VYPR

CWE-22

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')

BaseStableLikelihood: High

Description

The product uses external input to construct a pathname that is intended to identify a file or directory that is located underneath a restricted parent directory, but the product does not properly neutralize special elements within the pathname that can cause the pathname to resolve to a location that is outside of the restricted directory.

Hierarchy (View 1000)

Parents

Children

Related attack patterns (CAPEC)

CAPEC-126 · CAPEC-64 · CAPEC-76 · CAPEC-78 · CAPEC-79

CVEs mapped to this weakness (9,904)

page 455 of 496
  • CVE-2023-28833LowMar 30, 2023
    risk 0.00cvss 2.4epss 0.01

    Nextcloud server is an open source home cloud implementation. In affected versions admins of a server were able to upload a logo or a favicon and to provided a file name which was not restricted and could overwrite files in the appdata directory. Administrators may have access…

  • CVE-2023-28371CriMar 15, 2023
    risk 0.00cvss 9.8epss 0.02

    In Stellarium through 1.2, attackers can write to files that are typically unintended, such as ones with absolute pathnames or .. directory traversal.

  • CVE-2023-27588HigMar 14, 2023
    risk 0.00cvss 7.5epss 0.01

    Hasura is an open-source product that provides users GraphQL or REST APIs. A path traversal vulnerability has been discovered within Hasura GraphQL Engine prior to versions 1.3.4, 2.55.1, 2.20.1, and 2.21.0-beta1. Projects running on Hasura Cloud were not vulnerable. Self-hosted…

  • CVE-2023-25802HigMar 13, 2023
    risk 0.00cvss 7.5epss 0.01

    Roxy-WI is a Web interface for managing Haproxy, Nginx, Apache, and Keepalived servers. Versions prior to 6.3.6.0 don't correctly neutralize `dir/../filename` sequences, such as `/etc/nginx/../passwd`, allowing an actor to gain information about a server. Version 6.3.6.0 has a…

  • CVE-2017-20181MedMar 7, 2023
    risk 0.00cvss 5.3epss 0.00

    A vulnerability classified as critical was found in hgzojer Vocable Trainer up to 1.3.0 on Android. This vulnerability affects unknown code of the file src/at/hgz/vocabletrainer/VocableTrainerProvider.java. The manipulation leads to path traversal. Attacking locally is a…

  • CVE-2023-25579MedFeb 22, 2023
    risk 0.00cvss 6.0epss 0.01

    Nextcloud server is a self hosted home cloud product. In affected versions the `OC\Files\Node\Folder::getFullPath()` function was validating and normalizing the string in the wrong order. The function is used in the `newFile()` and `newFolder()` items, which may allow to…

  • CVE-2023-0947CriFeb 22, 2023
    risk 0.00cvss 9.8epss 0.04

    Path Traversal in GitHub repository flatpressblog/flatpress prior to 1.3.

  • CVE-2023-23946MedFeb 14, 2023
    risk 0.00cvss 6.2epss 0.01

    Git, a revision control system, is vulnerable to path traversal prior to versions 2.39.2, 2.38.4, 2.37.6, 2.36.5, 2.35.7, 2.34.7, 2.33.7, 2.32.6, 2.31.7, and 2.30.8. By feeding a crafted input to `git apply`, a path outside the working tree can be overwritten as the user who is…

  • CVE-2023-0593MedJan 31, 2023
    risk 0.00cvss 5.5epss 0.00

    A path traversal vulnerability affects yaffshiv YAFFS filesystem extractor. By crafting a malicious YAFFS file, an attacker could force yaffshiv to write outside of the extraction directory. This issue affects yaffshiv up to version 0.1 included, which is the most recent at…

  • CVE-2023-0592MedJan 31, 2023
    risk 0.00cvss 5.5epss 0.00

    A path traversal vulnerability affects jefferson's JFFS2 filesystem extractor. By crafting malicious JFFS2 files, attackers could force jefferson to write outside of the extraction directory.This issue affects jefferson: before 0.4.1.

  • CVE-2023-23608NonJan 26, 2023
    risk 0.00cvss 0.0epss 0.01

    Spotipy is a light weight Python library for the Spotify Web API. In versions prior to 2.22.1, if a malicious URI is passed to the library, the library can be tricked into performing an operation on a different API endpoint than intended. The code Spotipy uses to parse URIs and…

  • CVE-2020-36647MedJan 8, 2023
    risk 0.00cvss 5.5epss 0.01

    A vulnerability classified as critical has been found in YunoHost-Apps transmission_ynh. Affected is an unknown function of the file conf/nginx.conf. The manipulation leads to path traversal. The patch is identified as f136dfd44eda128129e5fd2d850a3a3c600e6a4a. It is recommended…

  • CVE-2022-4880MedJan 7, 2023
    risk 0.00cvss 5.5epss 0.01

    A vulnerability was found in stakira OpenUtau. It has been classified as critical. This affects the function VoicebankInstaller of the file OpenUtau.Core/Classic/VoicebankInstaller.cs of the component ZIP Archive Handler. The manipulation leads to path traversal. Upgrading to…

  • CVE-2022-4878MedJan 6, 2023
    risk 0.00cvss 5.5epss 0.01

    A vulnerability classified as critical has been found in JATOS. Affected is the function ZipUtil of the file modules/common/app/utils/common/ZipUtil.java of the component ZIP Handler. The manipulation leads to path traversal. Upgrading to version 3.7.5-alpha is able to address…

  • CVE-2017-20152LowDec 30, 2022
    risk 0.00cvss 3.1epss 0.01

    A vulnerability, which was classified as problematic, was found in aerouk imageserve. Affected is an unknown function of the file public/viewer.php of the component File Handler. The manipulation of the argument filelocation leads to path traversal. It is possible to launch the…

  • CVE-2022-4773LowDec 28, 2022
    risk 0.00cvss 2.5epss 0.00

    ** UNSUPPORTED WHEN ASSIGNED ** A vulnerability classified as problematic was found in cloudsync. Affected by this vulnerability is the function getItem of the file src/main/java/cloudsync/connector/LocalFilesystemConnector.java. The manipulation leads to path traversal. It is…

  • CVE-2022-4748MedDec 27, 2022
    risk 0.00cvss 5.5epss 0.01

    A vulnerability was found in FlatPress. It has been classified as critical. This affects the function doItemActions of the file fp-plugins/mediamanager/panels/panel.mediamanager.file.php of the component File Delete Handler. The manipulation of the argument deletefile leads to…

  • CVE-2022-41418HigDec 19, 2022
    risk 0.00cvss 7.2epss 0.01

    An issue in the component BlogEngine/BlogEngine.NET/AppCode/Api/UploadController.cs of BlogEngine.NET v3.3.8.0 allows attackers to execute arbitrary code via uploading a crafted PNG file.

  • CVE-2022-4594MedDec 18, 2022
    risk 0.00cvss 6.3epss 0.01

    A vulnerability was found in drogatkin TJWS2. It has been declared as critical. Affected by this vulnerability is the function deployWar of the file 1.x/src/rogatkin/web/WarRoller.java. The manipulation leads to path traversal. The attack can be launched remotely. The name of…

  • CVE-2022-4583MedDec 17, 2022
    risk 0.00cvss 6.3epss 0.01

    A vulnerability was found in jLEMS. It has been declared as critical. Affected by this vulnerability is the function unpackJar of the file src/main/java/org/lemsml/jlems/io/util/JUtil.java. The manipulation leads to path traversal. The attack can be launched remotely. The name…