VYPR

CWE-22

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')

BaseStableLikelihood: High

Description

The product uses external input to construct a pathname that is intended to identify a file or directory that is located underneath a restricted parent directory, but the product does not properly neutralize special elements within the pathname that can cause the pathname to resolve to a location that is outside of the restricted directory.

Hierarchy (View 1000)

Parents

Children

Related attack patterns (CAPEC)

CAPEC-126 · CAPEC-64 · CAPEC-76 · CAPEC-78 · CAPEC-79

CVEs mapped to this weakness (10,395)

page 86 of 520
  • CVE-2022-23854HigDec 23, 2022
    risk 0.55cvss 7.5epss 0.46

    AVEVA InTouch Access Anywhere versions 2020 R2 and older are vulnerable to a path traversal exploit that could allow an unauthenticated user with network access to read files on the system outside of the secure gateway web server.

  • CVE-2022-43451HigNov 3, 2022
    risk 0.55cvss 8.4epss 0.00

    OpenHarmony-v3.1.2 and prior versions had an Multiple path traversal vulnerability in appspawn and nwebspawn services. Local attackers can create arbitrary directories or escape application sandbox.If chained with other vulnerabilities it would allow an unprivileged process to…

  • CVE-2022-29298HigMay 12, 2022
    risk 0.55cvss 7.5epss 0.47

    SolarView Compact ver.6.00 allows attackers to access sensitive files via directory traversal.

  • CVE-2022-27836HigApr 11, 2022
    risk 0.55cvss 8.4epss 0.00

    Improper access control and path traversal vulnerability in Storage Manager and Storage Manager Service prior to SMR Apr-2022 Release 1 allow local attackers to access arbitrary system files without a proper permission. The patch adds proper validation logic to prevent arbitrary…

  • CVE-2021-35380HigFeb 15, 2022
    risk 0.55cvss 7.5epss 0.39

    A Directory Traversal vulnerability exists in Solari di Udine TermTalk Server (TTServer) 3.24.0.2, which lets an unauthenticated malicious user gain access to the files on the remote system by gaining access to the relative path of the file they want to download…

  • CVE-2021-20134HigDec 30, 2021
    risk 0.55cvss 8.4epss 0.08

    Quagga Services on D-Link DIR-2640 less than or equal to version 1.11B02 are affected by an absolute path traversal vulnerability that allows a remote, authenticated attacker to set an arbitrary file on the router's filesystem as the log file used by either Quagga service (zebra…

  • CVE-2021-41291HigSep 30, 2021
    risk 0.55cvss 7.5epss 0.83

    ECOA BAS controller suffers from a path traversal content disclosure vulnerability. Using the GET parameter in File Manager, unauthenticated attackers can remotely disclose directory content on the affected device.

  • CVE-2021-32018HigAug 3, 2021
    risk 0.55cvss 8.5epss 0.01

    An issue was discovered in JUMP AMS 3.6.0.04.009-2487. The JUMP SOAP API was vulnerable to arbitrary file reading due to an improper limitation of file loading on the server filesystem, aka directory traversal.

  • CVE-2020-7861HigApr 22, 2021
    risk 0.55cvss 8.4epss 0.01

    AnySupport (Remote support solution) before 2019.3.21.0 allows directory traversing because of swprintf function to copy file from a management PC to a client PC. This can be lead to arbitrary file execution.

  • CVE-2021-27030HigApr 19, 2021
    risk 0.55cvss 7.8epss 0.60

    A user may be tricked into opening a malicious FBX file which may exploit a Directory Traversal Remote Code Execution vulnerability in FBX’s Review causing it to run arbitrary code on the system.

  • CVE-2021-22190HigApr 12, 2021
    risk 0.55cvss 8.5epss 0.02

    A path traversal vulnerability via the GitLab Workhorse in all versions of GitLab could result in the leakage of a JWT token

  • CVE-2020-35749HigJan 15, 2021
    risk 0.55cvss 7.7epss 0.30

    Directory traversal vulnerability in class-simple_job_board_resume_download_handler.php in the Simple Board Job plugin 2.9.3 and earlier for WordPress allows remote attackers to read arbitrary files via the sjb_file parameter to wp-admin/post.php.

  • CVE-2020-8144HigApr 1, 2020
    risk 0.55cvss 8.4epss 0.01

    The UniFi Video Server v3.9.3 and prior (for Windows 7/8/10 x64) web interface Firmware Update functionality, under certain circumstances, does not validate firmware download destinations to ensure they are within the intended destination directory tree. It accepts a request…

  • CVE-2019-3696HigMar 3, 2020
    risk 0.55cvss 8.4epss 0.00

    A Improper Limitation of a Pathname to a Restricted Directory vulnerability in the packaging of pcp of SUSE Linux Enterprise High Performance Computing 15-ESPOS, SUSE Linux Enterprise High Performance Computing 15-LTSS, SUSE Linux Enterprise Module for Development Tools 15, SUSE…

  • CVE-2018-20470HigJun 17, 2019
    risk 0.55cvss 7.5epss 0.46

    An issue was discovered in Tyto Sahi Pro through 7.x.x and 8.0.0. A directory traversal (arbitrary file access) vulnerability exists in the web reports module. This allows an outside attacker to view contents of sensitive files.

  • CVE-2019-12593HigJun 3, 2019
    risk 0.55cvss 7.5epss 0.41

    IceWarp Mail Server through 10.4.4 is prone to a local file inclusion vulnerability via webmail/calendar/minimizer/index.php?style=..%5c directory traversal.

  • CVE-2018-10822HigOct 17, 2018
    risk 0.55cvss 7.5epss 0.39

    Directory traversal vulnerability in the web interface on D-Link DWR-116 through 1.06, DIR-140L through 1.02, DIR-640L through 1.02, DWR-512 through 2.02, DWR-712 through 2.02, DWR-912 through 2.02, DWR-921 through 2.02, and DWR-111 through 1.01 devices allows remote attackers…

  • CVE-2018-16299HigSep 24, 2018
    risk 0.55cvss 7.5epss 0.44

    The Localize My Post plugin 1.0 for WordPress allows Directory Traversal via the ajax/include.php file parameter.

  • CVE-2018-7098HigAug 14, 2018
    risk 0.55cvss 8.4epss 0.01

    A security vulnerability was identified in 3PAR Service Processor (SP) prior to SP-4.4.0.GA-110(MU7). The vulnerability may be locally exploited to allow directory traversal.

  • CVE-2018-15142HigAug 13, 2018
    risk 0.55cvss 8.8epss 0.18

    Directory traversal in portal/import_template.php in versions of OpenEMR before 5.0.1.4 allows a remote attacker authenticated in the patient portal to execute arbitrary PHP code by writing a file with a PHP extension via the "docid" and "content" parameters and accessing it in…