VYPR

CWE-22

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')

BaseStableLikelihood: High

Description

The product uses external input to construct a pathname that is intended to identify a file or directory that is located underneath a restricted parent directory, but the product does not properly neutralize special elements within the pathname that can cause the pathname to resolve to a location that is outside of the restricted directory.

Hierarchy (View 1000)

Parents

Children

Related attack patterns (CAPEC)

CAPEC-126 · CAPEC-64 · CAPEC-76 · CAPEC-78 · CAPEC-79

CVEs mapped to this weakness (10,395)

page 479 of 520
  • CVE-2023-35852HigJun 19, 2023
    risk 0.00cvss 7.5epss 0.01

    In Suricata before 6.0.13 (when there is an adversary who controls an external source of rules), a dataset filename, that comes from a rule, may trigger absolute or relative directory traversal, and lead to write access to a local filesystem. This is addressed in 6.0.13 by…

  • CVE-2023-35844HigJun 19, 2023
    risk 0.00cvss 7.5epss 0.06

    packages/backend/src/routers in Lightdash before 0.510.3 has insecure file endpoints, e.g., they allow .. directory traversal and do not ensure that an intended file extension (.csv or .png) is used.

  • CVE-2023-33690MedJun 5, 2023
    risk 0.00cvss 6.5epss 0.01

    SonicJS up to v0.7.0 allows attackers to execute an authenticated path traversal when an attacker injects special characters into the filename of a backup CMS.

  • CVE-2023-32676MedMay 26, 2023
    risk 0.00cvss 6.7epss 0.01

    Autolab is a course management service that enables auto-graded programming assignments. A Tar slip vulnerability was found in the Install assessment functionality of Autolab. To exploit this vulnerability an authenticated attacker with instructor permissions needs to upload a…

  • CVE-2023-32317MedMay 26, 2023
    risk 0.00cvss 6.7epss 0.01

    Autolab is a course management service that enables auto-graded programming assignments. A Tar slip vulnerability was found in the MOSS cheat checker functionality of Autolab. To exploit this vulnerability an authenticated attacker with instructor permissions needs to upload a…

  • CVE-2023-32322MedMay 18, 2023
    risk 0.00cvss 4.9epss 0.02

    Ombi is an open source application which allows users to request specific media from popular self-hosted streaming servers. Versions prior to 4.38.2 contain an arbitrary file read vulnerability where an Ombi administrative user may access files available to the Ombi server…

  • CVE-2023-25815LowApr 25, 2023
    risk 0.00cvss 3.3epss 0.01

    In Git for Windows, the Windows port of Git, no localized messages are shipped with the installer. As a consequence, Git is expected not to localize messages at all, and skips the gettext initialization. However, due to a change in MINGW-packages, the `gettext()` function's…

  • CVE-2020-19678HigApr 6, 2023
    risk 0.00cvss 7.5epss 0.03

    Directory Traversal vulnerability found in Pfsense v.2.1.3 and Pfsense Suricata v.1.4.6 pkg v.1.0.1 allows a remote attacker to obtain sensitive information via the file parameter to suricata/suricata_logs_browser.php.

  • CVE-2023-28833LowMar 30, 2023
    risk 0.00cvss 2.4epss 0.01

    Nextcloud server is an open source home cloud implementation. In affected versions admins of a server were able to upload a logo or a favicon and to provided a file name which was not restricted and could overwrite files in the appdata directory. Administrators may have access…

  • CVE-2023-28371CriMar 15, 2023
    risk 0.00cvss 9.8epss 0.02

    In Stellarium through 1.2, attackers can write to files that are typically unintended, such as ones with absolute pathnames or .. directory traversal.

  • CVE-2023-27588HigMar 14, 2023
    risk 0.00cvss 7.5epss 0.01

    Hasura is an open-source product that provides users GraphQL or REST APIs. A path traversal vulnerability has been discovered within Hasura GraphQL Engine prior to versions 1.3.4, 2.55.1, 2.20.1, and 2.21.0-beta1. Projects running on Hasura Cloud were not vulnerable. Self-hosted…

  • CVE-2023-25802HigMar 13, 2023
    risk 0.00cvss 7.5epss 0.01

    Roxy-WI is a Web interface for managing Haproxy, Nginx, Apache, and Keepalived servers. Versions prior to 6.3.6.0 don't correctly neutralize `dir/../filename` sequences, such as `/etc/nginx/../passwd`, allowing an actor to gain information about a server. Version 6.3.6.0 has a…

  • CVE-2017-20181MedMar 7, 2023
    risk 0.00cvss 5.3epss 0.00

    A vulnerability classified as critical was found in hgzojer Vocable Trainer up to 1.3.0 on Android. This vulnerability affects unknown code of the file src/at/hgz/vocabletrainer/VocableTrainerProvider.java. The manipulation leads to path traversal. Attacking locally is a…

  • CVE-2023-25579MedFeb 22, 2023
    risk 0.00cvss 6.0epss 0.01

    Nextcloud server is a self hosted home cloud product. In affected versions the `OC\Files\Node\Folder::getFullPath()` function was validating and normalizing the string in the wrong order. The function is used in the `newFile()` and `newFolder()` items, which may allow to…

  • CVE-2023-0947CriFeb 22, 2023
    risk 0.00cvss 9.8epss 0.04

    Path Traversal in GitHub repository flatpressblog/flatpress prior to 1.3.

  • CVE-2023-23946MedFeb 14, 2023
    risk 0.00cvss 6.2epss 0.01

    Git, a revision control system, is vulnerable to path traversal prior to versions 2.39.2, 2.38.4, 2.37.6, 2.36.5, 2.35.7, 2.34.7, 2.33.7, 2.32.6, 2.31.7, and 2.30.8. By feeding a crafted input to `git apply`, a path outside the working tree can be overwritten as the user who is…

  • CVE-2023-0593MedJan 31, 2023
    risk 0.00cvss 5.5epss 0.00

    A path traversal vulnerability affects yaffshiv YAFFS filesystem extractor. By crafting a malicious YAFFS file, an attacker could force yaffshiv to write outside of the extraction directory. This issue affects yaffshiv up to version 0.1 included, which is the most recent at…

  • CVE-2023-0592MedJan 31, 2023
    risk 0.00cvss 5.5epss 0.00

    A path traversal vulnerability affects jefferson's JFFS2 filesystem extractor. By crafting malicious JFFS2 files, attackers could force jefferson to write outside of the extraction directory.This issue affects jefferson: before 0.4.1.

  • CVE-2023-23608NonJan 26, 2023
    risk 0.00cvss 0.0epss 0.01

    Spotipy is a light weight Python library for the Spotify Web API. In versions prior to 2.22.1, if a malicious URI is passed to the library, the library can be tricked into performing an operation on a different API endpoint than intended. The code Spotipy uses to parse URIs and…

  • CVE-2020-36647MedJan 8, 2023
    risk 0.00cvss 5.5epss 0.01

    A vulnerability classified as critical has been found in YunoHost-Apps transmission_ynh. Affected is an unknown function of the file conf/nginx.conf. The manipulation leads to path traversal. The patch is identified as f136dfd44eda128129e5fd2d850a3a3c600e6a4a. It is recommended…