VYPR

CWE-22

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')

BaseStableLikelihood: High

Description

The product uses external input to construct a pathname that is intended to identify a file or directory that is located underneath a restricted parent directory, but the product does not properly neutralize special elements within the pathname that can cause the pathname to resolve to a location that is outside of the restricted directory.

Hierarchy (View 1000)

Parents

Children

Related attack patterns (CAPEC)

CAPEC-126 · CAPEC-64 · CAPEC-76 · CAPEC-78 · CAPEC-79

CVEs mapped to this weakness (10,395)

page 46 of 520
  • CVE-2023-45278CriOct 19, 2023
    risk 0.59cvss 9.1epss 0.02

    Directory Traversal vulnerability in the storage functionality of the API in Yamcs 5.8.6 allows attackers to delete arbitrary files via crafted HTTP DELETE request.

  • CVE-2023-45685CriOct 16, 2023
    risk 0.59cvss 9.1epss 0.01

    Insufficient path validation when extracting a zip archive in South River Technologies' Titan MFT and Titan SFTP servers on Windows and Linux allows an authenticated attacker to write a file to any location on the filesystem via path traversal

  • CVE-2023-39407CriSep 25, 2023
    risk 0.59cvss 9.1epss 0.00

    The Watchkit has a risk of unauthorized file access.Successful exploitation of this vulnerability may affect confidentiality and integrity.

  • CVE-2020-24113CriAug 22, 2023
    risk 0.59cvss 9.1epss 0.01

    Directory Traversal vulnerability in Contacts File Upload Interface in Yealink W60B version 77.83.0.85, allows attackers to gain sensitive information and cause a denial of service (DoS).

  • CVE-2023-39402CriAug 13, 2023
    risk 0.59cvss 9.1epss 0.00

    Parameter verification vulnerability in the installd module. Successful exploitation of this vulnerability may cause sandbox files to be read and written without authorization.

  • CVE-2023-39401CriAug 13, 2023
    risk 0.59cvss 9.1epss 0.00

    Parameter verification vulnerability in the installd module. Successful exploitation of this vulnerability may cause sandbox files to be read and written without authorization.

  • CVE-2023-39400CriAug 13, 2023
    risk 0.59cvss 9.1epss 0.00

    Parameter verification vulnerability in the installd module. Successful exploitation of this vulnerability may cause sandbox files to be read and written without authorization.

  • CVE-2020-27514CriAug 11, 2023
    risk 0.59cvss 9.1epss 0.01

    Directory Traversal vulnerability in delete function in admin.api.TemplateController in ZrLog version 2.1.15, allows remote attackers to delete arbitrary files and cause a denial of service (DoS).

  • CVE-2023-33369CriAug 3, 2023
    risk 0.59cvss 9.1epss 0.01

    A path traversal vulnerability exists in Control ID IDSecure 4.7.26.0 and prior, allowing attackers to delete arbitrary files on IDSecure filesystem, causing a denial of service.

  • CVE-2023-32623CriJun 28, 2023
    risk 0.59cvss 9.1epss 0.02

    Directory traversal vulnerability in Snow Monkey Forms v5.1.1 and earlier allows a remote unauthenticated attacker to delete arbitrary files on the server.

  • CVE-2023-26216CriMay 25, 2023
    risk 0.59cvss 9.1epss 0.01

    The server component of TIBCO Software Inc.'s TIBCO EBX Add-ons contains an exploitable vulnerability that allows an attacker to upload files to a directory accessible by the web server. Affected releases are TIBCO Software Inc.'s TIBCO EBX Add-ons: versions 4.5.16 and below.

  • CVE-2023-27812CriApr 13, 2023
    risk 0.59cvss 9.1epss 0.01

    bloofox v0.5.2 was discovered to contain an arbitrary file deletion vulnerability via the delete_file() function.

  • CVE-2023-1177CriMar 24, 2023
    risk 0.59cvss 9.3epss 0.70

    Path Traversal: '\..\filename' in GitHub repository mlflow/mlflow prior to 2.2.1.

  • CVE-2023-21456CriMar 16, 2023
    risk 0.59cvss 9.0epss 0.00

    Path traversal vulnerability in Galaxy Themes Service prior to SMR Mar-2023 Release 1 allows attacker to access arbitrary file with system uid.

  • CVE-2023-0511CriFeb 28, 2023
    risk 0.59cvss 9.1epss 0.01

    Relative Path Traversal vulnerability in ForgeRock Access Management Java Policy Agent allows Authentication Bypass. This issue affects Access Management Java Policy Agent: all versions up to 5.10.1

  • CVE-2023-0339CriFeb 28, 2023
    risk 0.59cvss 9.1epss 0.01

    Relative Path Traversal vulnerability in ForgeRock Access Management Web Policy Agent allows Authentication Bypass. This issue affects Access Management Web Policy Agent: all versions up to 5.10.1

  • CVE-2023-24188CriFeb 13, 2023
    risk 0.59cvss 9.1epss 0.01

    ureport v2.2.9 was discovered to contain a directory traversal vulnerability via the deletion function which allows for arbitrary files to be deleted.

  • CVE-2021-37317CriFeb 3, 2023
    risk 0.59cvss 9.1epss 0.02

    Directory Traversal vulnerability in Cloud Disk in ASUS RT-AC68U router firmware version before 3.0.0.4.386.41634 allows remote attackers to write arbitrary files via improper sanitation on the target for COPY and MOVE operations.

  • CVE-2020-18331CriJan 26, 2023
    risk 0.59cvss 9.1epss 0.01

    Directory traversal vulnerability in ChinaMobile PLC Wireless Router model GPN2.4P21-C-CN running the firmware version W2000EN-01(hardware platform Gpn2.4P21-C_WIFI-V0.05), via the getpage parameter to /cgi-bin/webproc.

  • CVE-2020-18330CriJan 26, 2023
    risk 0.59cvss 9.1epss 0.01

    An issue was discovered in the default configuration of ChinaMobile PLC Wireless Router model GPN2.4P21-C-CN running the firmware version W2000EN-01(hardware platform Gpn2.4P21-C_WIFI-V0.05), allows attackers to gain access to the configuration interface.