VYPR

CWE-22

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')

BaseStableLikelihood: High

Description

The product uses external input to construct a pathname that is intended to identify a file or directory that is located underneath a restricted parent directory, but the product does not properly neutralize special elements within the pathname that can cause the pathname to resolve to a location that is outside of the restricted directory.

Hierarchy (View 1000)

Parents

Children

Related attack patterns (CAPEC)

CAPEC-126 · CAPEC-64 · CAPEC-76 · CAPEC-78 · CAPEC-79

CVEs mapped to this weakness (10,457)

page 435 of 523
  • CVE-2011-4807Dec 14, 2011
    risk 0.03cvss —epss 0.03

    Directory traversal vulnerability in main.php in phpAlbum 0.4.1.16 and earlier allows remote attackers to read arbitrary files via a .. (dot dot) in the var1 parameter.

  • CVE-2011-4716Dec 8, 2011
    risk 0.03cvss —epss 0.03

    Directory traversal vulnerability in file in DreamBox DM800 1.6rc3, 1.5rc1, and earlier allows remote attackers to read arbitrary files via the file parameter.

  • CVE-2011-4714Dec 8, 2011
    risk 0.03cvss —epss 0.04

    Directory traversal vulnerability in Virtual Vertex Muster before 6.20 allows remote attackers to read arbitrary files via a \.. (backslash dot dot) in the URL.

  • CVE-2011-4713Dec 8, 2011
    risk 0.03cvss —epss 0.03

    Directory traversal vulnerability in catalog/content.php in osCSS2 2.1.0 and earlier allows remote attackers to read arbitrary files via a .. (dot dot) in the _ID parameter to (1) catalog/shopping_cart.php or (2) catalog/content.php.

  • CVE-2011-4712Dec 8, 2011
    risk 0.03cvss —epss 0.03

    Directory traversal vulnerability in Oxide WebServer allows remote attackers to read arbitrary files via a ..\ (dot dot backslash) in an HTTP request.

  • CVE-2011-4122Nov 17, 2011
    risk 0.03cvss —epss 0.01

    Directory traversal vulnerability in openpam_configure.c in OpenPAM before r478 on FreeBSD 8.1 allows local users to load arbitrary DSOs and gain privileges via a .. (dot dot) in the service_name argument to the pam_start function, as demonstrated by a .. in the -c option to…

  • CVE-2011-4431Nov 10, 2011
    risk 0.03cvss —epss 0.06

    Directory traversal vulnerability in main.php in Merethis Centreon before 2.3.2 allows remote authenticated users to execute arbitrary commands via a .. (dot dot) in the command_name parameter.

  • CVE-2010-4867Oct 5, 2011
    risk 0.03cvss —epss 0.02

    Directory traversal vulnerability in search.php3 (aka search.php) in W-Agora 4.2.1 and earlier allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the bn parameter.

  • CVE-2010-4858Oct 5, 2011
    risk 0.03cvss —epss 0.03

    Directory traversal vulnerability in team.rc5-72.php in DNET Live-Stats 0.8 allows remote attackers to read arbitrary files via a .. (dot dot) in the showlang parameter.

  • CVE-2010-4835Sep 14, 2011
    risk 0.03cvss —epss 0.02

    Directory traversal vulnerability in index.php in OneOrZero AIMS 2.6.0 Members Edition allows remote authenticated users to read arbitrary files via directory traversal sequences in the controller parameter in a show_report action.

  • CVE-2009-5093Sep 12, 2011
    risk 0.03cvss —epss 0.03

    Directory traversal vulnerability in gastbuch.php in Gästebuch (Gastebuch) 1.6 allows remote attackers to read arbitrary files via a .. (dot dot) in the start parameter.

  • CVE-2009-5089Sep 12, 2011
    risk 0.03cvss —epss 0.02

    Directory traversal vulnerability in index.php in IdeaCart 0.02 and 0.02a allows remote attackers to read arbitrary files via a .. (dot dot) in the page parameter.

  • CVE-2009-5087Sep 12, 2011
    risk 0.03cvss —epss 0.04

    Directory traversal vulnerability in geohttpserver in Geovision Digital Video Surveillance System 8.2 allows remote attackers to read arbitrary files via a .. (dot dot) in a GET request.

  • CVE-2010-4801Apr 27, 2011
    risk 0.03cvss —epss 0.02

    Directory traversal vulnerability in admin/updatelist.php in BaconMap 1.0 allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the filepath parameter.

  • CVE-2010-4798Apr 27, 2011
    risk 0.03cvss —epss 0.02

    Directory traversal vulnerability in index.php in OrangeHRM 2.6.0.1 allows remote attackers to include and execute arbitrary local files via directory traversal sequences in the uri parameter.

  • CVE-2011-0751Mar 16, 2011
    risk 0.03cvss —epss 0.04

    Directory traversal vulnerability in nhttpd (aka Nostromo webserver) before 1.9.4 allows remote attackers to execute arbitrary programs or read arbitrary files via a ..%2f (encoded dot dot slash) in a URI.

  • CVE-2011-1099Mar 9, 2011
    risk 0.03cvss —epss 0.03

    Multiple directory traversal vulnerabilities in FocalMedia.Net Quick Polls before 1.0.2 allow remote attackers to (1) read arbitrary files via a .. (dot dot) in the p parameter in a preview action to index.php, or (2) delete arbitrary files via a .. (dot dot) in the p parameter…

  • CVE-2011-0903Feb 7, 2011
    risk 0.03cvss —epss 0.02

    Multiple directory traversal vulnerabilities in AR Web Content Manager (AWCM) 2.2 allow remote attackers to read arbitrary files and possibly have other unspecified impact via a .. (dot dot) in the (1) awcm_theme or (2) awcm_lang cookie to (a) index.php or (b) header.php.

  • CVE-2011-0506Jan 20, 2011
    risk 0.03cvss —epss 0.03

    Directory traversal vulnerability in modules/profile/user.php in Ax Developer CMS (AxDCMS) 0.1.1 allows remote attackers to execute arbitrary code via a .. (dot dot) in the aXconf[default_language] parameter.

  • CVE-2011-0505Jan 20, 2011
    risk 0.03cvss —epss 0.02

    Directory traversal vulnerability in system/system.php in Zwii 2.1.1, when magic_quotes_gpc is disabled and register_globals is enabled, allows remote attackers to include and execute arbitrary local files via directory traversal sequences in the set[template][value] parameter.