VYPR

CWE-22

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')

BaseStableLikelihood: High

Description

The product uses external input to construct a pathname that is intended to identify a file or directory that is located underneath a restricted parent directory, but the product does not properly neutralize special elements within the pathname that can cause the pathname to resolve to a location that is outside of the restricted directory.

Hierarchy (View 1000)

Parents

Children

Related attack patterns (CAPEC)

CAPEC-126 · CAPEC-64 · CAPEC-76 · CAPEC-78 · CAPEC-79

CVEs mapped to this weakness (10,395)

page 69 of 520
  • CVE-2023-23314HigJan 23, 2023
    risk 0.57cvss 8.8epss 0.01

    An arbitrary file upload vulnerability in the /api/upload component of zdir v3.2.0 allows attackers to execute arbitrary code via a crafted .ssh file.

  • CVE-2022-45299CriJan 13, 2023
    risk 0.57cvss 9.8epss 0.01

    An issue in the IpFile argument of rust-lang webbrowser-rs v0.8.2 allows attackers to access arbitrary files via supplying a crafted URL.

  • CVE-2022-42136HigJan 13, 2023
    risk 0.57cvss 8.8epss 0.01

    Authenticated mail users, under specific circumstances, could add files with unsanitized content in public folders where the IIS user had permission to access. That action, could lead an attacker to store arbitrary code on that files and execute RCE commands.

  • CVE-2022-46306HigJan 3, 2023
    risk 0.57cvss 8.8epss 0.01

    ChangingTec ServiSign component has a path traversal vulnerability due to insufficient filtering for special characters in the DLL file path. An unauthenticated remote attacker can host a malicious website for the component user to access, which triggers the component to load…

  • CVE-2022-45969CriDec 15, 2022
    risk 0.57cvss 9.8epss 0.01

    Alist v3.4.0 is vulnerable to Directory Traversal,

  • CVE-2022-46256HigDec 14, 2022
    risk 0.57cvss 8.8epss 0.02

    A path traversal vulnerability was identified in GitHub Enterprise Server that allowed remote code execution when building a GitHub Pages site. To exploit this vulnerability, an attacker would need permission to create and build a GitHub Pages site on the instance. This…

  • CVE-2022-45829HigDec 6, 2022
    risk 0.57cvss 8.7epss 0.01

    Auth. Path Traversal vulnerability in Easy WP SMTP plugin <= 1.5.1 at WordPress.

  • CVE-2022-39345CriOct 25, 2022
    risk 0.57cvss 9.8epss 0.01

    Gin-vue-admin is a backstage management system based on vue and gin, which separates the front and rear of the full stack. Gin-vue-admin prior to 2.5.4 is vulnerable to path traversal, which leads to file upload vulnerabilities. Version 2.5.4 contains a patch for this issue.…

  • CVE-2022-23770HigOct 17, 2022
    risk 0.57cvss 8.8epss 0.01

    This vulnerability could allow a remote attacker to execute remote commands with improper validation of parameters of certain API constructors. Remote attackers could use this vulnerability to execute malicious commands such as directory traversal.

  • CVE-2022-34426HigOct 11, 2022
    risk 0.57cvss 8.8epss 0.02

    Dell Container Storage Modules 1.2 contains an Improper Limitation of a Pathname to a Restricted Directory in goiscsi and gobrick libraries which could lead to OS command injection. A remote unauthenticated attacker could exploit this vulnerability leading to unintentional…

  • CVE-2022-23767HigSep 19, 2022
    risk 0.57cvss 8.8epss 0.01

    This vulnerability of SecureGate is SQL-Injection using login without password. A path traversal vulnerability is also identified during file transfer. An attacker can take advantage of these vulnerabilities to perform various attacks such as obtaining privileges and executing…

  • CVE-2022-1798HigSep 15, 2022
    risk 0.57cvss 8.7epss 0.00

    A path traversal vulnerability in KubeVirt versions up to 0.56 (and 0.55.1) on all platforms allows a user able to configure the kubevirt to read arbitrary files on the host filesystem which are publicly readable or which are readable for UID 107 or GID 107. /proc/self/<> is not…

  • CVE-2022-34375HigAug 30, 2022
    risk 0.57cvss 8.8epss 0.01

    Dell Container Storage Modules 1.2 contains a path traversal vulnerability in goiscsi and gobrick libraries. A remote authenticated malicious user with low privileges could exploit this vulnerability leading to unintentional access to path outside of restricted directory.

  • CVE-2022-32427HigAug 25, 2022
    risk 0.57cvss 8.8epss 0.02

    PrinterLogic Windows Client through 25.0.0.676 allows attackers to execute directory traversal. Authenticated users with prior knowledge of the driver filename could exploit this to escalate privileges or distribute malicious content. This issue has been resolved in PrinterLogic…

  • CVE-2022-2557HigAug 22, 2022
    risk 0.57cvss 8.8epss 0.02

    The Team WordPress plugin before 4.1.2 contains a file which could allow any authenticated users to download arbitrary files from the server via a path traversal vector. Furthermore, the file will also be deleted after its content is returned to the user

  • CVE-2022-2184HigAug 1, 2022
    risk 0.57cvss 8.8epss 0.01

    The CAPTCHA 4WP WordPress plugin before 7.1.0 lets user input reach a sensitive require_once call in one of its admin-side templates. This can be abused by attackers, via a Cross-Site Request Forgery attack to run arbitrary code on the server.

  • CVE-2022-22685HigJul 28, 2022
    risk 0.57cvss 8.7epss 0.01

    Improper limitation of a pathname to a restricted directory ('Path Traversal') vulnerability in webapi component in Synology WebDAV Server before 2.4.0-0062 allows remote authenticated users to delete arbitrary files via unspecified vectors.

  • CVE-2022-31836CriJul 5, 2022
    risk 0.57cvss 9.8epss 0.02

    The leafInfo.match() function in Beego v2.0.3 and below uses path.join() to deal with wildcardvalues which can lead to cross directory risk.

  • CVE-2022-31395HigJun 23, 2022
    risk 0.57cvss 8.8epss 0.03

    Algo Communication Products Ltd. 8373 IP Zone Paging Adapter Firmware 1.7.6 allows attackers to perform a directory traversal via a web request sent to /fm-data.lua.

  • CVE-2022-1657HigJun 13, 2022
    risk 0.57cvss 8.8epss 0.02

    Vulnerable versions of the Jupiter (<= 6.10.1) and JupiterX (<= 2.0.6) Themes allow logged-in users, including subscriber-level users, to perform Path Traversal and Local File inclusion. In the JupiterX theme, the jupiterx_cp_load_pane_action AJAX action present in the…