VYPR

CWE-22

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')

BaseStableLikelihood: High

Description

The product uses external input to construct a pathname that is intended to identify a file or directory that is located underneath a restricted parent directory, but the product does not properly neutralize special elements within the pathname that can cause the pathname to resolve to a location that is outside of the restricted directory.

Hierarchy (View 1000)

Parents

Children

Related attack patterns (CAPEC)

CAPEC-126 · CAPEC-64 · CAPEC-76 · CAPEC-78 · CAPEC-79

CVEs mapped to this weakness (10,395)

page 49 of 520
  • CVE-2021-20651CriFeb 12, 2021
    risk 0.59cvss 9.1epss 0.02

    Directory traversal vulnerability in ELECOM File Manager all versions allows remote attackers to create an arbitrary file or overwrite an existing file in a directory which can be accessed with the application privileges via unspecified vectors.

  • CVE-2020-36193HigKEVJan 18, 2021
    risk 0.59cvss 7.5epss 0.71

    Tar.php in Archive_Tar through 1.4.11 allows write operations with Directory Traversal due to inadequate checking of symbolic links, a related issue to CVE-2020-28948.

  • CVE-2018-19945CriDec 31, 2020
    risk 0.59cvss 9.1epss 0.01

    A vulnerability has been reported to affect earlier QNAP devices running QTS 4.3.4 to 4.3.6. Caused by improper limitations of a pathname to a restricted directory, this vulnerability allows for renaming arbitrary files on the target system, if exploited. QNAP have already fixed…

  • CVE-2020-26837CriDec 9, 2020
    risk 0.59cvss 9.1epss 0.02

    SAP Solution Manager 7.2 (User Experience Monitoring), version - 7.2, allows an authenticated user to upload a malicious script that can exploit an existing path traversal vulnerability to compromise confidentiality exposing elements of the file system, partially compromise…

  • CVE-2020-9920CriOct 22, 2020
    risk 0.59cvss 9.1epss 0.02

    A path handling issue was addressed with improved validation. This issue is fixed in iOS 13.6 and iPadOS 13.6, macOS Catalina 10.15.6, watchOS 6.2.8. A malicious mail server may overwrite arbitrary mail files.

  • CVE-2020-13347CriOct 7, 2020
    risk 0.59cvss 9.1epss 0.02

    A command injection vulnerability was discovered in Gitlab runner versions prior to 13.2.4, 13.3.2 and 13.4.1. When the runner is configured on a Windows system with a docker executor, which allows the attacker to run arbitrary commands on Windows host, via DOCKER_AUTH_CONFIG…

  • CVE-2020-18191CriOct 2, 2020
    risk 0.59cvss 9.1epss 0.02

    GetSimpleCMS-3.3.15 is affected by directory traversal. Remote attackers are able to delete arbitrary files via /GetSimpleCMS-3.3.15/admin/log.php

  • CVE-2020-18190CriOct 2, 2020
    risk 0.59cvss 9.1epss 0.02

    Bludit v3.8.1 is affected by directory traversal. Remote attackers are able to delete arbitrary files via /admin/ajax/upload-profile-picture.

  • CVE-2020-13376CriAug 7, 2020
    risk 0.59cvss 9.0epss 0.04

    SecurEnvoy SecurMail 9.3.503 allows attackers to upload executable files and achieve OS command execution via a crafted SecurEnvoyReply cookie.

  • CVE-2019-20851CriJun 19, 2020
    risk 0.59cvss 9.1epss 0.01

    An issue was discovered in Mattermost Mobile Apps before 1.26.0. An attacker can use directory traversal with the Video Preview feature to overwrite arbitrary files on a device.

  • CVE-2020-8604HigMay 27, 2020
    risk 0.59cvss 7.5epss 0.90

    A vulnerability in Trend Micro InterScan Web Security Virtual Appliance 6.5 may allow remote attackers to disclose sensitive informatoin on affected installations.

  • CVE-2020-11431CriMay 7, 2020
    risk 0.59cvss 9.1epss 0.02

    The documentation component in i-net Clear Reports 16.0 to 19.2, HelpDesk 8.0 to 8.3, and PDFC 4.3 to 6.2 allows a remote unauthenticated attacker to read arbitrary system files and directories on the target server via Directory Traversal.

  • CVE-2020-10634CriMay 5, 2020
    risk 0.59cvss 9.1epss 0.01

    SAE IT-systems FW-50 Remote Telemetry Unit (RTU). A specially crafted request could allow an attacker to view the file structure of the affected device and access files that should be inaccessible.

  • CVE-2020-5554CriMar 25, 2020
    risk 0.59cvss 9.1epss 0.02

    Directory traversal vulnerability in Shihonkanri Plus GOOUT Ver1.5.8 and Ver2.2.10 allows remote attackers to read and write arbitrary files via unspecified vectors.

  • CVE-2020-6203CriMar 10, 2020
    risk 0.59cvss 9.1epss 0.02

    SAP NetWeaver UDDI Server (Services Registry), versions- 7.10, 7.11, 7.20, 7.30, 7.31, 7.40, 7.50; allows an attacker to exploit insufficient validation of path information provided by users, thus characters representing 'traverse to parent directory' are passed through to the…

  • CVE-2019-15855CriJan 17, 2020
    risk 0.59cvss 9.1epss 0.02

    An issue was discovered in Maarch RM before 2.5. A path traversal vulnerability allows an unauthenticated remote attacker to overwrite any files with a crafted POST request if the default installation procedure was followed. This results in a permanent Denial of Service.

  • CVE-2019-19374CriDec 11, 2019
    risk 0.59cvss 9.1epss 0.03

    An issue was discovered in core/assets/form/form_question_types/form_question_type_file_upload/form_question_type_file_upload.inc in Squiz Matrix CMS 5.5.0 prior to 5.5.0.3, 5.5.1 prior to 5.5.1.8, 5.5.2 prior to 5.5.2.4, and 5.5.3 prior to 5.5.3.3 where a user can delete…

  • CVE-2019-19683CriDec 9, 2019
    risk 0.59cvss 9.1epss 0.02

    RoxyFileman, as shipped with nopCommerce v4.2.0, is vulnerable to ../ path traversal via d or f to Admin/RoxyFileman/ProcessRequest because of Libraries/Nop.Services/Media/RoxyFileman/FileRoxyFilemanService.cs.

  • CVE-2019-14914CriSep 20, 2019
    risk 0.59cvss 9.1epss 0.02

    An issue was discovered in PRiSE adAS 1.7.0. The path is not properly escaped in the medatadata_del method, leading to an arbitrary file read and deletion via Directory Traversal.

  • CVE-2014-10390CriAug 22, 2019
    risk 0.59cvss 9.1epss 0.03

    The wp-support-plus-responsive-ticket-system plugin before 4.2 for WordPress has directory traversal.