VYPR

CWE-22

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')

BaseStableLikelihood: High

Description

The product uses external input to construct a pathname that is intended to identify a file or directory that is located underneath a restricted parent directory, but the product does not properly neutralize special elements within the pathname that can cause the pathname to resolve to a location that is outside of the restricted directory.

Hierarchy (View 1000)

Parents

Children

Related attack patterns (CAPEC)

CAPEC-126 · CAPEC-64 · CAPEC-76 · CAPEC-78 · CAPEC-79

CVEs mapped to this weakness (10,395)

page 97 of 520
  • CVE-2020-21862HigJul 6, 2023
    risk 0.53cvss 8.1epss 0.01

    Directory traversal vulnerability in DuxCMS 2.1 allows attackers to delete arbitrary files via /admin/AdminBackup/del.

  • CVE-2023-32522HigJun 26, 2023
    risk 0.53cvss 8.1epss 0.03

    A path traversal exists in a specific dll of Trend Micro Mobile Security (Enterprise) 9.8 SP5 which could allow an authenticated remote attacker to delete arbitrary files. Please note: an attacker must first obtain the ability to execute low-privileged code on the target…

  • CVE-2023-35801HigJun 23, 2023
    risk 0.53cvss 8.1epss 0.01

    A directory traversal vulnerability in Safe Software FME Server before 2022.2.5 allows an attacker to bypass validation when editing a network-based resource connection, resulting in the unauthorized reading and writing of arbitrary files. Successful exploitation requires an…

  • CVE-2023-28382HigMay 26, 2023
    risk 0.53cvss 8.1epss 0.01

    Directory traversal vulnerability in ESS REC Agent Server Edition series allows an authenticated attacker to view or alter an arbitrary file on the server. Affected products and versions are as follows: ESS REC Agent Server Edition for Linux V1.0.0 to V1.4.3, ESS REC Agent…

  • CVE-2020-13377HigMay 12, 2023
    risk 0.53cvss 8.1epss 0.02

    The web-services interface of Loadbalancer.org Enterprise VA MAX through 8.3.8 could allow an authenticated, remote, low-privileged attacker to conduct directory traversal attacks and obtain read and write access to sensitive files.

  • CVE-2023-28127HigMay 9, 2023
    risk 0.53cvss 7.5epss 0.59

    A path traversal vulnerability exists in Avalanche version 6.3.x and below that when exploited could result in possible information disclosure.

  • CVE-2023-27700HigMar 28, 2023
    risk 0.53cvss 8.1epss 0.01

    MuYuCMS v2.2 was discovered to contain an arbitrary file deletion vulnerability via the component /accessory/picdel.html.

  • CVE-2022-42476HigMar 7, 2023
    risk 0.53cvss 8.2epss 0.00

    A relative path traversal vulnerability [CWE-23] in Fortinet FortiOS version 7.2.0 through 7.2.2, 7.0.0 through 7.0.8 and before 6.4.11, FortiProxy version 7.2.0 through 7.2.2 and 7.0.0 through 7.0.8 allows privileged VDOM administrators to escalate their privileges to super…

  • CVE-2023-26255HigFeb 28, 2023
    risk 0.53cvss 7.5epss 0.47

    An unauthenticated path traversal vulnerability affects the "STAGIL Navigation for Jira - Menu & Themes" plugin before 2.0.52 for Jira. By modifying the fileName parameter to the snjCustomDesignConfig endpoint, it is possible to traverse and read the file system.

  • CVE-2023-0454HigFeb 1, 2023
    risk 0.53cvss 8.1epss 0.01

    OrangeScrum version 2.0.11 allows an authenticated external attacker to delete arbitrary local files from the server. This is possible because the application uses an unsanitized attacker-controlled parameter to construct an internal path.

  • CVE-2022-40701HigJan 26, 2023
    risk 0.53cvss 8.1epss 0.03

    A directory traversal vulnerability exists in the httpd delfile.cgi functionality of Siretta QUARTZ-GOLD G5.0.1.5-210720-141020. A specially-crafted HTTP request can lead to arbitrary file deletion. An attacker can send an HTTP request to trigger this vulnerability.

  • CVE-2021-37500HigJan 20, 2023
    risk 0.53cvss 8.1epss 0.01

    Directory traversal vulnerability in Reprise License Manager (RLM) web interface before 14.2BL4 in the diagnostics function that allows RLM users with sufficient privileges to overwrite any file the on the server.

  • CVE-2022-2893HigJan 17, 2023
    risk 0.53cvss 8.2epss 0.01

    RONDS EPM version 1.19.5 does not properly validate the filename parameter, which could allow an unauthorized user to specify file paths and download files.  

  • CVE-2022-3782CriJan 13, 2023
    risk 0.53cvss 9.1epss 0.06

    keycloak: path traversal via double URL encoding. A flaw was found in Keycloak, where it does not properly validate URLs included in a redirect. An attacker can use this flaw to construct a malicious request to bypass validation and access other URLs and potentially sensitive…

  • CVE-2022-36943HigJan 3, 2023
    risk 0.53cvss 8.1epss 0.01

    SSZipArchive versions 2.5.3 and older contain an arbitrary file write vulnerability due to lack of sanitization on paths which are symlinks. SSZipArchive will overwrite files on the filesystem when opening a malicious ZIP containing a symlink as the first item.

  • CVE-2022-2969HigDec 1, 2022
    risk 0.53cvss 8.1epss 0.02

    Delta Industrial Automation DIALink versions prior to v1.5.0.0 Beta 4 uses an external input to construct a pathname intended to identify a file or directory located underneath a restricted parent directory. However, the software does not properly neutralize special elements…

  • CVE-2022-4030HigNov 29, 2022
    risk 0.53cvss 8.1epss 0.02

    The Simple:Press plugin for WordPress is vulnerable to Path Traversal in versions up to, and including, 6.8 via the 'file' parameter which can be manipulated during user avatar deletion. This makes it possible with attackers, with minimal permissions such as a subscriber, to…

  • CVE-2022-38421HigOct 14, 2022
    risk 0.53cvss 7.2epss 0.79

    Adobe ColdFusion versions Update 14 (and earlier) and Update 4 (and earlier) are affected by an Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability that could result in arbitrary code execution in the context of the current user.…

  • CVE-2021-33354HigSep 30, 2022
    risk 0.53cvss 8.1epss 0.01

    Directory Traversal vulnerability in htmly before 2.8.1 allows remote attackers to perform arbitrary file deletions via modified file parameter.

  • CVE-2022-28741HigSep 9, 2022
    risk 0.53cvss 8.1epss 0.01

    aEnrich a+HRD 5.x Learning Management Key Performance Indicator System has a local file inclusion (LFI) vulnerability that occurs due to missing input validation in v5.x