VYPR

CWE-22

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')

BaseStableLikelihood: High

Description

The product uses external input to construct a pathname that is intended to identify a file or directory that is located underneath a restricted parent directory, but the product does not properly neutralize special elements within the pathname that can cause the pathname to resolve to a location that is outside of the restricted directory.

Hierarchy (View 1000)

Parents

Children

Related attack patterns (CAPEC)

CAPEC-126 · CAPEC-64 · CAPEC-76 · CAPEC-78 · CAPEC-79

CVEs mapped to this weakness (9,904)

page 457 of 496
  • CVE-2022-31504CriJul 11, 2022
    risk 0.00cvss 9.3epss 0.01

    The ChangeWeDer/BaiduWenkuSpider_flaskWeb repository before 2021-11-29 on GitHub allows absolute path traversal because the Flask send_file function is used unsafely.

  • CVE-2022-31503CriJul 11, 2022
    risk 0.00cvss 9.3epss 0.01

    The orchest/orchest repository before 2022.05.0 on GitHub allows absolute path traversal because the Flask send_file function is used unsafely.

  • CVE-2022-31502CriJul 11, 2022
    risk 0.00cvss 9.3epss 0.01

    The operatorequals/wormnest repository through 0.4.7 on GitHub allows absolute path traversal because the Flask send_file function is used unsafely.

  • CVE-2022-31501CriJul 11, 2022
    risk 0.00cvss 9.3epss 0.01

    The ChaoticOnyx/OnyxForum repository before 2022-05-04 on GitHub allows absolute path traversal because the Flask send_file function is used unsafely.

  • CVE-2022-31372HigJun 16, 2022
    risk 0.00cvss 7.5epss 0.01

    Wiris Mathtype v7.28.0 was discovered to contain a path traversal vulnerability in the resourceFile parameter. This vulnerability is exploited via a crafted request to the resource handler.

  • CVE-2022-1721HigMay 16, 2022
    risk 0.00cvss 7.5epss 0.02

    Path Traversal in WellKnownServlet in GitHub repository jgraph/drawio prior to 18.0.5. Read local files of the web application.

  • CVE-2022-24830MedMay 14, 2022
    risk 0.00cvss 6.5epss 0.03

    OpenClinica is an open source software for Electronic Data Capture (EDC) and Clinical Data Management (CDM). OpenClinica prior to version 3.16 is vulnerable to path traversal in multiple endpoints, leading to arbitrary file read/write, and potential remote code execution. There…

  • CVE-2022-28451HigMay 2, 2022
    risk 0.00cvss 7.5epss 0.02

    nopCommerce 4.50.1 is vulnerable to Directory Traversal via the backup file in the Maintenance feature.

  • CVE-2022-26068MedMay 1, 2022
    risk 0.00cvss 6.5epss 0.02

    This affects the package pistacheio/pistache before 0.0.3.20220425. It is possible to traverse directories to fetch arbitrary files from the server.

  • CVE-2022-25842MedMay 1, 2022
    risk 0.00cvss 6.9epss 0.04

    All versions of package com.alibaba.oneagent:one-java-agent-plugin are vulnerable to Arbitrary File Write via Archive Extraction (Zip Slip) using a specially crafted archive that holds directory traversal filenames (e.g. ../../evil.exe). The attacker can overwrite executable…

  • CVE-2022-29967HigApr 29, 2022
    risk 0.00cvss 7.5epss 0.02

    static_compressed_inmemory_website_callback.c in Glewlwyd through 2.6.2 allows directory traversal.

  • CVE-2022-24851HigApr 15, 2022
    risk 0.00cvss 8.1epss 0.01

    LDAP Account Manager (LAM) is an open source web frontend for managing entries stored in an LDAP directory. The profile editor tool has an edit profile functionality, the parameters on this page are not properly sanitized and hence leads to stored XSS attacks. An authenticated…

  • CVE-2021-43290CriApr 14, 2022
    risk 0.00cvss 9.8epss 0.03

    An issue was discovered in ThoughtWorks GoCD before 21.3.0. An attacker who has compromised a GoCD agent can upload a malicious file into a directory of a GoCD server. They can control the filename but the directory is placed inside of a directory that they can't control.

  • CVE-2021-43289HigApr 14, 2022
    risk 0.00cvss 7.5epss 0.02

    An issue was discovered in ThoughtWorks GoCD before 21.3.0. An attacker who has compromised a GoCD agent can upload a malicious file into an arbitrary directory of a GoCD server, but does not control the filename.

  • CVE-2021-26601HigMar 28, 2022
    risk 0.00cvss 8.1epss 0.03

    ImpressCMS before 1.4.3 allows libraries/image-editor/image-edit.php image_temp Directory Traversal.

  • CVE-2022-24774HigMar 22, 2022
    risk 0.00cvss 7.1epss 0.01

    CycloneDX BOM Repository Server is a bill of materials (BOM) repository server for distributing CycloneDX BOMs. CycloneDX BOM Repository Server before version 2.0.1 has an improper input validation vulnerability leading to path traversal. A malicious user may potentially exploit…

  • CVE-2022-1000CriMar 17, 2022
    risk 0.00cvss 9.8epss 0.02

    Path Traversal in GitHub repository prasathmani/tinyfilemanager prior to 2.4.7.

  • CVE-2021-29134MedMar 15, 2022
    risk 0.00cvss 5.3epss 0.01

    The avatar middleware in Gitea before 1.13.6 allows Directory Traversal via a crafted URL.

  • CVE-2022-23612HigFeb 22, 2022
    risk 0.00cvss 7.5epss 0.02

    OpenMRS is a patient-based medical record system focusing on giving providers a free customizable electronic medical record system. Affected versions are subject to arbitrary file exfiltration due to failure to sanitize request when satisfying GET requests for `/images` &…

  • CVE-2022-25358MedFeb 18, 2022
    risk 0.00cvss 5.3epss 0.01

    A ..%2F path traversal vulnerability exists in the path handler of awful-salmonella-tar before 0.0.4. Attackers can only list directories (not read files). This occurs because the safe-path? Scheme predicate is not used for directories.