VYPR

CWE-22

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')

BaseStableLikelihood: High

Description

The product uses external input to construct a pathname that is intended to identify a file or directory that is located underneath a restricted parent directory, but the product does not properly neutralize special elements within the pathname that can cause the pathname to resolve to a location that is outside of the restricted directory.

Hierarchy (View 1000)

Parents

Children

Related attack patterns (CAPEC)

CAPEC-126 · CAPEC-64 · CAPEC-76 · CAPEC-78 · CAPEC-79

CVEs mapped to this weakness (10,395)

page 66 of 520
  • CVE-2024-32680HigMay 17, 2024
    risk 0.57cvss 8.8epss 0.01

    Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal'), Improper Control of Generation of Code ('Code Injection') vulnerability in PluginUS HUSKY – Products Filter for WooCommerce (formerly WOOF) allows Using Malicious Files, Code Inclusion.This issue…

  • CVE-2022-0369HigMay 7, 2024
    risk 0.57cvss 8.8epss 0.02

    Triangle MicroWorks SCADA Data Gateway Restore Workspace Directory Traversal Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Triangle MicroWorks SCADA Data Gateway. Although authentication is…

  • CVE-2023-51603HigMay 3, 2024
    risk 0.57cvss 8.8epss 0.02

    Honeywell Saia PG5 Controls Suite CAB File Parsing Directory Traversal Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Honeywell Saia PG5 Controls Suite. User interaction is required to…

  • CVE-2023-51599HigMay 3, 2024
    risk 0.57cvss 8.8epss 0.02

    Honeywell Saia PG5 Controls Suite Directory Traversal Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Honeywell Saia PG5 Controls Suite. User interaction is required to exploit this…

  • CVE-2023-50233HigMay 3, 2024
    risk 0.57cvss 8.8epss 0.02

    Inductive Automation Ignition getJavaExecutable Directory Traversal Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Inductive Automation Ignition. User interaction is required to exploit this…

  • CVE-2023-42130HigMay 3, 2024
    risk 0.57cvss 8.8epss 0.02

    A10 Thunder ADC FileMgmtExport Directory Traversal Arbitrary File Read and Deletion Vulnerability. This vulnerability allows remote attackers to read and delete arbitrary files on affected installations of A10 Thunder ADC. Authentication is required to exploit this…

  • CVE-2024-34033HigMay 3, 2024
    risk 0.57cvss 8.8epss 0.01

    Delta Electronics DIAEnergie has insufficient input validation which makes it possible to perform a path traversal attack and write outside of the intended directory. If a file name is specified that already exists on the file system, then the original file will be overwritten.…

  • CVE-2024-2434HigApr 25, 2024
    risk 0.57cvss 8.5epss 0.23

    An issue has been discovered in GitLab affecting all versions of GitLab CE/EE 16.9 prior to 16.9.6, 16.10 prior to 16.10.4, and 16.11 prior to 16.11.1 where path traversal could lead to DoS and restricted file read.

  • CVE-2024-28976HigApr 24, 2024
    risk 0.57cvss 8.8epss 0.00

    Dell Repository Manager, versions prior to 3.4.5, contains a Path Traversal vulnerability in API module. A local attacker with low privileges could potentially exploit this vulnerability to gain unauthorized write access to the files stored on the server filesystem with the…

  • CVE-2024-32258HigApr 23, 2024
    risk 0.57cvss 8.8epss 0.02

    The network server of fceux 2.7.0 has a path traversal vulnerability, allowing attackers to overwrite any files on the server without authentication by fake ROM.

  • CVE-2024-27976HigApr 19, 2024
    risk 0.57cvss 8.8epss 0.03

    A Path Traversal vulnerability in web component of Ivanti Avalanche before 6.4.3 allows a remote authenticated attacker to execute arbitrary commands as SYSTEM.

  • CVE-2024-25000HigApr 19, 2024
    risk 0.57cvss 8.8epss 0.03

    A Path Traversal vulnerability in web component of Ivanti Avalanche before 6.4.3 allows a remote authenticated attacker to execute arbitrary commands as SYSTEM.

  • CVE-2024-24999HigApr 19, 2024
    risk 0.57cvss 8.8epss 0.03

    A Path Traversal vulnerability in web component of Ivanti Avalanche before 6.4.3 allows a remote authenticated attacker to execute arbitrary commands as SYSTEM.

  • CVE-2024-24997HigApr 19, 2024
    risk 0.57cvss 8.8epss 0.03

    A Path Traversal vulnerability in web component of Ivanti Avalanche before 6.4.3 allows a remote authenticated attacker to execute arbitrary commands as SYSTEM.

  • CVE-2024-1961HigApr 16, 2024
    risk 0.57cvss 8.8epss 0.01

    vertaai/modeldb is vulnerable to a path traversal attack due to improper sanitization of user-supplied file paths in its file upload functionality. Attackers can exploit this vulnerability to write arbitrary files anywhere in the file system by manipulating the 'artifact_path'…

  • CVE-2024-29053HigApr 9, 2024
    risk 0.57cvss 8.8epss 0.03

    Microsoft Defender for IoT Remote Code Execution Vulnerability

  • CVE-2024-21677HigMar 19, 2024
    risk 0.57cvss 8.8epss 0.01

    This High severity Path Traversal vulnerability was introduced in version 6.13.0 of Confluence Data Center. This Path Traversal vulnerability, with a CVSS Score of 8.3, allows an unauthenticated attacker to exploit an undefinable vulnerability which has high impact to…

  • CVE-2024-27771HigMar 18, 2024
    risk 0.57cvss 8.8epss 0.01

    Unitronics Unistream Unilogic – Versions prior to 1.35.227 - CWE-22: 'Path Traversal' may allow RCE

  • CVE-2024-27770HigMar 18, 2024
    risk 0.57cvss 8.8epss 0.01

    Unitronics Unistream Unilogic – Versions prior to 1.35.227 - CWE-23: Relative Path Traversal

  • CVE-2024-27102CriMar 13, 2024
    risk 0.57cvss 9.9epss 0.01

    Wings is the server control plane for Pterodactyl Panel. This vulnerability impacts anyone running the affected versions of Wings. The vulnerability can potentially be used to access files and directories on the host system. The full scope of impact is exactly unknown, but…