VYPR

CWE-22

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')

BaseStableLikelihood: High

Description

The product uses external input to construct a pathname that is intended to identify a file or directory that is located underneath a restricted parent directory, but the product does not properly neutralize special elements within the pathname that can cause the pathname to resolve to a location that is outside of the restricted directory.

Hierarchy (View 1000)

Parents

Children

Related attack patterns (CAPEC)

CAPEC-126 · CAPEC-64 · CAPEC-76 · CAPEC-78 · CAPEC-79

CVEs mapped to this weakness (9,901)

page 461 of 496
  • CVE-2020-11498HigApr 2, 2020
    risk 0.00cvss 8.8epss 0.03

    Slack Nebula through 1.1.0 contains a relative path vulnerability that allows a low-privileged attacker to execute code in the context of the root user via tun_darwin.go or tun_windows.go. A user can also use Nebula to execute arbitrary code in the user's own context, e.g., for…

  • CVE-2020-10696HigMar 31, 2020
    risk 0.00cvss 8.8epss 0.03

    A path traversal flaw was found in Buildah in versions before 1.14.5. This flaw allows an attacker to trick a user into building a malicious container image hosted on an HTTP(s) server and then write files to the user's system anywhere that the user has permissions.

  • CVE-2020-8131HigFeb 24, 2020
    risk 0.00cvss 7.5epss 0.05

    Arbitrary filesystem write vulnerability in Yarn before 1.22.0 allows attackers to write to any path on the filesystem and potentially lead to arbitrary code execution by forcing the user to install a malicious package.

  • CVE-2020-8545HigFeb 3, 2020
    risk 0.00cvss 7.5epss 0.01

    Global.py in AIL framework 2.8 allows path traversal.

  • CVE-2020-5221MedJan 22, 2020
    risk 0.00cvss 6.5epss 0.01

    In uftpd before 2.11, it is possible for an unauthenticated user to perform a directory traversal attack using multiple different FTP commands and read and write to arbitrary locations on the filesystem due to the lack of a well-written chroot jail in compose_abspath(). This has…

  • CVE-2019-11246MedAug 29, 2019
    risk 0.00cvss 6.5epss 0.04

    The kubectl cp command allows copying files between containers and the user machine. To copy files from a container, Kubernetes runs tar inside the container to create a tar archive, copies it over the network, and kubectl unpacks it on the user’s machine. If the tar binary in…

  • CVE-2019-15520MedAug 23, 2019
    risk 0.00cvss 5.3epss 0.02

    comelz Quark before 2019-03-26 allows directory traversal to locations outside of the project directory.

  • CVE-2019-15519CriAug 23, 2019
    risk 0.00cvss 9.8epss 0.03

    Power-Response before 2019-02-02 allows directory traversal (up to the application's main directory) via a plugin.

  • CVE-2019-15518MedAug 23, 2019
    risk 0.00cvss 5.3epss 0.02

    Swoole before 4.2.13 allows directory traversal in swPort_http_static_handler.

  • CVE-2019-15517MedAug 23, 2019
    risk 0.00cvss 5.5epss 0.01

    jc21 Nginx Proxy Manager before 2.0.13 allows %2e%2e%2f directory traversal.

  • CVE-2019-15516HigAug 23, 2019
    risk 0.00cvss 7.5epss 0.02

    Cuberite before 2019-06-11 allows webadmin directory traversal via ....// because the protection mechanism simply removes one ../ substring.

  • CVE-2019-10185HigJul 31, 2019
    risk 0.00cvss 8.6epss 0.04

    It was found that icedtea-web up to and including 1.7.2 and 1.8.2 was vulnerable to a zip-slip attack during auto-extraction of a JAR file. An attacker could use this flaw to write files to arbitrary locations. This could also be used to replace the main running application and,…

  • CVE-2019-10182HigJul 31, 2019
    risk 0.00cvss 8.2epss 0.03

    It was found that icedtea-web though 1.7.2 and 1.8.2 did not properly sanitize paths from elements in JNLP files. An attacker could trick a victim into running a specially crafted application and use this flaw to upload arbitrary files to arbitrary locations in the…

  • CVE-2019-14452HigJul 31, 2019
    risk 0.00cvss 7.5epss 0.04

    Sigil before 0.9.16 is vulnerable to a directory traversal, allowing attackers to write arbitrary files via a ../ (dot dot slash) in a ZIP archive entry that is mishandled during extraction.

  • CVE-2019-10152HigJul 30, 2019
    risk 0.00cvss 7.2epss 0.00

    A path traversal vulnerability has been discovered in podman before version 1.4.0 in the way it handles symlinks inside containers. An attacker who has compromised an existing container can cause arbitrary files on the host filesystem to be read/written when an administrator…

  • CVE-2018-17180MedMay 17, 2019
    risk 0.00cvss 5.3epss 0.02

    An issue was discovered in OpenEMR before 5.0.1 Patch 7. Directory Traversal exists via docid=../ to /portal/lib/download_template.php.

  • CVE-2019-5624HigApr 30, 2019
    risk 0.00cvss 7.3epss 0.03

    Rapid7 Metasploit Framework suffers from an instance of CWE-22, Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') in the Zip import function of Metasploit. Exploiting this vulnerability can allow an attacker to execute arbitrary code in Metasploit at…

  • CVE-2019-9889LowMar 21, 2019
    risk 0.00cvss 2.7epss 0.02

    In Vanilla before 2.6.4, a flaw exists within the getSingleIndex function of the AddonManager class. The issue results in a require call using a crafted type value, leading to Directory Traversal with File Inclusion. An attacker can leverage this vulnerability to execute code…

  • CVE-2019-9195CriFeb 26, 2019
    risk 0.00cvss 9.8epss 0.04

    util/src/zip.rs in Grin before 1.0.2 mishandles suspicious files. An attacker can execute arbitrary code via directory traversal in a ZIP archive.

  • CVE-2018-20332HigDec 21, 2018
    risk 0.00cvss 7.5epss 0.02

    An issue has been discovered in the OpenWebif plugin through 1.2.4 for Enigma2 based devices. Reading of arbitrary files is possible with /file?action=download&file= followed by a full pathname, and listing of arbitrary directories is possible with /file?action=download&dir=…