VYPR

CWE-22

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')

BaseStableLikelihood: High

Description

The product uses external input to construct a pathname that is intended to identify a file or directory that is located underneath a restricted parent directory, but the product does not properly neutralize special elements within the pathname that can cause the pathname to resolve to a location that is outside of the restricted directory.

Hierarchy (View 1000)

Parents

Children

Related attack patterns (CAPEC)

CAPEC-126 · CAPEC-64 · CAPEC-76 · CAPEC-78 · CAPEC-79

CVEs mapped to this weakness (10,395)

page 485 of 520
  • CVE-2020-7665HigSep 1, 2020
    risk 0.00cvss 7.5epss 0.02

    This affects all versions of package github.com/u-root/u-root/pkg/uzip. It is vulnerable to both leading and non-leading relative path traversal attacks in zip file extraction.

  • CVE-2020-15908HigJul 23, 2020
    risk 0.00cvss 7.5epss 0.02

    tar/TarFileReader.cpp in Cauldron cbang (aka C-Bang or C!) before 1.6.0 allows Directory Traversal during extraction from a TAR archive.

  • CVE-2020-15124CriJul 22, 2020
    risk 0.00cvss 9.6epss 0.02

    In Goobi Viewer Core before version 4.8.3, a path traversal vulnerability allows for remote attackers to access files on the server via the application. This is limited to files accessible to the application server user, eg. tomcat, but can potentially lead to the disclosure of…

  • CVE-2020-13795MedJun 3, 2020
    risk 0.00cvss 5.3epss 0.02

    An issue was discovered in Navigate CMS through 2.8.7. It allows Directory Traversal because lib/packages/templates/template.class.php mishandles ../ and ..\ substrings.

  • CVE-2020-11073HigMay 13, 2020
    risk 0.00cvss 7.9epss 0.01

    In Autoswitch Python Virtualenv before version 0.16.0, a user who enters a directory with a malicious `.venv` file could run arbitrary code without any user interaction. This is fixed in version: 1.16.0

  • CVE-2020-12649HigMay 5, 2020
    risk 0.00cvss 7.5epss 0.02

    Gurbalib through 2020-04-30 allows lib/cmds/player/help.c directory traversal for reading administrative paths.

  • CVE-2020-12479HigApr 29, 2020
    risk 0.00cvss 8.8epss 0.03

    TeamPass 2.1.27.36 allows any authenticated TeamPass user to trigger a PHP file include vulnerability via a crafted HTTP request with sources/users.queries.php newValue directory traversal.

  • CVE-2020-12443CriApr 29, 2020
    risk 0.00cvss 9.8epss 0.04

    BigBlueButton before 2.2.6 allows remote attackers to read arbitrary files because the presfilename (lowercase) value can be a .pdf filename while the presFilename (mixed case) value has a ../ sequence. This can be leveraged for privilege escalation via a directory traversal to…

  • CVE-2020-12103HigApr 28, 2020
    risk 0.00cvss 7.7epss 0.01

    In Tiny File Manager 2.4.1 there is a vulnerability in the ajax file backup copy functionality which allows authenticated users to create backup copies of files (with .bak extension) outside the scope in the same directory in which they are stored.

  • CVE-2020-12102HigApr 28, 2020
    risk 0.00cvss 7.7epss 0.02

    In Tiny File Manager 2.4.1, there is a Path Traversal vulnerability in the ajax recursive directory listing functionality. This allows authenticated users to enumerate directories and files on the filesystem (outside of the application scope).

  • CVE-2020-11736LowApr 13, 2020
    risk 0.00cvss 3.9epss 0.01

    fr-archive-libarchive.c in GNOME file-roller through 3.36.1 allows Directory Traversal during extraction because it lacks a check of whether a file's parent is a symlink to a directory outside of the intended extraction location.

  • CVE-2020-11498HigApr 2, 2020
    risk 0.00cvss 8.8epss 0.03

    Slack Nebula through 1.1.0 contains a relative path vulnerability that allows a low-privileged attacker to execute code in the context of the root user via tun_darwin.go or tun_windows.go. A user can also use Nebula to execute arbitrary code in the user's own context, e.g., for…

  • CVE-2020-10696HigMar 31, 2020
    risk 0.00cvss 8.8epss 0.03

    A path traversal flaw was found in Buildah in versions before 1.14.5. This flaw allows an attacker to trick a user into building a malicious container image hosted on an HTTP(s) server and then write files to the user's system anywhere that the user has permissions.

  • CVE-2020-8131HigFeb 24, 2020
    risk 0.00cvss 7.5epss 0.05

    Arbitrary filesystem write vulnerability in Yarn before 1.22.0 allows attackers to write to any path on the filesystem and potentially lead to arbitrary code execution by forcing the user to install a malicious package.

  • CVE-2020-8545HigFeb 3, 2020
    risk 0.00cvss 7.5epss 0.01

    Global.py in AIL framework 2.8 allows path traversal.

  • CVE-2020-5221MedJan 22, 2020
    risk 0.00cvss 6.5epss 0.01

    In uftpd before 2.11, it is possible for an unauthenticated user to perform a directory traversal attack using multiple different FTP commands and read and write to arbitrary locations on the filesystem due to the lack of a well-written chroot jail in compose_abspath(). This has…

  • CVE-2019-11246MedAug 29, 2019
    risk 0.00cvss 6.5epss 0.04

    The kubectl cp command allows copying files between containers and the user machine. To copy files from a container, Kubernetes runs tar inside the container to create a tar archive, copies it over the network, and kubectl unpacks it on the user’s machine. If the tar binary in…

  • CVE-2019-15520MedAug 23, 2019
    risk 0.00cvss 5.3epss 0.02

    comelz Quark before 2019-03-26 allows directory traversal to locations outside of the project directory.

  • CVE-2019-15519CriAug 23, 2019
    risk 0.00cvss 9.8epss 0.03

    Power-Response before 2019-02-02 allows directory traversal (up to the application's main directory) via a plugin.

  • CVE-2019-15518MedAug 23, 2019
    risk 0.00cvss 5.3epss 0.02

    Swoole before 4.2.13 allows directory traversal in swPort_http_static_handler.