CWE-22
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
Description
The product uses external input to construct a pathname that is intended to identify a file or directory that is located underneath a restricted parent directory, but the product does not properly neutralize special elements within the pathname that can cause the pathname to resolve to a location that is outside of the restricted directory.
Hierarchy (View 1000)
Related attack patterns (CAPEC)
CAPEC-126 · CAPEC-64 · CAPEC-76 · CAPEC-78 · CAPEC-79
CVEs mapped to this weakness (10,395)
page 73 of 520| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2019-18871 | Hig | 0.57 | 8.8 | 0.03 | May 7, 2020 | A path traversal in debug.php accessed via default.php in Blaauw Remote Kiln Control through v3.00r4 allows an authenticated attacker to upload arbitrary files, leading to arbitrary remote code execution. | ||
| CVE-2020-11652 | Med | 0.57 | 6.5 | 0.86 | KEV | Apr 30, 2020 | An issue was discovered in SaltStack Salt before 2019.2.4 and 3000 before 3000.2. The salt-master process ClearFuncs class allows access to some methods that improperly sanitize paths. These methods allow arbitrary directory access to authenticated users. | |
| CVE-2020-12265 | Cri | 0.57 | 9.8 | 0.02 | Apr 26, 2020 | The decompress package before 4.2.1 for Node.js is vulnerable to Arbitrary File Write via ../ in an archive member, when a symlink is used, because of Directory Traversal. | ||
| CVE-2020-4272 | Hig | 0.57 | 8.8 | 0.03 | Apr 15, 2020 | IBM QRadar 7.3.0 to 7.3.3 Patch 2 could allow a remote attacker to include arbitrary files. A remote attacker could send a specially-crafted request specify a malicious file from a remote system, which could allow the attacker to execute arbitrary code on the vulnerable server.… | ||
| CVE-2020-6225 | Hig | 0.57 | 8.8 | 0.01 | Apr 14, 2020 | SAP NetWeaver (Knowledge Management), versions (KMC-CM - 7.00, 7.01, 7.02, 7.30, 7.31, 7.40, 7.50 and KMC-WPC 7.30, 7.31, 7.40, 7.50), does not sufficiently validate path information provided by users, thus characters representing traverse to parent directory are passed through… | ||
| CVE-2020-5187 | Hig | 0.57 | 8.8 | 0.02 | Feb 24, 2020 | DNN (formerly DotNetNuke) through 9.4.4 allows Path Traversal (issue 2 of 2). | ||
| CVE-2019-10765 | Cri | 0.57 | 9.8 | 0.02 | Nov 20, 2019 | iobroker.admin before 3.6.12 allows attacker to include file contents from outside the `/log/file1/` directory. | ||
| CVE-2019-3976 | Hig | 0.57 | 8.8 | 0.02 | Oct 29, 2019 | RouterOS 6.45.6 Stable, RouterOS 6.44.5 Long-term, and below are vulnerable to an arbitrary directory creation vulnerability via the upgrade package's name field. If an authenticated user installs a malicious package then a directory could be created and the developer shell… | ||
| CVE-2013-4855 | Hig | 0.57 | 8.8 | 0.02 | Oct 25, 2019 | D-Link DIR-865L has SMB Symlink Traversal due to misconfiguration in the SMB service allowing symbolic links to be created to locations outside of the Samba share. | ||
| CVE-2019-14657 | Hig | 0.57 | 8.8 | 0.04 | Oct 8, 2019 | Yealink phones through 2019-08-04 have an issue with OpenVPN file upload. They execute tar as root to extract files, but do not validate the extraction directory. Creating a tar file with ../../../../ allows replacement of almost any file on a phone. This leads to password… | ||
| CVE-2019-17313 | Hig | 0.57 | 8.8 | 0.02 | Oct 7, 2019 | SugarCRM before 8.0.4 and 9.x before 9.0.2 allows directory traversal in the Studio module by a Developer user. | ||
| CVE-2019-17312 | Hig | 0.57 | 8.8 | 0.02 | Oct 7, 2019 | SugarCRM before 8.0.4 and 9.x before 9.0.2 allows directory traversal in the file function by a Regular user. | ||
| CVE-2019-17311 | Hig | 0.57 | 8.8 | 0.02 | Oct 7, 2019 | SugarCRM before 8.0.4 and 9.x before 9.0.2 allows directory traversal in the attachment function by a Regular user. | ||
| CVE-2019-16915 | Cri | 0.57 | 9.8 | 0.04 | Sep 26, 2019 | An issue was discovered in pfSense through 2.4.4-p3. widgets/widgets/picture.widget.php uses the widgetkey parameter directly without sanitization (e.g., a basename call) for a pathname to file_get_contents or file_put_contents. | ||
| CVE-2019-14788 | Hig | 0.57 | 8.8 | 0.04 | Aug 15, 2019 | wp-admin/admin-ajax.php?action=newsletters_exportmultiple in the Tribulant Newsletters plugin before 4.6.19 for WordPress allows directory traversal with resultant remote PHP code execution via the subscribers[1][1] parameter in conjunction with an exportfile=../ value. | ||
| CVE-2016-10828 | Hig | 0.57 | 8.8 | 0.03 | Aug 1, 2019 | cPanel before 55.9999.141 allows arbitrary code execution because of an unsafe @INC path (SEC-97). | ||
| CVE-2019-3632 | Hig | 0.57 | 8.8 | 0.02 | Jun 27, 2019 | Directory Traversal vulnerability in McAfee Enterprise Security Manager (ESM) prior to 11.2.0 and prior to 10.4.0 allows authenticated user to gain elevated privileges via specially crafted input. | ||
| CVE-2019-12901 | Hig | 0.57 | 8.8 | 0.02 | Jun 20, 2019 | Pydio Cells before 1.5.0 fails to neutralize '../' elements, allowing an attacker with minimum privilege to Upload files to, and Delete files/folders from, an unprivileged directory, leading to Privilege escalation. | ||
| CVE-2019-12277 | Cri | 0.57 | 9.8 | 0.02 | May 22, 2019 | Blogifier 2.3 before 2019-05-11 does not properly restrict APIs, as demonstrated by missing checks for .. in a pathname. | ||
| CVE-2019-11831 | Cri | 0.57 | 9.8 | 0.05 | May 9, 2019 | The PharStreamWrapper (aka phar-stream-wrapper) package 2.x before 2.1.1 and 3.x before 3.1.1 for TYPO3 does not prevent directory traversal, which allows attackers to bypass a deserialization protection mechanism, as demonstrated by a phar:///path/bad.phar/../good.phar URL. |
- risk 0.57cvss 8.8epss 0.03
A path traversal in debug.php accessed via default.php in Blaauw Remote Kiln Control through v3.00r4 allows an authenticated attacker to upload arbitrary files, leading to arbitrary remote code execution.
