VYPR

CWE-22

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')

BaseStableLikelihood: High

Description

The product uses external input to construct a pathname that is intended to identify a file or directory that is located underneath a restricted parent directory, but the product does not properly neutralize special elements within the pathname that can cause the pathname to resolve to a location that is outside of the restricted directory.

Hierarchy (View 1000)

Parents

Children

Related attack patterns (CAPEC)

CAPEC-126 · CAPEC-64 · CAPEC-76 · CAPEC-78 · CAPEC-79

CVEs mapped to this weakness (9,904)

page 456 of 496
  • CVE-2022-4494MedDec 14, 2022
    risk 0.00cvss 6.3epss 0.01

    A vulnerability, which was classified as critical, has been found in bspkrs MCPMappingViewer. Affected by this issue is the function extractZip of the file src/main/java/bspkrs/mmv/RemoteZipHandler.java of the component ZIP File Handler. The manipulation leads to path traversal.…

  • CVE-2022-46154HigDec 6, 2022
    risk 0.00cvss 8.6epss 0.01

    Kodexplorer is a chinese language web based file manager and browser based code editor. Versions prior to 4.50 did not prevent unauthenticated users from requesting arbitrary files from the host OS file system. As a result any files available to the host process may be accessed…

  • CVE-2022-23470HigDec 6, 2022
    risk 0.00cvss 8.6epss 0.01

    Galaxy is an open-source platform for data analysis. An arbitrary file read exists in Galaxy 22.01 and Galaxy 22.05 due to the switch to Gunicorn, which can be used to read any file accessible to the operating system user under which Galaxy is running. This vulnerability affects…

  • CVE-2022-45866MedNov 23, 2022
    risk 0.00cvss 5.3epss 0.01

    qpress before PierreLvx/qpress 20220819 and before version 11.3, as used in Percona XtraBackup and other products, allows directory traversal via ../ in a .qp file.

  • CVE-2022-39347LowNov 16, 2022
    risk 0.00cvss 2.6epss 0.01

    FreeRDP is a free remote desktop protocol library and clients. Affected versions of FreeRDP are missing path canonicalization and base path check for `drive` channel. A malicious server can trick a FreeRDP based client to read files outside the shared directory. This issue has…

  • CVE-2022-3976MedNov 13, 2022
    risk 0.00cvss 5.5epss 0.00

    A vulnerability has been found in MZ Automation libiec61850 up to 1.4 and classified as critical. This vulnerability affects unknown code of the file src/mms/iso_mms/client/mms_client_files.c of the component MMS File Services. The manipulation of the argument filename leads to…

  • CVE-2022-3966MedNov 13, 2022
    risk 0.00cvss 4.3epss 0.01

    A vulnerability, which was classified as critical, has been found in Ultimate Member Plugin up to 2.5.0. This issue affects the function load_template of the file includes/core/class-shortcodes.php of the component Template Handler. The manipulation of the argument tpl leads to…

  • CVE-2022-39367HigOct 28, 2022
    risk 0.00cvss 8.6epss 0.01

    QTIWorks is a software suite for standards-based assessment delivery. Prior to version 1.0-beta15, the QTIWorks Engine allows users to upload QTI content packages as ZIP files. The ZIP handling code does not sufficiently check the paths of files contained within ZIP files, so…

  • CVE-2022-39221HigSep 21, 2022
    risk 0.00cvss 7.5epss 0.01

    McWebserver mod runs a simple HTTP server alongside the Minecraft server in seperate threads. Path traversal in McWebserver Minecraft Mod for Fabric and Quilt up to and including 0.1.2.1 and McWebserver Minecraft Mod for Forge up to and including 0.1.1 allows all files,…

  • CVE-2022-39210LowSep 17, 2022
    risk 0.00cvss 3.2epss 0.00

    Nextcloud android is the official Android client for the Nextcloud home server platform. Internal paths to the Nextcloud Android app files are not properly protected. As a result access to internal files of the from within the Nextcloud Android app is possible. This may lead to…

  • CVE-2022-38301HigSep 14, 2022
    risk 0.00cvss 8.8epss 0.01

    Onedev v7.4.14 contains a path traversal vulnerability which allows attackers to access restricted files and directories via uploading a crafted JAR file into the directory /opt/onedev/lib.

  • CVE-2022-36081HigSep 7, 2022
    risk 0.00cvss 7.5epss 0.01

    Wikmd is a file based wiki that uses markdown. Prior to version 1.7.1, Wikmd is vulnerable to path traversal when accessing `/list/<path:folderpath>` and discloses lists of files located on the server including sensitive data. Version 1.7.1 fixes this issue.

  • CVE-2022-36065HigSep 6, 2022
    risk 0.00cvss 7.5epss 0.01

    GrowthBook is an open-source platform for feature flagging and A/B testing. With some self-hosted configurations in versions prior to 2022-08-29, attackers can register new accounts and upload files to arbitrary directories within the container. If the attacker uploads a Python…

  • CVE-2022-2653MedAug 4, 2022
    risk 0.00cvss 6.5epss 0.01

    With this vulnerability an attacker can read many sensitive files like configuration files, or the /proc/self/environ file, that contains the environment variable used by the web server that includes database credentials. If the web server user is root, an attacker will be able…

  • CVE-2022-36889HigJul 27, 2022
    risk 0.00cvss 8.8epss 0.02

    Jenkins Deployer Framework Plugin 85.v1d1888e8c021 and earlier does not restrict the application path of the applications when configuring a deployment, allowing attackers with Item/Configure permission to upload arbitrary files from the Jenkins controller file system to the…

  • CVE-2022-35861HigJul 17, 2022
    risk 0.00cvss 7.8epss 0.00

    pyenv 1.2.24 through 2.3.2 allows local users to gain privileges via a .python-version file in the current working directory. An attacker can craft a Python version string in .python-version to execute shims under their control. (Shims are executables that pass a command along…

  • CVE-2022-31564CriJul 11, 2022
    risk 0.00cvss 9.3epss 0.01

    The woduq1414/munhak-moa repository before 2022-05-03 on GitHub allows absolute path traversal because the Flask send_file function is used unsafely.

  • CVE-2022-31549CriJul 11, 2022
    risk 0.00cvss 9.3epss 0.01

    The olmax99/helm-flask-celery repository before 2022-05-25 on GitHub allows absolute path traversal because the Flask send_file function is used unsafely.

  • CVE-2022-31510CriJul 11, 2022
    risk 0.00cvss 9.3epss 0.01

    The sergeKashkin/Simple-RAT repository before 2022-05-03 on GitHub allows absolute path traversal because the Flask send_file function is used unsafely.

  • CVE-2022-31508CriJul 11, 2022
    risk 0.00cvss 9.3epss 0.01

    The idayrus/evoting repository before 2022-05-08 on GitHub allows absolute path traversal because the Flask send_file function is used unsafely.