VYPR

CWE-22

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')

BaseStableLikelihood: High

Description

The product uses external input to construct a pathname that is intended to identify a file or directory that is located underneath a restricted parent directory, but the product does not properly neutralize special elements within the pathname that can cause the pathname to resolve to a location that is outside of the restricted directory.

Hierarchy (View 1000)

Parents

Children

Related attack patterns (CAPEC)

CAPEC-126 · CAPEC-64 · CAPEC-76 · CAPEC-78 · CAPEC-79

CVEs mapped to this weakness (10,395)

page 89 of 520
  • CVE-2024-40348HigJul 20, 2024
    risk 0.54cvss 8.2epss 0.08

    An issue in the component /api/swaggerui/static of Bazaar v1.4.3 allows unauthenticated attackers to execute a directory traversal.

  • CVE-2024-5182CriJun 20, 2024
    risk 0.54cvss 9.1epss 0.26

    A path traversal vulnerability exists in mudler/localai version 2.14.0, where an attacker can exploit the `model` parameter during the model deletion process to delete arbitrary files. Specifically, by crafting a request with a manipulated `model` parameter, an attacker can…

  • CVE-2024-3573CriApr 16, 2024
    risk 0.54cvss 9.3epss 0.01

    mlflow/mlflow is vulnerable to Local File Inclusion (LFI) due to improper parsing of URIs, allowing attackers to bypass checks and read arbitrary files on the system. The issue arises from the 'is_local_uri' function's failure to properly handle URIs with empty or 'file'…

  • CVE-2024-29434HigApr 2, 2024
    risk 0.54cvss 8.3epss 0.01

    An issue in the system image upload interface of Alldata v0.4.6 allows attackers to execute a directory traversal when uploading a file.

  • CVE-2024-0964CriFeb 5, 2024
    risk 0.54cvss 9.4epss 0.01

    A local file include could be remotely triggered in Gradio due to a vulnerable user-supplied JSON value in an API request.

  • CVE-2023-44251HigDec 13, 2023
    risk 0.54cvss 8.3epss 0.01

    ** UNSUPPORTED WHEN ASSIGNED **A improper limitation of a pathname to a restricted directory ('path traversal') vulnerability [CWE-22] in Fortinet FortiWAN version 5.2.0 through 5.2.1 and version 5.1.1. through 5.1.2 may allow an authenticated attacker to read and delete…

  • CVE-2023-34260HigNov 3, 2023
    risk 0.54cvss 7.5epss 0.73

    Kyocera TASKalfa 4053ci printers through 2VG_S000.002.561 allow a denial of service (service outage) via /wlmdeu%2f%2e%2e%2f%2e%2e followed by a directory reference such as %2fetc%00index.htm to try to read the /etc directory.

  • CVE-2023-4990HigOct 11, 2023
    risk 0.54cvss 8.3epss 0.01

    Directory traversal vulnerability in MCL-Net versions prior to 4.6 Update Package (P01) may allow attackers to read arbitrary files.

  • CVE-2022-31474HigMar 13, 2023
    risk 0.54cvss 7.5epss 0.64

    Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in iThemes BackupBuddy allows Path Traversal.This issue affects BackupBuddy: from 8.5.8.0 through 8.7.4.1.

  • CVE-2022-41216HigFeb 22, 2023
    risk 0.54cvss 8.3epss 0.01

    Local File Inclusion vulnerability within Cloudflow allows attackers to retrieve confidential information from the system.

  • CVE-2022-0902HigJul 21, 2022
    risk 0.54cvss 8.1epss 0.16

    Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal'), Improper Neutralization of Special Elements used in a Command ('Command Injection') vulnerability in flow computer and remote controller products of ABB ( RMC-100 (Standard), RMC-100-LITE, XIO, XFCG5…

  • CVE-2022-31507CriJul 11, 2022
    risk 0.54cvss 9.3epss 0.02

    The ganga-devs/ganga repository before 8.5.10 on GitHub allows absolute path traversal because the Flask send_file function is used unsafely.

  • CVE-2022-31506CriJul 11, 2022
    risk 0.54cvss 9.3epss 0.01

    The cmusatyalab/opendiamond repository through 10.1.1 on GitHub allows absolute path traversal because the Flask send_file function is used unsafely.

  • CVE-2020-14523HigFeb 11, 2022
    risk 0.54cvss 8.3epss 0.02

    Multiple Mitsubishi Electric Factory Automation products have a vulnerability that allows an attacker to execute arbitrary code.

  • CVE-2021-45043HigDec 15, 2021
    risk 0.54cvss 7.5epss 0.33

    HD-Network Real-time Monitoring System 2.0 allows ../ directory traversal to read /etc/shadow via the /language/lang s_Language parameter.

  • CVE-2021-38360HigSep 10, 2021
    risk 0.54cvss 8.3epss 0.02

    The wp-publications WordPress plugin is vulnerable to restrictive local file inclusion via the Q_FILE parameter found in the ~/bibtexbrowser.php file which allows attackers to include local zip files and achieve remote code execution, in versions up to and including 0.0.

  • CVE-2021-37701HigAug 31, 2021
    risk 0.54cvss 8.2epss 0.03

    The npm package "tar" (aka node-tar) before versions 4.4.16, 5.0.8, and 6.1.7 has an arbitrary file creation/overwrite and arbitrary code execution vulnerability. node-tar aims to guarantee that any file whose location would be modified by a symbolic link is not extracted. This…

  • CVE-2021-20023MedKEVApr 20, 2021
    risk 0.54cvss 4.9epss 0.51

    SonicWall Email Security version 10.0.9.x contains a vulnerability that allows a post-authenticated attacker to read an arbitrary file on the remote host.

  • CVE-2021-21357HigMar 23, 2021
    risk 0.54cvss 8.3epss 0.02

    TYPO3 is an open source PHP based web content management system. In TYPO3 before versions 8.7.40, 9.5.25, 10.4.14, 11.1.1 due to improper input validation, attackers can by-pass restrictions of predefined options and submit arbitrary data in the Form Designer backend module of…

  • CVE-2020-27871HigFeb 10, 2021
    risk 0.54cvss 7.2epss 0.91

    This vulnerability allows remote attackers to create arbitrary files on affected installations of SolarWinds Orion Platform 2020.2.1. Although authentication is required to exploit this vulnerability, the existing authentication mechanism can be bypassed. The specific flaw…