VYPR

CWE-22

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')

BaseStableLikelihood: High

Description

The product uses external input to construct a pathname that is intended to identify a file or directory that is located underneath a restricted parent directory, but the product does not properly neutralize special elements within the pathname that can cause the pathname to resolve to a location that is outside of the restricted directory.

Hierarchy (View 1000)

Parents

Children

Related attack patterns (CAPEC)

CAPEC-126 · CAPEC-64 · CAPEC-76 · CAPEC-78 · CAPEC-79

CVEs mapped to this weakness (10,395)

page 80 of 520
  • CVE-2022-39838HigSep 5, 2022
    risk 0.56cvss 8.6epss 0.02

    Systematic FIX Adapter (ALFAFX) 2.4.0.25 13/09/2017 allows remote file inclusion via a UNC share pathname, and also allows absolute path traversal to local pathnames.

  • CVE-2022-31566HigJul 11, 2022
    risk 0.56cvss 8.6epss 0.01

    The DSAB-local/DSAB repository through 2019-02-18 on GitHub allows absolute path traversal because the Flask send_file function is used unsafely.

  • CVE-2021-36288HigApr 8, 2022
    risk 0.56cvss 8.6epss 0.01

    Dell VNX2 for File version 8.1.21.266 and earlier, contain a path traversal vulnerability which may lead unauthenticated users to read/write restricted files

  • CVE-2021-30497HigApr 6, 2022
    risk 0.56cvss 7.5epss 0.97

    Ivanti Avalanche (Premise) 6.3.2 allows remote unauthenticated users to read arbitrary files via Absolute Path Traversal. The imageFilePath parameter processed by the /AvalancheWeb/image endpoint is not verified to be within the scope of the image folder, e.g., the attacker can…

  • CVE-2022-26960CriMar 21, 2022
    risk 0.56cvss 9.1epss 0.51

    connector.minimal.php in std42 elFinder through 2.1.60 is affected by path traversal. This allows unauthenticated remote attackers to read, write, and browse files outside the configured document root. This is due to improper handling of absolute file paths.

  • CVE-2021-46381HigMar 4, 2022
    risk 0.56cvss 7.5epss 0.59

    Local File Inclusion due to path traversal in D-Link DAP-1620 leads to unauthorized internal files reading [/etc/passwd] and [/etc/shadow].

  • CVE-2021-32498HigDec 17, 2021
    risk 0.56cvss 8.6epss 0.01

    SICK SOPAS ET before version 4.8.0 allows attackers to manipulate the pathname of the emulator and use path traversal to run an arbitrary executable located on the host system. When the user starts the emulator from SOPAS ET the corresponding executable will be started instead…

  • CVE-2021-41381HigSep 23, 2021
    risk 0.56cvss 7.5epss 0.53

    Payara Micro Community 5.2021.6 and below allows Directory Traversal.

  • CVE-2021-23428HigSep 1, 2021
    risk 0.56cvss 8.6epss 0.02

    This affects all versions of package elFinder.NetCore. The Path.Combine(...) method is used to create an absolute file path. Due to missing sanitation of the user input and a missing check of the generated path its possible to escape the Files directory via path traversal

  • CVE-2021-23427HigSep 1, 2021
    risk 0.56cvss 8.6epss 0.01

    This affects all versions of package elFinder.NetCore. The ExtractAsync function within the FileSystem is vulnerable to arbitrary extraction due to insufficient validation.

  • CVE-2020-24144HigJul 7, 2021
    risk 0.56cvss 8.6epss 0.02

    Directory traversal in the Media File Organizer (aka media-file-organizer) plugin 1.0.1 for WordPress lets an attacker get access to files that are stored outside the web root folder via the items[] parameter in a move operation.

  • CVE-2020-23715HigJun 28, 2021
    risk 0.56cvss 8.6epss 0.02

    Directory Traversal vulnerability in Webport CMS 1.19.10.17121 via the file parameter to file/download.

  • CVE-2020-4039HigApr 30, 2021
    risk 0.56cvss 8.6epss 0.01

    SUSI.AI is an intelligent Open Source personal assistant. SUSI.AI Server before version d27ed0f has a directory traversal vulnerability due to insufficient input validation. Any admin config and file readable by the app can be retrieved by the attacker. Furthermore, some files…

  • CVE-2020-24136HigApr 7, 2021
    risk 0.56cvss 8.6epss 0.02

    Directory traversal in Wcms 0.3.2 allows an attacker to read arbitrary files on the server that is running an application via the pagename parameter to wex/html.php.

  • CVE-2020-15012HigOct 12, 2020
    risk 0.56cvss 8.6epss 0.03

    A Directory Traversal issue was discovered in Sonatype Nexus Repository Manager 2.x before 2.14.19. A user that requests a crafted path can traverse up the file system to get access to content on disk (that the user running nxrm also has access to).

  • CVE-2020-15050HigJul 13, 2020
    risk 0.56cvss 7.5epss 0.51

    An issue was discovered in the Video Extension in Suprema BioStar 2 before 2.8.2. Remote attackers can read arbitrary files from the server via Directory Traversal.

  • CVE-2020-6768HigFeb 7, 2020
    risk 0.56cvss 8.6epss 0.02

    A path traversal vulnerability in the Bosch Video Management System (BVMS) NoTouch deployment allows an unauthenticated remote attacker to read arbitrary files from the Central Server. This affects Bosch BVMS versions 10.0 <= 10.0.0.1225, 9.0 <= 9.0.0.827, 8.0 <= 8.0.329 and 7.5…

  • CVE-2019-19458HigDec 3, 2019
    risk 0.56cvss 8.6epss 0.03

    SALTO ProAccess SPACE 5.4.3.0 allows Directory Traversal in the Data Export feature.

  • CVE-2015-9406HigSep 20, 2019
    risk 0.56cvss 7.5epss 0.55

    Directory traversal vulnerability in the mTheme-Unus theme before 2.3 for WordPress allows an attacker to read arbitrary files via a .. (dot dot) in the files parameter to css/css.php.

  • CVE-2019-14322HigJul 28, 2019
    risk 0.56cvss 7.5epss 0.56

    In Pallets Werkzeug before 0.15.5, SharedDataMiddleware mishandles drive names (such as C:) in Windows pathnames.