VYPR

CWE-22

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')

BaseStableLikelihood: High

Description

The product uses external input to construct a pathname that is intended to identify a file or directory that is located underneath a restricted parent directory, but the product does not properly neutralize special elements within the pathname that can cause the pathname to resolve to a location that is outside of the restricted directory.

Hierarchy (View 1000)

Parents

Children

Related attack patterns (CAPEC)

CAPEC-126 · CAPEC-64 · CAPEC-76 · CAPEC-78 · CAPEC-79

CVEs mapped to this weakness (10,395)

page 71 of 520
  • CVE-2021-45418HigDec 22, 2021
    risk 0.57cvss 8.8epss 0.02

    Certain Starcharge products are vulnerable to Directory Traversal via main.cgi. The affected products include: Nova 360 Cabinet <=1.3.0.0.6 - Fixed: 1.3.0.0.9 and Titan 180 Premium <=1.3.0.0.7b102 - Fixed: Beta1.3.0.1.0.

  • CVE-2021-43176HigDec 7, 2021
    risk 0.57cvss 8.8epss 0.01

    The GOautodial API prior to commit 3c3a979 made on October 13th, 2021 takes a user-supplied “action” parameter and appends a .php file extension to locate and load the correct PHP file to implement the API call. Vulnerable versions of GOautodial do not sanitize the user…

  • CVE-2021-43676CriDec 3, 2021
    risk 0.57cvss 9.8epss 0.01

    matyhtf framework v3.0.5 is affected by a path manipulation vulnerability in Smarty.class.php.

  • CVE-2021-21692CriNov 4, 2021
    risk 0.57cvss 9.8epss 0.02

    FilePath#renameTo and FilePath#moveAllChildrenTo in Jenkins 2.318 and earlier, LTS 2.303.2 and earlier only check 'read' agent-to-controller access permission on the source path, instead of 'delete'.

  • CVE-2021-21690CriNov 4, 2021
    risk 0.57cvss 9.8epss 0.03

    Agent processes are able to completely bypass file path filtering by wrapping the file operation in an agent file path in Jenkins 2.318 and earlier, LTS 2.303.2 and earlier.

  • CVE-2021-31385HigOct 19, 2021
    risk 0.57cvss 8.8epss 0.01

    An Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in J-Web of Juniper Networks Junos OS allows any low-privileged authenticated attacker to elevate their privileges to root. This issue affects: Juniper Networks Junos OS 12.3 versions…

  • CVE-2021-38346HigOct 14, 2021
    risk 0.57cvss 8.8epss 0.02

    The Brizy Page Builder plugin <= 2.3.11 for WordPress allowed authenticated users to upload executable files to a location of their choice using the brizy_create_block_screenshot AJAX action. The file would be named using the id parameter, which could be prepended with "../" to…

  • CVE-2021-40097HigSep 27, 2021
    risk 0.57cvss 8.8epss 0.03

    An issue was discovered in Concrete CMS through 8.5.5. Authenticated path traversal leads to to remote code execution via uploaded PHP code, related to the bFilename parameter.

  • CVE-2021-39316HigAug 31, 2021
    risk 0.57cvss 7.5epss 0.66

    The Zoomsounds plugin <= 6.45 for WordPress allows arbitrary files, including sensitive configuration files such as wp-config.php, to be downloaded via the `dzsap_download` action using directory traversal in the `link` parameter.

  • CVE-2021-26086MedKEVAug 16, 2021
    risk 0.57cvss 5.3epss 1.00

    Affected versions of Atlassian Jira Server and Data Center allow remote attackers to read particular files via a path traversal vulnerability in the /WEB-INF/web.xml endpoint. The affected versions are before version 8.5.14, from version 8.6.0 before 8.13.6, and from version…

  • CVE-2021-38197CriAug 8, 2021
    risk 0.57cvss 9.8epss 0.02

    unarr.go in go-unarr (aka Go bindings for unarr) 0.1.1 allows Directory Traversal via ../ in a pathname within a TAR archive.

  • CVE-2021-37444HigJul 25, 2021
    risk 0.57cvss 8.8epss 0.02

    NCH IVM Attendant v5.12 and earlier suffers from a directory traversal weakness upon uploading plugins in a ZIP archive. This can lead to code execution if a ZIP element's pathname is set to a Windows startup folder, a file for the inbuilt Out-Going Message function, or a file…

  • CVE-2021-37441HigJul 25, 2021
    risk 0.57cvss 8.8epss 0.01

    NCH Axon PBX v2.22 and earlier allows path traversal for file deletion via the logdelete?file=/.. substring.

  • CVE-2021-24013HigJul 12, 2021
    risk 0.57cvss 8.8epss 0.01

    Multiple Path traversal vulnerabilities in the Webmail of FortiMail before 6.4.4 may allow a regular user to obtain unauthorized access to files and data via specifically crafted web requests.

  • CVE-2021-20517HigJun 7, 2021
    risk 0.57cvss 8.8epss 0.02

    IBM WebSphere Application Server Network Deployment 8.5 and 9.0 could allow a remote authenticated attacker to traverse directories. An attacker could send a specially-crafted URL request containing "dot dot" sequences (/../) to read and delete arbitrary files on the system. IBM…

  • CVE-2021-28798HigMay 21, 2021
    risk 0.57cvss 8.8epss 0.01

    A relative path traversal vulnerability has been reported to affect QNAP NAS running QTS and QuTS hero. If exploited, this vulnerability allows attackers to modify files that impact system integrity. QNAP have already fixed this vulnerability in the following versions: QTS…

  • CVE-2020-29134HigMar 5, 2021
    risk 0.57cvss 8.6epss 0.27

    The TOTVS Fluig platform allows path traversal through the parameter "file = .. /" encoded in base64. This affects all versions Fluig Lake 1.7.0, Fluig 1.6.5 and Fluig 1.6.4

  • CVE-2020-29494HigJan 14, 2021
    risk 0.57cvss 8.7epss 0.02

    Dell EMC Avamar Server, versions 19.1, 19.2, 19.3, contain a Path Traversal Vulnerability in PDM. A remote user could potentially exploit this vulnerability, to gain unauthorized write access to the arbitrary files stored on the server filesystem, causing deletion of arbitrary…

  • CVE-2020-25617HigDec 16, 2020
    risk 0.57cvss 8.8epss 0.03

    An issue was discovered in SolarWinds N-Central 12.3.0.670. The AdvancedScripts HTTP endpoint allows Relative Path Traversal by an authenticated user of the N-Central Administration Console (NAC), leading to execution of OS commands as root.

  • CVE-2020-25074CriNov 10, 2020
    risk 0.57cvss 9.8epss 0.07

    The cache action in action/cache.py in MoinMoin through 1.9.10 allows directory traversal through a crafted HTTP request. An attacker who can upload attachments to the wiki can use this to achieve remote code execution.