VYPR

CWE-22

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')

BaseStableLikelihood: High

Description

The product uses external input to construct a pathname that is intended to identify a file or directory that is located underneath a restricted parent directory, but the product does not properly neutralize special elements within the pathname that can cause the pathname to resolve to a location that is outside of the restricted directory.

Hierarchy (View 1000)

Parents

Children

Related attack patterns (CAPEC)

CAPEC-126 · CAPEC-64 · CAPEC-76 · CAPEC-78 · CAPEC-79

CVEs mapped to this weakness (10,395)

page 67 of 520
  • CVE-2024-25386HigMar 1, 2024
    risk 0.57cvss 8.8epss 0.02

    Directory Traversal vulnerability in DICOM® Connectivity Framework by laurelbridge before v.2.7.6b allows a remote attacker to execute arbitrary code via the format_logfile.pl file.

  • CVE-2024-21891HigFeb 20, 2024
    risk 0.57cvss 8.8epss 0.01

    Node.js depends on multiple built-in utility functions to normalize paths provided to node:fs functions, which can be overwitten with user-defined implementations leading to filesystem permission model bypass through path traversal attack. This vulnerability affects all users…

  • CVE-2024-22514HigFeb 6, 2024
    risk 0.57cvss 8.8epss 0.01

    An issue discovered in iSpyConnect.com Agent DVR 5.1.6.0 allows attackers to run arbitrary files by restoring a crafted backup file.

  • CVE-2024-21852HigFeb 1, 2024
    risk 0.57cvss 8.8epss 0.01

    In Rapid Software LLC's Rapid SCADA versions prior to Version 5.8.4, an attacker can supply a malicious configuration file by utilizing a Zip Slip vulnerability in the unpacking routine to achieve remote code execution.

  • CVE-2024-23827CriJan 29, 2024
    risk 0.57cvss 9.8epss 0.01

    Nginx-UI is a web interface to manage Nginx configurations. The Import Certificate feature allows arbitrary write into the system. The feature does not check if the provided user input is a certification/key and allows to write into arbitrary paths in the system. It's possible…

  • CVE-2024-23768HigJan 22, 2024
    risk 0.57cvss 8.8epss 0.01

    Dremio before 24.3.1 allows path traversal. An authenticated user who has no privileges on certain folders (and the files and datasets in these folders) can access these folders, files, and datasets. To be successful, the user must have access to the source and at least one…

  • CVE-2021-24566HigJan 16, 2024
    risk 0.57cvss 8.8epss 0.01

    The WooCommerce Currency Switcher FOX WordPress plugin before 1.3.7 was vulnerable to LFI attacks via the "woocs" shortcode.

  • CVE-2023-5504HigJan 11, 2024
    risk 0.57cvss 8.7epss 0.01

    The BackWPup plugin for WordPress is vulnerable to Directory Traversal in versions up to, and including, 4.0.1 via the Log File Folder. This allows authenticated attackers to store backups in arbitrary folders on the server provided they can be written to by the server.…

  • CVE-2023-45722HigJan 3, 2024
    risk 0.57cvss 8.8epss 0.01

    HCL DRYiCE MyXalytics is impacted by path traversal arbitrary file read vulnerability because it uses external input to construct a pathname that is intended to identify a file or directory that is located underneath a restricted parent directory.  The product does not properly…

  • CVE-2023-6972CriDec 23, 2023
    risk 0.57cvss 9.8epss 0.01

    The Backup Migration plugin for WordPress is vulnerable to Path Traversal in all versions up to, and including, 1.3.9 via the 'content-backups' and 'content-name', 'content-manifest', or 'content-bmitmp' and 'content-identy' HTTP headers. This makes it possible for…

  • CVE-2023-49108HigDec 4, 2023
    risk 0.57cvss 8.8epss 0.01

    Path traversal vulnerability exists in RakRak Document Plus Ver.3.2.0.0 to Ver.6.4.0.7 (excluding Ver.6.1.1.3a). If this vulnerability is exploited, arbitrary files on the server may be obtained or deleted by a user of the product with specific privileges.

  • CVE-2023-46690HigNov 30, 2023
    risk 0.57cvss 8.8epss 0.02

    In Delta Electronics InfraSuite Device Master v.1.0.7, a vulnerability exists that allows an attacker to write to any file to any location of the filesystem, which could lead to remote code execution.

  • CVE-2018-16739HigOct 26, 2023
    risk 0.57cvss 8.8epss 0.01

    An issue was discovered on certain ABUS TVIP devices. Due to a path traversal in /opt/cgi/admin/filewrite, an attacker can write to files, and thus execute code arbitrarily with root privileges.

  • CVE-2023-37913CriOct 25, 2023
    risk 0.57cvss 9.9epss 0.01

    XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. Starting in version 3.5-milestone-1 and prior to versions 14.10.8 and 15.3-rc-1, triggering the office converter with a specially crafted file name allows writing the…

  • CVE-2023-26578HigOct 25, 2023
    risk 0.57cvss 8.8epss 0.01

    Arbitrary file upload to web root in the IDAttend’s IDWeb application 3.1.013 allows authenticated attackers to upload dangerous files to web root such as ASP or ASPX, gaining command execution on the affected server.

  • CVE-2022-38484HigOct 25, 2023
    risk 0.57cvss 8.8epss 0.02

    An arbitrary file upload and directory traversal vulnerability exist in the file upload functionality of the System Setup menu in AgeVolt Portal prior to version 0.1. A remote authenticated attacker could leverage this vulnerability to upload files to any location on the target…

  • CVE-2023-4274HigOct 20, 2023
    risk 0.57cvss 8.7epss 0.01

    The Migration, Backup, Staging – WPvivid plugin for WordPress is vulnerable to Directory Traversal in versions up to, and including, 0.9.89. This allows authenticated attackers with administrative privileges to delete the contents of arbitrary directories on the server, which…

  • CVE-2023-35187HigOct 19, 2023
    risk 0.57cvss 8.8epss 0.03

    The SolarWinds Access Rights Manager was susceptible to a Directory Traversal Remote Code Vulnerability. This vulnerability allows an unauthenticated user to achieve the Remote Code Execution.

  • CVE-2023-45352HigOct 9, 2023
    risk 0.57cvss 8.8epss 0.01

    Atos Unify OpenScape Common Management Portal V10 before V10 R4.17.0 and V10 R5.1.0 allows an authenticated attacker to execute arbitrary code on the operating system via a Common Management Portal web interface Path traversal vulnerability allowing write access outside the…

  • CVE-2022-35908HigSep 29, 2023
    risk 0.57cvss 8.8epss 0.01

    Cambium Enterprise Wi-Fi System Software before 6.4.2 does not sanitize the ping host argument in device-agent.