VYPR

CWE-22

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')

BaseStableLikelihood: High

Description

The product uses external input to construct a pathname that is intended to identify a file or directory that is located underneath a restricted parent directory, but the product does not properly neutralize special elements within the pathname that can cause the pathname to resolve to a location that is outside of the restricted directory.

Hierarchy (View 1000)

Parents

Children

Related attack patterns (CAPEC)

CAPEC-126 · CAPEC-64 · CAPEC-76 · CAPEC-78 · CAPEC-79

CVEs mapped to this weakness (10,395)

page 484 of 520
  • CVE-2020-21056MedMay 20, 2021
    risk 0.00cvss 4.3epss 0.01

    Directory Traversal vulnerability exists in FusionPBX 4.5.7, which allows a remote malicious user to create folders via the folder variale to app\edit\foldernew.php.

  • CVE-2020-21055MedMay 20, 2021
    risk 0.00cvss 6.5epss 0.01

    A Directory Traversal vulnerability exists in FusionPBX 4.5.7 allows malicoius users to rename any file of the system.via the (1) folder, (2) filename, and (3) newfilename variables in app\edit\filerename.php.

  • CVE-2021-20206HigMar 26, 2021
    risk 0.00cvss 7.2epss 0.02

    An improper limitation of path name flaw was found in containernetworking/cni in versions before 0.8.1. When specifying the plugin to load in the 'type' field in the network configuration, it is possible to use special elements such as "../" separators to reference binaries…

  • CVE-2021-27367HigFeb 17, 2021
    risk 0.00cvss 7.5epss 0.02

    Controller/Backend/FileEditController.php and Controller/Backend/FilemanagerController.php in Bolt before 4.1.13 allow Directory Traversal.

  • CVE-2020-15097CriFeb 2, 2021
    risk 0.00cvss 9.1epss 0.02

    loklak is an open-source server application which is able to collect messages from various sources, including twitter. The server contains a search index and a peer-to-peer index sharing interface. All messages are stored in an elasticsearch index. In loklak less than or equal…

  • CVE-2020-8567MedJan 21, 2021
    risk 0.00cvss 4.9epss 0.01

    Kubernetes Secrets Store CSI Driver Vault Plugin prior to v0.0.6, Azure Plugin prior to v0.0.10, and GCP Plugin prior to v0.2.0 allow an attacker who can create specially-crafted SecretProviderClass objects to write to arbitrary file paths on the host filesystem, including…

  • CVE-2020-26295HigJan 21, 2021
    risk 0.00cvss 8.7epss 0.02

    OpenMage is a community-driven alternative to Magento CE. In OpenMage before versions 19.4.10 and 20.0.5, an administrator with permission to import/export data and to edit cms pages was able to inject an executable file on the server via layout xml. The latest OpenMage Versions…

  • CVE-2020-26285HigJan 21, 2021
    risk 0.00cvss 8.7epss 0.03

    OpenMage is a community-driven alternative to Magento CE. In OpenMage before versions 19.4.10 and 20.0.5, there is a vulnerability which enables remote code execution. In affected versions an administrator with permission to import/export data and to create widget instances was…

  • CVE-2020-26252HigJan 20, 2021
    risk 0.00cvss 8.7epss 0.02

    OpenMage is a community-driven alternative to Magento CE. In OpenMage before versions 19.4.10 and 20.0.6, there is a vulnerability which enables remote code execution. In affected versions an administrator with permission to update product data to be able to store an executable…

  • CVE-2021-3178MedJan 19, 2021
    risk 0.00cvss 6.5epss 0.02

    fs/nfsd/nfs3xdr.c in the Linux kernel through 5.10.8, when there is an NFS export of a subdirectory of a filesystem, allows remote attackers to traverse to other parts of the filesystem via READDIRPLUS. NOTE: some parties argue that such a subdirectory export is not intended to…

  • CVE-2021-3139HigJan 13, 2021
    risk 0.00cvss 8.1epss 0.03

    In Open-iSCSI tcmu-runner 1.3.x, 1.4.x, and 1.5.x through 1.5.2, xcopy_locate_udev in tcmur_cmd_handler.c lacks a check for transport-layer restrictions, allowing remote attackers to read or write files via directory traversal in an XCOPY request. For example, an attack can…

  • CVE-2020-35883CriDec 31, 2020
    risk 0.00cvss 9.1epss 0.02

    An issue was discovered in the mozwire crate through 2020-08-18 for Rust. A ../ directory-traversal situation allows overwriting local files that have .conf at the end of the filename.

  • CVE-2020-27534MedDec 30, 2020
    risk 0.00cvss 5.3epss 0.02

    util/binfmt_misc/check.go in Builder in Docker Engine before 19.03.9 calls os.OpenFile with a potentially unsafe qemu-check temporary pathname, constructed with an empty first argument in an ioutil.TempDir call.

  • CVE-2020-29373MedNov 28, 2020
    risk 0.00cvss 6.5epss 0.01

    An issue was discovered in fs/io_uring.c in the Linux kernel before 5.6. It unsafely handles the root directory during path lookups, and thus a process inside a mount namespace can escape to unintended filesystem locations, aka CID-ff002b30181d.

  • CVE-2020-15236HigOct 5, 2020
    risk 0.00cvss 8.6epss 0.02

    In Wiki.js before version 2.5.151, directory traversal outside of Wiki.js context is possible when a storage module with local asset cache fetching is enabled. A malicious user can potentially read any file on the file system by crafting a special URL that allows for directory…

  • CVE-2020-24621HigSep 25, 2020
    risk 0.00cvss 8.8epss 0.03

    A remote code execution (RCE) vulnerability was discovered in the htmlformentry (aka HTML Form Entry) module before 3.11.0 for OpenMRS. By leveraging path traversal, a malicious Velocity Template Language file could be written to a directory. This file could then be accessed and…

  • CVE-2020-15182HigSep 17, 2020
    risk 0.00cvss 8.4epss 0.01

    The SOY Inquiry component of SOY CMS is affected by Cross-site Request Forgery (CSRF) and Remote Code Execution (RCE). The vulnerability affects versions 2.0.0.3 and earlier of SOY Inquiry. This allows remote attackers to force the administrator to edit files once the…

  • CVE-2020-2275MedSep 16, 2020
    risk 0.00cvss 6.5epss 0.02

    Jenkins Copy data to workspace Plugin 1.0 and earlier does not limit which directories can be copied from the Jenkins controller to job workspaces, allowing attackers with Job/Configure permission to read arbitrary files on the Jenkins controller.

  • CVE-2020-7669HigSep 1, 2020
    risk 0.00cvss 7.5epss 0.02

    This affects all versions of package github.com/u-root/u-root/pkg/tarutil. It is vulnerable to both leading and non-leading relative path traversal attacks in tar file extraction.

  • CVE-2020-7666HigSep 1, 2020
    risk 0.00cvss 7.5epss 0.02

    This affects all versions of package github.com/u-root/u-root/pkg/cpio. It is vulnerable to leading, non-leading relative path traversal attacks and symlink based (relative and absolute) path traversal attacks in cpio file extraction.