VYPR

CWE-22

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')

BaseStableLikelihood: High

Description

The product uses external input to construct a pathname that is intended to identify a file or directory that is located underneath a restricted parent directory, but the product does not properly neutralize special elements within the pathname that can cause the pathname to resolve to a location that is outside of the restricted directory.

Hierarchy (View 1000)

Parents

Children

Related attack patterns (CAPEC)

CAPEC-126 · CAPEC-64 · CAPEC-76 · CAPEC-78 · CAPEC-79

CVEs mapped to this weakness (10,395)

page 73 of 520
  • CVE-2019-18871HigMay 7, 2020
    risk 0.57cvss 8.8epss 0.03

    A path traversal in debug.php accessed via default.php in Blaauw Remote Kiln Control through v3.00r4 allows an authenticated attacker to upload arbitrary files, leading to arbitrary remote code execution.

  • CVE-2020-11652MedKEVApr 30, 2020
    risk 0.57cvss 6.5epss 0.86

    An issue was discovered in SaltStack Salt before 2019.2.4 and 3000 before 3000.2. The salt-master process ClearFuncs class allows access to some methods that improperly sanitize paths. These methods allow arbitrary directory access to authenticated users.

  • CVE-2020-12265CriApr 26, 2020
    risk 0.57cvss 9.8epss 0.02

    The decompress package before 4.2.1 for Node.js is vulnerable to Arbitrary File Write via ../ in an archive member, when a symlink is used, because of Directory Traversal.

  • CVE-2020-4272HigApr 15, 2020
    risk 0.57cvss 8.8epss 0.03

    IBM QRadar 7.3.0 to 7.3.3 Patch 2 could allow a remote attacker to include arbitrary files. A remote attacker could send a specially-crafted request specify a malicious file from a remote system, which could allow the attacker to execute arbitrary code on the vulnerable server.…

  • CVE-2020-6225HigApr 14, 2020
    risk 0.57cvss 8.8epss 0.01

    SAP NetWeaver (Knowledge Management), versions (KMC-CM - 7.00, 7.01, 7.02, 7.30, 7.31, 7.40, 7.50 and KMC-WPC 7.30, 7.31, 7.40, 7.50), does not sufficiently validate path information provided by users, thus characters representing traverse to parent directory are passed through…

  • CVE-2020-5187HigFeb 24, 2020
    risk 0.57cvss 8.8epss 0.02

    DNN (formerly DotNetNuke) through 9.4.4 allows Path Traversal (issue 2 of 2).

  • CVE-2019-10765CriNov 20, 2019
    risk 0.57cvss 9.8epss 0.02

    iobroker.admin before 3.6.12 allows attacker to include file contents from outside the `/log/file1/` directory.

  • CVE-2019-3976HigOct 29, 2019
    risk 0.57cvss 8.8epss 0.02

    RouterOS 6.45.6 Stable, RouterOS 6.44.5 Long-term, and below are vulnerable to an arbitrary directory creation vulnerability via the upgrade package's name field. If an authenticated user installs a malicious package then a directory could be created and the developer shell…

  • CVE-2013-4855HigOct 25, 2019
    risk 0.57cvss 8.8epss 0.02

    D-Link DIR-865L has SMB Symlink Traversal due to misconfiguration in the SMB service allowing symbolic links to be created to locations outside of the Samba share.

  • CVE-2019-14657HigOct 8, 2019
    risk 0.57cvss 8.8epss 0.04

    Yealink phones through 2019-08-04 have an issue with OpenVPN file upload. They execute tar as root to extract files, but do not validate the extraction directory. Creating a tar file with ../../../../ allows replacement of almost any file on a phone. This leads to password…

  • CVE-2019-17313HigOct 7, 2019
    risk 0.57cvss 8.8epss 0.02

    SugarCRM before 8.0.4 and 9.x before 9.0.2 allows directory traversal in the Studio module by a Developer user.

  • CVE-2019-17312HigOct 7, 2019
    risk 0.57cvss 8.8epss 0.02

    SugarCRM before 8.0.4 and 9.x before 9.0.2 allows directory traversal in the file function by a Regular user.

  • CVE-2019-17311HigOct 7, 2019
    risk 0.57cvss 8.8epss 0.02

    SugarCRM before 8.0.4 and 9.x before 9.0.2 allows directory traversal in the attachment function by a Regular user.

  • CVE-2019-16915CriSep 26, 2019
    risk 0.57cvss 9.8epss 0.04

    An issue was discovered in pfSense through 2.4.4-p3. widgets/widgets/picture.widget.php uses the widgetkey parameter directly without sanitization (e.g., a basename call) for a pathname to file_get_contents or file_put_contents.

  • CVE-2019-14788HigAug 15, 2019
    risk 0.57cvss 8.8epss 0.04

    wp-admin/admin-ajax.php?action=newsletters_exportmultiple in the Tribulant Newsletters plugin before 4.6.19 for WordPress allows directory traversal with resultant remote PHP code execution via the subscribers[1][1] parameter in conjunction with an exportfile=../ value.

  • CVE-2016-10828HigAug 1, 2019
    risk 0.57cvss 8.8epss 0.03

    cPanel before 55.9999.141 allows arbitrary code execution because of an unsafe @INC path (SEC-97).

  • CVE-2019-3632HigJun 27, 2019
    risk 0.57cvss 8.8epss 0.02

    Directory Traversal vulnerability in McAfee Enterprise Security Manager (ESM) prior to 11.2.0 and prior to 10.4.0 allows authenticated user to gain elevated privileges via specially crafted input.

  • CVE-2019-12901HigJun 20, 2019
    risk 0.57cvss 8.8epss 0.02

    Pydio Cells before 1.5.0 fails to neutralize '../' elements, allowing an attacker with minimum privilege to Upload files to, and Delete files/folders from, an unprivileged directory, leading to Privilege escalation.

  • CVE-2019-12277CriMay 22, 2019
    risk 0.57cvss 9.8epss 0.02

    Blogifier 2.3 before 2019-05-11 does not properly restrict APIs, as demonstrated by missing checks for .. in a pathname.

  • CVE-2019-11831CriMay 9, 2019
    risk 0.57cvss 9.8epss 0.05

    The PharStreamWrapper (aka phar-stream-wrapper) package 2.x before 2.1.1 and 3.x before 3.1.1 for TYPO3 does not prevent directory traversal, which allows attackers to bypass a deserialization protection mechanism, as demonstrated by a phar:///path/bad.phar/../good.phar URL.