VYPR

CWE-22

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')

BaseStableLikelihood: High

Description

The product uses external input to construct a pathname that is intended to identify a file or directory that is located underneath a restricted parent directory, but the product does not properly neutralize special elements within the pathname that can cause the pathname to resolve to a location that is outside of the restricted directory.

Hierarchy (View 1000)

Parents

Children

Related attack patterns (CAPEC)

CAPEC-126 · CAPEC-64 · CAPEC-76 · CAPEC-78 · CAPEC-79

CVEs mapped to this weakness (10,395)

page 70 of 520
  • CVE-2021-42643HigMay 17, 2022
    risk 0.57cvss 8.8epss 0.02

    cmseasy V7.7.5_20211012 is affected by an arbitrary file write vulnerability. Through this vulnerability, a PHP script file is written to the website server, and accessing this file can lead to a code execution vulnerability.

  • CVE-2022-26889HigMay 6, 2022
    risk 0.57cvss 8.8epss 0.01

    In Splunk Enterprise versions before 8.1.2, the uri path to load a relative resource within a web page is vulnerable to path traversal. It allows an attacker to potentially inject arbitrary content into the web page (e.g., HTML Injection, XSS) or bypass SPL safeguards for risky…

  • CVE-2022-24877CriMay 6, 2022
    risk 0.57cvss 9.9epss 0.01

    Flux is an open and extensible continuous delivery solution for Kubernetes. Path Traversal in the kustomize-controller via a malicious `kustomization.yaml` allows an attacker to expose sensitive data from the controller’s pod filesystem and possibly privilege escalation in…

  • CVE-2021-26629HigApr 26, 2022
    risk 0.57cvss 8.8epss 0.02

    A path traversal vulnerability in XPLATFORM's runtime archive function could lead to arbitrary file creation. When the .xzip archive file is decompressed, an arbitrary file can be d in the parent path by using the path traversal pattern ‘..\’.

  • CVE-2021-44519HigApr 19, 2022
    risk 0.57cvss 8.8epss 0.03

    In Citrix XenMobile Server through 10.12 RP9, there is an Authenticated Directory Traversal vulnerability, leading to remote code execution.

  • CVE-2022-29281HigApr 15, 2022
    risk 0.57cvss 8.8epss 0.02

    Notable before 1.9.0-beta.8 doesn't effectively prevent the opening of executable files when clicking on a link. There is improper validation of the file URI scheme. A hyperlink to an SMB share could lead to execution of an arbitrary program (or theft of NTLM credentials via an…

  • CVE-2022-26612CriApr 7, 2022
    risk 0.57cvss 9.8epss 0.04

    In Apache Hadoop, The unTar function uses unTarUsingJava function on Windows and the built-in tar utility on Unix and other OSes. As a result, a TAR entry may create a symlink under the expected extraction directory which points to an external directory. A subsequent TAR entry…

  • CVE-2021-46417HigApr 7, 2022
    risk 0.57cvss 7.5epss 0.60

    Insecure handling of a download function leads to disclosure of internal files due to path traversal with root privileges in Franklin Fueling Systems Colibri Controller Module 1.8.19.8580.

  • CVE-2022-23732HigApr 5, 2022
    risk 0.57cvss 8.8epss 0.02

    A path traversal vulnerability was identified in GitHub Enterprise Server management console that allowed the bypass of CSRF protections. This could potentially lead to privilege escalation. To exploit this vulnerability, an attacker would need to target a user that was actively…

  • CVE-2021-24962HigMar 28, 2022
    risk 0.57cvss 8.8epss 0.03

    The WordPress File Upload Free and Pro WordPress plugins before 4.16.3 allow users with a role as low as Contributor to perform path traversal via a shortcode argument, which can then be used to upload a PHP code disguised as an image inside the auto-loaded directory of the…

  • CVE-2022-25267HigMar 23, 2022
    risk 0.57cvss 8.8epss 0.01

    Passwork On-Premise Edition before 4.6.13 allows migration/uploadExportFile Directory Traversal (to upload files).

  • CVE-2022-22771HigMar 15, 2022
    risk 0.57cvss 8.8epss 0.02

    The Server component of TIBCO Software Inc.'s TIBCO JasperReports Library, TIBCO JasperReports Library for ActiveMatrix BPM, TIBCO JasperReports Server, TIBCO JasperReports Server for AWS Marketplace, TIBCO JasperReports Server for ActiveMatrix BPM, and TIBCO JasperReports…

  • CVE-2022-21808HigMar 11, 2022
    risk 0.57cvss 8.8epss 0.01

    Path traversal vulnerability exists in CAMS for HIS Server contained in the following Yokogawa Electric products: CENTUM CS 3000 versions from R3.08.10 to R3.09.00, CENTUM VP versions from R4.01.00 to R4.03.00, from R5.01.00 to R5.04.20, and from R6.01.00 to R6.08.00, Exaopc…

  • CVE-2021-3762CriMar 3, 2022
    risk 0.57cvss 9.8epss 0.05

    A directory traversal vulnerability was found in the ClairCore engine of Clair. An attacker can exploit this by supplying a crafted container image which, when scanned by Clair, allows for arbitrary file write on the filesystem, potentially allowing for remote code execution.

  • CVE-2022-24977CriFeb 14, 2022
    risk 0.57cvss 9.8epss 0.06

    ImpressCMS before 1.4.2 allows unauthenticated remote code execution via ...../// directory traversal in origName or imageName, leading to unsafe interaction with the CKEditor processImage.php script. The payload may be placed in PHP_SESSION_UPLOAD_PROGRESS when the PHP…

  • CVE-2021-22748HigFeb 11, 2022
    risk 0.57cvss 8.8epss 0.02

    A CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability exists that could allow a remote code execution when a file is saved. Affected Product: C-Bus Toolkit (V1.15.9 and prior), C-Gate Server (V2.11.7 and prior)

  • CVE-2022-0401CriFeb 1, 2022
    risk 0.57cvss 9.8epss 0.02

    Path Traversal in NPM w-zip prior to 1.0.12.

  • CVE-2021-23484CriJan 28, 2022
    risk 0.57cvss 9.8epss 0.02

    The package zip-local before 0.3.5 are vulnerable to Arbitrary File Write via Archive Extraction (Zip Slip) which can lead to an extraction of a crafted file outside the intended extraction directory.

  • CVE-2021-44737HigJan 20, 2022
    risk 0.57cvss 8.8epss 0.01

    PJL directory traversal vulnerability in Lexmark devices through 2021-12-07 that can be leveraged to overwrite internal configuration files.

  • CVE-2021-21879HigDec 22, 2021
    risk 0.57cvss 8.8epss 0.04

    A directory traversal vulnerability exists in the Web Manager File Upload functionality of Lantronix PremierWave 2050 8.9.0.0R4. A specially-crafted HTTP request can lead to arbitrary file overwrite. An attacker can make an authenticated HTTP request to trigger this…