VYPR

CWE-22

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')

BaseStableLikelihood: High

Description

The product uses external input to construct a pathname that is intended to identify a file or directory that is located underneath a restricted parent directory, but the product does not properly neutralize special elements within the pathname that can cause the pathname to resolve to a location that is outside of the restricted directory.

Hierarchy (View 1000)

Parents

Children

Related attack patterns (CAPEC)

CAPEC-126 · CAPEC-64 · CAPEC-76 · CAPEC-78 · CAPEC-79

CVEs mapped to this weakness (10,395)

page 483 of 520
  • CVE-2021-41242HigDec 10, 2021
    risk 0.00cvss 8.1epss 0.01

    OpenOlat is a web-basedlearning management system. A path traversal vulnerability exists in OpenOlat prior to versions 15.5.12 and 16.0.5. By providing a filename that contains a relative path as a parameter in some REST methods, it is possible to create directory structures and…

  • CVE-2021-43800HigDec 6, 2021
    risk 0.00cvss 7.5epss 0.02

    Wiki.js is a wiki app built on Node.js. Prior to version 2.5.254, directory traversal outside of Wiki.js context is possible when a storage module with local asset cache fetching is enabled on a Windows host. A malicious user can potentially read any file on the file system by…

  • CVE-2021-44278CriDec 3, 2021
    risk 0.00cvss 9.8epss 0.01

    Librenms 21.11.0 is affected by a path manipulation vulnerability in includes/html/pages/device/showconfig.inc.php.

  • CVE-2021-3916MedNov 5, 2021
    risk 0.00cvss 6.5epss 0.01

    bookstack is vulnerable to Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')

  • CVE-2019-3556HigOct 26, 2021
    risk 0.00cvss 8.1epss 0.02

    HHVM supports the use of an "admin" server which accepts administrative requests over HTTP. One of those request handlers, dump-pcre-cache, can be used to output cached regular expressions from the current execution context into a file. The handler takes a parameter which…

  • CVE-2021-41185HigOct 26, 2021
    risk 0.00cvss 8.8epss 0.01

    Mycodo is an environmental monitoring and regulation system. An exploit in versions prior to 8.12.7 allows anyone with access to endpoints to download files outside the intended directory. A patch has been applied and a release made. Users should upgrade to version 8.12.7. As a…

  • CVE-2021-41178HigOct 25, 2021
    risk 0.00cvss 8.8epss 0.02

    Nextcloud is an open-source, self-hosted productivity platform. Prior to versions 20.0.13, 21.0.5, and 22.2.0, a file traversal vulnerability makes an attacker able to download arbitrary SVG images from the host system, including user provided files. This could also be leveraged…

  • CVE-2021-41152HigOct 18, 2021
    risk 0.00cvss 7.7epss 0.01

    OpenOlat is a web-based e-learning platform for teaching, learning, assessment and communication, an LMS, a learning management system. In affected versions by manipulating the HTTP request an attacker can modify the path of a requested file download in the folder component to…

  • CVE-2021-3874MedOct 15, 2021
    risk 0.00cvss 6.5epss 0.01

    bookstack is vulnerable to Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')

  • CVE-2021-27341CriSep 16, 2021
    risk 0.00cvss 9.8epss 0.02

    OpenSIS Community Edition version <= 7.6 is affected by a local file inclusion vulnerability in DownloadWindow.php via the "filename" parameter.

  • CVE-2021-41072HigSep 14, 2021
    risk 0.00cvss 8.1epss 0.02

    squashfs_opendir in unsquash-2.c in Squashfs-Tools 4.5 allows Directory Traversal, a different vulnerability than CVE-2021-40153. A squashfs filesystem that has been crafted to include a symbolic link and then contents under the same filename in a filesystem can cause unsquashfs…

  • CVE-2021-39180HigAug 31, 2021
    risk 0.00cvss 8.1epss 0.02

    OpenOLAT is a web-based learning management system (LMS). A path traversal vulnerability exists in versions prior to 15.3.18, 15.5.3, and 16.0.0. Using a specially prepared ZIP file, it is possible to overwrite any file that is writable by the application server user (e.g. the…

  • CVE-2021-40153HigAug 27, 2021
    risk 0.00cvss 8.1epss 0.03

    squashfs_opendir in unsquash-1.c in Squashfs-Tools 4.5 stores the filename in the directory entry; this is then used by unsquashfs to create the new file during the unsquash. The filename is not validated for traversal outside of the destination directory, and thus allows…

  • CVE-2021-38511HigAug 10, 2021
    risk 0.00cvss 7.5epss 0.01

    An issue was discovered in the tar crate before 0.4.36 for Rust. When symlinks are present in a TAR archive, extraction can create arbitrary directories via .. traversal.

  • CVE-2021-32814HigAug 3, 2021
    risk 0.00cvss 8.8epss 0.02

    Skytable is a NoSQL database with automated snapshots and TLS. Versions prior to 0.5.1 are vulnerable to a a directory traversal attack enabling remotely connected clients to destroy and/or manipulate critical files on the host's file system. This security bug has been patched…

  • CVE-2021-36156MedAug 3, 2021
    risk 0.00cvss 5.3epss 0.01

    An issue was discovered in Grafana Loki through 2.2.1. The header value X-Scope-OrgID is used to construct file paths for rules files, and if crafted to conduct directory traversal such as ae ../../sensitive/path/in/deployment pathname, then Loki will attempt to parse a rules…

  • CVE-2021-30483MedJul 30, 2021
    risk 0.00cvss 5.3epss 0.02

    isomorphic-git before 1.8.2 allows Directory Traversal via a crafted repository.

  • CVE-2021-31272CriJun 18, 2021
    risk 0.00cvss 9.8epss 0.03

    SerenityOS before commit 3844e8569689dd476064a0759d704bc64fb3ca2c contains a directory traversal vulnerability in tar/unzip that may lead to command execution or privilege escalation.

  • CVE-2021-33497CriMay 24, 2021
    risk 0.00cvss 9.1epss 0.02

    Dutchcoders transfer.sh before 1.2.4 allows Directory Traversal for deleting files.

  • CVE-2020-21057HigMay 20, 2021
    risk 0.00cvss 8.1epss 0.02

    Directory Traversal vulnerability in FusionPBX 4.5.7, which allows a remote malicious user to delete folders on the system via the folder variable to app/edit/folderdelete.php.