJul 15, 2018
    risk 0.28cvss 5.3epss 0.02

    ZNC before 1.7.1-rc1 is prone to a path traversal flaw via ../ in a web skin name to access files outside of the intended skins directories.

  • CVE-2018-7764MedJul 3, 2018
    risk 0.28cvss 4.3epss 0.01

    The vulnerability exists within runscript.php applet in Schneider Electric U.motion Builder software versions prior to v1.3.4. There is a directory traversal vulnerability in the processing of the 's' parameter of the applet.

  • CVE-2018-7763MedJul 3, 2018
    risk 0.28cvss 4.3epss 0.01

    The vulnerability exists within css.inc.php in Schneider Electric U.motion Builder software versions prior to v1.3.4. The 'css' parameter contains a directory traversal vulnerability.

  • CVE-2018-11342MedMay 22, 2018
    risk 0.28cvss 4.3epss 0.01

    A path traversal vulnerability in fileExplorer.cgi in ASUSTOR AS6202T ADM 3.1.0.RFQ3 allows attackers to arbitrarily specify a path to a file on the system to create folders via the dest_folder parameter.

  • CVE-2018-0586MedMay 14, 2018
    risk 0.28cvss 4.3epss 0.02

    Directory traversal vulnerability in the shortcodes function of Ultimate Member plugin prior to version 2.0.4 for WordPress allows remote authenticated attackers to read arbitrary files via unspecified vectors.

  • CVE-2018-9159MedMar 31, 2018
    risk 0.28cvss 5.3epss 0.04

    In Spark before 2.7.2, a remote attacker can read unintended static files via various representations of absolute or relative pathnames, as demonstrated by file: URLs and directory traversal sequences. NOTE: this product is unrelated to Ignite Realtime Spark.

  • CVE-2018-2366MedMar 14, 2018
    risk 0.28cvss 4.3epss 0.02

    SAP Business Process Automation (BPA) By Redwood, 9.0, 9.1, allows an attacker to exploit insufficient validation of path information provided by users, thus characters representing 'traverse to parent directory' are passed through to the file APIs.

  • CVE-2018-7212MedFeb 18, 2018
    risk 0.28cvss 5.3epss 0.02

    An issue was discovered in rack-protection/lib/rack/protection/path_traversal.rb in Sinatra 2.x before 2.0.1 on Windows. Path traversal is possible via backslash characters.

  • CVE-2017-10907MedDec 22, 2017
    risk 0.28cvss 4.3epss 0.01

    Directory traversal vulnerability in OneThird CMS Show Off v1.85 and earlier. Show Off v1.85 en and earlier allows an attacker to read arbitrary files via unspecified vectors.

  • CVE-2017-2258MedAug 29, 2017
    risk 0.28cvss 4.3epss 0.01

    Directory traversal vulnerability in Cybozu Garoon 4.2.4 to 4.2.5 allows an attacker to read arbitrary files via Garoon SOAP API "WorkflowHandleApplications".