- risk 0.57cvss 6.5epss 0.86
An issue was discovered in SaltStack Salt before 2019.2.4 and 3000 before 3000.2. The salt-master process ClearFuncs class allows access to some methods that improperly sanitize paths. These methods allow arbitrary directory access to authenticated users.
- risk 0.57cvss 9.8epss 0.02
The decompress package before 4.2.1 for Node.js is vulnerable to Arbitrary File Write via ../ in an archive member, when a symlink is used, because of Directory Traversal.
- risk 0.57cvss 8.8epss 0.03
IBM QRadar 7.3.0 to 7.3.3 Patch 2 could allow a remote attacker to include arbitrary files. A remote attacker could send a specially-crafted request specify a malicious file from a remote system, which could allow the attacker to execute arbitrary code on the vulnerable server.…
- risk 0.57cvss 8.8epss 0.01
SAP NetWeaver (Knowledge Management), versions (KMC-CM - 7.00, 7.01, 7.02, 7.30, 7.31, 7.40, 7.50 and KMC-WPC 7.30, 7.31, 7.40, 7.50), does not sufficiently validate path information provided by users, thus characters representing traverse to parent directory are passed through…
- risk 0.57cvss 8.8epss 0.02
DNN (formerly DotNetNuke) through 9.4.4 allows Path Traversal (issue 2 of 2).
- risk 0.57cvss 9.8epss 0.02
iobroker.admin before 3.6.12 allows attacker to include file contents from outside the `/log/file1/` directory.
- risk 0.57cvss 8.8epss 0.02
RouterOS 6.45.6 Stable, RouterOS 6.44.5 Long-term, and below are vulnerable to an arbitrary directory creation vulnerability via the upgrade package's name field. If an authenticated user installs a malicious package then a directory could be created and the developer shell…
- risk 0.57cvss 8.8epss 0.02
D-Link DIR-865L has SMB Symlink Traversal due to misconfiguration in the SMB service allowing symbolic links to be created to locations outside of the Samba share.
- risk 0.57cvss 8.8epss 0.04
Yealink phones through 2019-08-04 have an issue with OpenVPN file upload. They execute tar as root to extract files, but do not validate the extraction directory. Creating a tar file with ../../../../ allows replacement of almost any file on a phone. This leads to password…
- risk 0.57cvss 8.8epss 0.02
SugarCRM before 8.0.4 and 9.x before 9.0.2 allows directory traversal in the Studio module by a Developer user.
- risk 0.57cvss 8.8epss 0.02
SugarCRM before 8.0.4 and 9.x before 9.0.2 allows directory traversal in the file function by a Regular user.
- risk 0.57cvss 8.8epss 0.02
SugarCRM before 8.0.4 and 9.x before 9.0.2 allows directory traversal in the attachment function by a Regular user.
- risk 0.57cvss 9.8epss 0.04
An issue was discovered in pfSense through 2.4.4-p3. widgets/widgets/picture.widget.php uses the widgetkey parameter directly without sanitization (e.g., a basename call) for a pathname to file_get_contents or file_put_contents.
- risk 0.57cvss 8.8epss 0.04
wp-admin/admin-ajax.php?action=newsletters_exportmultiple in the Tribulant Newsletters plugin before 4.6.19 for WordPress allows directory traversal with resultant remote PHP code execution via the subscribers[1][1] parameter in conjunction with an exportfile=../ value.
- risk 0.57cvss 8.8epss 0.03
cPanel before 55.9999.141 allows arbitrary code execution because of an unsafe @INC path (SEC-97).
- risk 0.57cvss 8.8epss 0.02
Directory Traversal vulnerability in McAfee Enterprise Security Manager (ESM) prior to 11.2.0 and prior to 10.4.0 allows authenticated user to gain elevated privileges via specially crafted input.
- risk 0.57cvss 8.8epss 0.02
Pydio Cells before 1.5.0 fails to neutralize '../' elements, allowing an attacker with minimum privilege to Upload files to, and Delete files/folders from, an unprivileged directory, leading to Privilege escalation.
- risk 0.57cvss 9.8epss 0.02
Blogifier 2.3 before 2019-05-11 does not properly restrict APIs, as demonstrated by missing checks for .. in a pathname.
- risk 0.57cvss 9.8epss 0.05
The PharStreamWrapper (aka phar-stream-wrapper) package 2.x before 2.1.1 and 3.x before 3.1.1 for TYPO3 does not prevent directory traversal, which allows attackers to bypass a deserialization protection mechanism, as demonstrated by a phar:///path/bad.phar/../good.phar URL.