VYPR

CWE-22

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')

BaseStableLikelihood: High

Description

The product uses external input to construct a pathname that is intended to identify a file or directory that is located underneath a restricted parent directory, but the product does not properly neutralize special elements within the pathname that can cause the pathname to resolve to a location that is outside of the restricted directory.

Hierarchy (View 1000)

Parents

Children

Related attack patterns (CAPEC)

CAPEC-126 · CAPEC-64 · CAPEC-76 · CAPEC-78 · CAPEC-79

CVEs mapped to this weakness (9,904)

page 459 of 496
  • CVE-2021-3874MedOct 15, 2021
    risk 0.00cvss 6.5epss 0.01

    bookstack is vulnerable to Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')

  • CVE-2021-27341CriSep 16, 2021
    risk 0.00cvss 9.8epss 0.02

    OpenSIS Community Edition version <= 7.6 is affected by a local file inclusion vulnerability in DownloadWindow.php via the "filename" parameter.

  • CVE-2021-41072HigSep 14, 2021
    risk 0.00cvss 8.1epss 0.02

    squashfs_opendir in unsquash-2.c in Squashfs-Tools 4.5 allows Directory Traversal, a different vulnerability than CVE-2021-40153. A squashfs filesystem that has been crafted to include a symbolic link and then contents under the same filename in a filesystem can cause unsquashfs…

  • CVE-2021-39180HigAug 31, 2021
    risk 0.00cvss 8.1epss 0.02

    OpenOLAT is a web-based learning management system (LMS). A path traversal vulnerability exists in versions prior to 15.3.18, 15.5.3, and 16.0.0. Using a specially prepared ZIP file, it is possible to overwrite any file that is writable by the application server user (e.g. the…

  • CVE-2021-40153HigAug 27, 2021
    risk 0.00cvss 8.1epss 0.03

    squashfs_opendir in unsquash-1.c in Squashfs-Tools 4.5 stores the filename in the directory entry; this is then used by unsquashfs to create the new file during the unsquash. The filename is not validated for traversal outside of the destination directory, and thus allows…

  • CVE-2021-38511HigAug 10, 2021
    risk 0.00cvss 7.5epss 0.01

    An issue was discovered in the tar crate before 0.4.36 for Rust. When symlinks are present in a TAR archive, extraction can create arbitrary directories via .. traversal.

  • CVE-2021-32814HigAug 3, 2021
    risk 0.00cvss 8.8epss 0.02

    Skytable is a NoSQL database with automated snapshots and TLS. Versions prior to 0.5.1 are vulnerable to a a directory traversal attack enabling remotely connected clients to destroy and/or manipulate critical files on the host's file system. This security bug has been patched…

  • CVE-2021-36156MedAug 3, 2021
    risk 0.00cvss 5.3epss 0.01

    An issue was discovered in Grafana Loki through 2.2.1. The header value X-Scope-OrgID is used to construct file paths for rules files, and if crafted to conduct directory traversal such as ae ../../sensitive/path/in/deployment pathname, then Loki will attempt to parse a rules…

  • CVE-2021-30483MedJul 30, 2021
    risk 0.00cvss 5.3epss 0.02

    isomorphic-git before 1.8.2 allows Directory Traversal via a crafted repository.

  • CVE-2021-31272CriJun 18, 2021
    risk 0.00cvss 9.8epss 0.03

    SerenityOS before commit 3844e8569689dd476064a0759d704bc64fb3ca2c contains a directory traversal vulnerability in tar/unzip that may lead to command execution or privilege escalation.

  • CVE-2021-33497CriMay 24, 2021
    risk 0.00cvss 9.1epss 0.02

    Dutchcoders transfer.sh before 1.2.4 allows Directory Traversal for deleting files.

  • CVE-2020-21057HigMay 20, 2021
    risk 0.00cvss 8.1epss 0.02

    Directory Traversal vulnerability in FusionPBX 4.5.7, which allows a remote malicious user to delete folders on the system via the folder variable to app/edit/folderdelete.php.

  • CVE-2020-21056MedMay 20, 2021
    risk 0.00cvss 4.3epss 0.01

    Directory Traversal vulnerability exists in FusionPBX 4.5.7, which allows a remote malicious user to create folders via the folder variale to app\edit\foldernew.php.

  • CVE-2020-21055MedMay 20, 2021
    risk 0.00cvss 6.5epss 0.01

    A Directory Traversal vulnerability exists in FusionPBX 4.5.7 allows malicoius users to rename any file of the system.via the (1) folder, (2) filename, and (3) newfilename variables in app\edit\filerename.php.

  • CVE-2021-20206HigMar 26, 2021
    risk 0.00cvss 7.2epss 0.02

    An improper limitation of path name flaw was found in containernetworking/cni in versions before 0.8.1. When specifying the plugin to load in the 'type' field in the network configuration, it is possible to use special elements such as "../" separators to reference binaries…

  • CVE-2021-27367HigFeb 17, 2021
    risk 0.00cvss 7.5epss 0.02

    Controller/Backend/FileEditController.php and Controller/Backend/FilemanagerController.php in Bolt before 4.1.13 allow Directory Traversal.

  • CVE-2020-15097CriFeb 2, 2021
    risk 0.00cvss 9.1epss 0.02

    loklak is an open-source server application which is able to collect messages from various sources, including twitter. The server contains a search index and a peer-to-peer index sharing interface. All messages are stored in an elasticsearch index. In loklak less than or equal…

  • CVE-2020-8567MedJan 21, 2021
    risk 0.00cvss 4.9epss 0.01

    Kubernetes Secrets Store CSI Driver Vault Plugin prior to v0.0.6, Azure Plugin prior to v0.0.10, and GCP Plugin prior to v0.2.0 allow an attacker who can create specially-crafted SecretProviderClass objects to write to arbitrary file paths on the host filesystem, including…

  • CVE-2020-26295HigJan 21, 2021
    risk 0.00cvss 8.7epss 0.02

    OpenMage is a community-driven alternative to Magento CE. In OpenMage before versions 19.4.10 and 20.0.5, an administrator with permission to import/export data and to edit cms pages was able to inject an executable file on the server via layout xml. The latest OpenMage Versions…

  • CVE-2020-26285HigJan 21, 2021
    risk 0.00cvss 8.7epss 0.03

    OpenMage is a community-driven alternative to Magento CE. In OpenMage before versions 19.4.10 and 20.0.5, there is a vulnerability which enables remote code execution. In affected versions an administrator with permission to import/export data and to create widget instances was…