VYPR

CWE-22

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')

BaseStableLikelihood: High

Description

The product uses external input to construct a pathname that is intended to identify a file or directory that is located underneath a restricted parent directory, but the product does not properly neutralize special elements within the pathname that can cause the pathname to resolve to a location that is outside of the restricted directory.

Hierarchy (View 1000)

Parents

Children

Related attack patterns (CAPEC)

CAPEC-126 · CAPEC-64 · CAPEC-76 · CAPEC-78 · CAPEC-79

CVEs mapped to this weakness (10,395)

page 6 of 520
  • CVE-2022-29517CriDec 15, 2022
    risk 0.69cvss 9.9epss 0.58

    A directory traversal vulnerability exists in the HelpdeskActions.aspx edittemplate functionality of Lansweeper lansweeper 10.1.1.0. A specially-crafted HTTP request can lead to arbitrary file upload. An attacker can send an HTTP request to trigger this vulnerability.

  • CVE-2022-30547CriAug 22, 2022
    risk 0.69cvss 9.9epss 0.64

    A directory traversal vulnerability exists in the unzipDirectory functionality of WWBN AVideo 11.6 and dev master commit 3f7c0364. A specially-crafted HTTP request can lead to arbitrary command execution. An attacker can send an HTTP request to trigger this vulnerability.

  • CVE-2021-20034CriSep 27, 2021
    risk 0.69cvss 9.1epss 0.81

    An improper access control vulnerability in SMA100 allows a remote unauthenticated attacker to bypass the path traversal checks and delete an arbitrary file potentially resulting in a reboot to factory default settings.

  • CVE-2020-11819CriApr 16, 2020
    risk 0.69cvss 9.8epss 0.27

    In Rukovoditel 2.5.2, an attacker may inject an arbitrary .php file location instead of a language file and thus achieve command execution.

  • CVE-2014-4650CriFeb 20, 2020
    risk 0.69cvss 9.8epss 0.25

    The CGIHTTPServer module in Python 2.7.5 and 3.3.4 does not properly handle URLs in which URL encoding is used for path separators, which allows remote attackers to read script source code or conduct directory traversal attacks and execute unintended code via a crafted character…

  • CVE-2013-6225CriJan 13, 2020
    risk 0.69cvss 9.8epss 0.27

    LiveZilla 5.0.1.4 has a Remote Code Execution vulnerability

  • CVE-2019-6714CriMar 21, 2019
    risk 0.69cvss 9.8epss 0.32

    An issue was discovered in BlogEngine.NET through 3.3.6.0. A path traversal and Local File Inclusion vulnerability in PostList.ascx.cs can cause unauthenticated users to load a PostView.ascx component from a potentially untrusted location on the local filesystem. This is…

  • CVE-2018-7300CriFeb 22, 2018
    risk 0.69cvss 9.8epss 0.31

    Directory Traversal / Arbitrary File Write / Remote Code Execution in the User.setLanguage method in eQ-3 AG Homematic CCU2 2.29.2 and earlier allows remote attackers to write arbitrary files to the device's filesystem. This vulnerability can be exploited by unauthenticated…

  • CVE-2018-5997CriJan 25, 2018
    risk 0.69cvss 9.8epss 0.24

    An issue was discovered in the HTTP Server in RAVPower Filehub 2.000.056. Due to an unrestricted upload feature and a path traversal vulnerability, it is possible to upload a file on a filesystem with root privileges: this will lead to remote code execution as root.

  • CVE-2017-1000002CriJul 17, 2017
    risk 0.69cvss 9.8epss 0.31

    ATutor versions 2.2.1 and earlier are vulnerable to a directory traversal and file extension check bypass in the Course component resulting in code execution. ATutor versions 2.2.1 and earlier are vulnerable to a directory traversal vulnerability in the Course Icon component…

  • CVE-2025-1661CriMar 11, 2025
    risk 0.68cvss 9.8epss 0.56

    The HUSKY – Products Filter Professional for WooCommerce plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 1.3.6.5 via the 'template' parameter of the woof_text_search AJAX action. This makes it possible for unauthenticated…

  • CVE-2024-46909CriDec 2, 2024
    risk 0.68cvss 9.8epss 0.49

    In WhatsUp Gold versions released before 2024.0.1, a remote unauthenticated attacker could leverage this vulnerability to execute code in the context of the service account.

  • CVE-2024-53676CriNov 27, 2024
    risk 0.68cvss 9.8epss 0.56

    A directory traversal vulnerability in Hewlett Packard Enterprise Insight Remote Support may allow remote code execution.

  • CVE-2023-6989CriFeb 5, 2024
    risk 0.68cvss 9.8epss 0.57

    The Shield Security – Smart Bot Blocking & Intrusion Prevention Security plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 18.5.9 via the render_action_template parameter. This makes it possible for unauthenticated attacker to…

  • CVE-2023-6623CriJan 15, 2024
    risk 0.68cvss 9.8epss 0.51

    The Essential Blocks WordPress plugin before 4.4.3 does not prevent unauthenticated attackers from overwriting local variables when rendering templates over the REST API, which may lead to Local File Inclusion attacks.

  • CVE-2023-38950HigKEVAug 3, 2023
    risk 0.68cvss 7.5epss 0.85

    A path traversal vulnerability in the iclock API of ZKTeco BioTime v8.5.5 allows unauthenticated attackers to read arbitrary files via supplying a crafted payload. This vulnerability was fixed in version 9.0.120240617.19506 of ZKBioTime.

  • CVE-2023-26802CriMar 26, 2023
    risk 0.68cvss 9.8epss 0.49

    An issue in the component /network_config/nsg_masq.cgi of DCN (Digital China Networks) DCBI-Netlog-LAB v1.0 allows attackers to bypass authentication and execute arbitrary commands via a crafted request.

  • CVE-2023-27855CriMar 22, 2023
    risk 0.68cvss 9.8epss 0.13

    In affected versions, a path traversal exists when processing a message in Rockwell Automation's ThinManager ThinServer. An unauthenticated remote attacker could potentially exploit this vulnerability to upload arbitrary files to any directory on the disk drive where…

  • CVE-2022-48323CriFeb 13, 2023
    risk 0.68cvss 9.8epss 0.57

    Sunlogin Sunflower Simplified (aka Sunflower Simple and Personal) 1.0.1.43315 is vulnerable to a path traversal issue. A remote and unauthenticated attacker can execute arbitrary programs on the victim host by sending a crafted HTTP request, as demonstrated by /check?cmd=ping../…

  • CVE-2022-0679CriMar 28, 2022
    risk 0.68cvss 9.8epss 0.48

    The Narnoo Distributor WordPress plugin through 2.5.1 fails to validate and sanitize the lib_path parameter before it is passed into a call to require() via the narnoo_distributor_lib_request AJAX action (available to both unauthenticated and authenticated users) which results…