VYPR

CWE-22

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')

BaseStableLikelihood: High

Description

The product uses external input to construct a pathname that is intended to identify a file or directory that is located underneath a restricted parent directory, but the product does not properly neutralize special elements within the pathname that can cause the pathname to resolve to a location that is outside of the restricted directory.

Hierarchy (View 1000)

Parents

Children

Related attack patterns (CAPEC)

CAPEC-126 · CAPEC-64 · CAPEC-76 · CAPEC-78 · CAPEC-79

CVEs mapped to this weakness (10,395)

page 47 of 520
  • CVE-2022-47945CriDec 23, 2022
    risk 0.59cvss 9.8epss 0.28

    ThinkPHP Framework before 6.0.14 allows local file inclusion via the lang parameter when the language pack feature is enabled (lang_switch_on=true). An unauthenticated and remote attacker can exploit this to execute arbitrary operating system commands, as demonstrated by…

  • CVE-2022-45290CriDec 9, 2022
    risk 0.59cvss 9.1epss 0.01

    Kbase Doc v1.0 was discovered to contain an arbitrary file deletion vulnerability via the component /web/IndexController.java.

  • CVE-2022-37865CriNov 7, 2022
    risk 0.59cvss 9.1epss 0.02

    With Apache Ivy 2.4.0 an optional packaging attribute has been introduced that allows artifacts to be unpacked on the fly if they used pack200 or zip packaging. For artifacts using the "zip", "jar" or "war" packaging Ivy prior to 2.5.1 doesn't verify the target path when…

  • CVE-2022-33897CriOct 25, 2022
    risk 0.59cvss 9.1epss 0.01

    A directory traversal vulnerability exists in the web_server /ajax/remove/ functionality of Robustel R1510 3.1.16. A specially-crafted network request can lead to arbitrary file deletion. An attacker can send a sequence of requests to trigger this vulnerability.

  • CVE-2022-42308CriOct 3, 2022
    risk 0.59cvss 9.0epss 0.00

    An issue was discovered in Veritas NetBackup through 8.2 and related Veritas products. An attacker with local access can delete arbitrary files by leveraging a path traversal in the pbx_exchange registration code.

  • CVE-2022-38340CriSep 20, 2022
    risk 0.59cvss 9.1epss 0.01

    Safe Software FME Server v2021.2.5, v2022.0.0.2 and below was discovered to contain a Path Traversal vulnerability via the component fmedataupload.

  • CVE-2022-36261CriAug 23, 2022
    risk 0.59cvss 9.1epss 0.01

    An arbitrary file deletion vulnerability was discovered in taocms 3.0.2, that allows attacker to delete file in server when request url admin.php?action=file&ctrl=del&path=/../../../test.txt

  • CVE-2022-20812CriJul 6, 2022
    risk 0.59cvss 9.0epss 0.02

    Multiple vulnerabilities in the API and in the web-based management interface of Cisco Expressway Series and Cisco TelePresence Video Communication Server (VCS) could allow a remote attacker to overwrite arbitrary files or conduct null byte poisoning attacks on an affected…

  • CVE-2022-1953CriJun 27, 2022
    risk 0.59cvss 9.1epss 0.02

    The Product Configurator for WooCommerce WordPress plugin before 1.2.32 suffers from an arbitrary file deletion vulnerability via an AJAX action, accessible to unauthenticated users, which accepts user input that is being used in a path and passed to unlink() without validation…

  • CVE-2022-30117CriJun 24, 2022
    risk 0.59cvss 9.1epss 0.02

    Concrete 8.5.7 and below as well as Concrete 9.0 through 9.0.2 allow traversal in /index.php/ccm/system/file/upload which could result in an Arbitrary File Delete exploit. This was remediated by sanitizing /index.php/ccm/system/file/upload to ensure Concrete doesn’t allow…

  • CVE-2022-32328CriJun 14, 2022
    risk 0.59cvss 9.1epss 0.01

    Fast Food Ordering System v1.0 is vulnerable to Delete any file. via /ffos/classes/Master.php?f=delete_img.

  • CVE-2022-31483CriJun 6, 2022
    risk 0.59cvss 9.1epss 0.02

    An authenticated attacker can upload a file with a filename including “..” and “/” to achieve the ability to upload the desired file anywhere on the filesystem. This vulnerability impacts products based on HID Mercury Intelligent Controllers LP1501, LP1502, LP2500,…

  • CVE-2022-25591CriMay 13, 2022
    risk 0.59cvss 9.1epss 0.03

    BlogEngine.NET v3.3.8.0 was discovered to contain an arbitrary file deletion vulnerability which allows attackers to delete files within the web server root directory via a crafted HTTP request.

  • CVE-2021-22794CriApr 13, 2022
    risk 0.59cvss 9.1epss 0.02

    A CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability exists that could cause remote code execution. Affected Product: StruxureWare Data Center Expert (V7.8.1 and prior)

  • CVE-2022-27277CriApr 10, 2022
    risk 0.59cvss 9.1epss 0.01

    InHand Networks InRouter 900 Industrial 4G Router before v1.0.0.r11700 was discovered to contain an arbitrary file deletion vulnerability via the function sub_17C08.

  • CVE-2021-42853CriMar 10, 2022
    risk 0.59cvss 9.1epss 0.02

    It was discovered that the SteelCentral AppInternals Dynamic Sampling Agent's (DSA) AgentDiagnosticServlet has directory traversal vulnerability at the "/api/appInternals/1.0/agent/diagnostic/logs" API. The affected endpoint does not have any input validation of the user's input…

  • CVE-2021-42767CriMar 1, 2022
    risk 0.59cvss 9.1epss 0.02

    A directory traversal vulnerability in the apoc plugins in Neo4J Graph database before 4.4.0.1 allows attackers to read local files, and sometimes create local files. This is fixed in 3.5.17, 4.2.10, 4.3.0.4, and 4.4.0.1.

  • CVE-2022-21371HigJan 19, 2022
    risk 0.59cvss 7.5epss 0.93

    Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Web Container). Supported versions that are affected are 12.1.3.0.0, 12.2.1.3.0, 12.2.1.4.0 and 14.1.1.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network…

  • CVE-2021-40525CriJan 4, 2022
    risk 0.59cvss 9.1epss 0.04

    Apache James ManagedSieve implementation alongside with the file storage for sieve scripts is vulnerable to path traversal, allowing reading and writing any file. This vulnerability had been patched in Apache James 3.6.1 and higher. We recommend the upgrade. Distributed and…

  • CVE-2020-20944CriDec 27, 2021
    risk 0.59cvss 9.1epss 0.02

    An issue in /admin/index.php?lfj=mysql&action=del of Qibosoft v7 allows attackers to arbitrarily delete files.