VYPR

CWE-22

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')

BaseStableLikelihood: High

Description

The product uses external input to construct a pathname that is intended to identify a file or directory that is located underneath a restricted parent directory, but the product does not properly neutralize special elements within the pathname that can cause the pathname to resolve to a location that is outside of the restricted directory.

Hierarchy (View 1000)

Parents

Children

Related attack patterns (CAPEC)

CAPEC-126 · CAPEC-64 · CAPEC-76 · CAPEC-78 · CAPEC-79

CVEs mapped to this weakness (10,395)

page 98 of 520
  • CVE-2022-38258HigSep 8, 2022
    risk 0.53cvss 8.1epss 0.01

    A local file inclusion (LFI) vulnerability in D-Link DIR 819 v1.06 allows attackers to cause a Denial of Service (DoS) or access sensitive server information via manipulation of the getpage parameter in a crafted web request.

  • CVE-2021-40285HigAug 26, 2022
    risk 0.53cvss 8.1epss 0.01

    htmly v2.8.1 was discovered to contain an arbitrary file deletion vulnerability via the component \views\backup.html.php.

  • CVE-2021-40668HigJun 9, 2022
    risk 0.53cvss 8.1epss 0.01

    The Android application HTTP File Server (Version 1.4.1) by 'slowscript' is affected by a path traversal vulnerability that permits arbitrary directory listing, file read, and file write.

  • CVE-2021-27771HigMay 12, 2022
    risk 0.53cvss 8.2epss 0.01

    User SID can be modified resulting in an Arbitrary File Upload or deletion of directories causing a Denial of Service. When interacting in a normal matter with the Sametime chat application, users hold a cookie containing their session ID (SID). This value is also used when…

  • CVE-2022-28527HigApr 26, 2022
    risk 0.53cvss 8.1epss 0.01

    dhcms v20170919 was discovered to contain an arbitrary folder deletion vulnerability via /admin.php?r=admin/AdminBackup/del.

  • CVE-2022-28523HigApr 26, 2022
    risk 0.53cvss 8.1epss 0.01

    HongCMS 3.0.0 allows arbitrary file deletion via the component /admin/index.php/template/ajax?action=delete.

  • CVE-2022-28059HigApr 26, 2022
    risk 0.53cvss 8.1epss 0.01

    Verydows v2.0 was discovered to contain an arbitrary file deletion vulnerability via \backend\database_controller.php.

  • CVE-2022-28058HigApr 26, 2022
    risk 0.53cvss 8.1epss 0.01

    Verydows v2.0 was discovered to contain an arbitrary file deletion vulnerability via \backend\file_controller.php.

  • CVE-2021-40680HigApr 25, 2022
    risk 0.53cvss 8.1epss 0.01

    There is a Directory Traversal vulnerability in Artica Proxy (4.30.000000 SP206 through SP255, and VMware appliance 4.30.000000 through SP273) via the filename parameter to /cgi-bin/main.cgi.

  • CVE-2021-22797HigApr 13, 2022
    risk 0.53cvss 7.8epss 0.26

    A CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal) vulnerability exists that could cause malicious script to be deployed in an unauthorized location and may result in code execution on the engineering workstation when a malicious project file…

  • CVE-2022-23971HigApr 7, 2022
    risk 0.53cvss 8.1epss 0.00

    ASUS RT-AX56U’s update_PLC/PORT file has a path traversal vulnerability due to insufficient filtering for special characters in the URL parameter. An unauthenticated LAN attacker can overwrite a system file by uploading another PLC/PORT file with the same file name, which…

  • CVE-2022-23970HigApr 7, 2022
    risk 0.53cvss 8.1epss 0.00

    ASUS RT-AX56U’s update_json function has a path traversal vulnerability due to insufficient filtering for special characters in the URL parameter. An unauthenticated LAN attacker can overwrite a system file by uploading another file with the same file name, which results in…

  • CVE-2022-21177HigMar 11, 2022
    risk 0.53cvss 8.1epss 0.01

    There is a path traversal vulnerability in CAMS for HIS Log Server contained in the following Yokogawa Electric products: CENTUM CS 3000 versions from R3.08.10 to R3.09.00, CENTUM VP versions from R4.01.00 to R4.03.00, from R5.01.00 to R5.04.20, andfrom R6.01.00 to R6.08.00,…

  • CVE-2021-41002HigMar 2, 2022
    risk 0.53cvss 8.1epss 0.01

    Multiple authenticated remote path traversal vulnerabilities were discovered in the AOS-CX command line interface in Aruba CX 6200F Switch Series, Aruba 6300 Switch Series, Aruba 6400 Switch Series, Aruba 8320 Switch Series, Aruba 8325 Switch Series, Aruba 8400 Switch Series,…

  • CVE-2022-25412HigFeb 28, 2022
    risk 0.53cvss 8.1epss 0.01

    Maxsite CMS v180 was discovered to contain multiple arbitrary file deletion vulnerabilities in /admin_page/all-files-update-ajax.php via the dir and deletefile parameters.

  • CVE-2021-46037HigFeb 18, 2022
    risk 0.53cvss 8.1epss 0.01

    MCMS v5.2.4 was discovered to contain an arbitrary file deletion vulnerability via the component /template/unzip.do.

  • CVE-2022-24647HigFeb 10, 2022
    risk 0.53cvss 8.1epss 0.01

    Cuppa CMS v1.0 was discovered to contain an arbitrary file deletion vulnerability via the unlink() function.

  • CVE-2021-42753HigFeb 2, 2022
    risk 0.53cvss 8.1epss 0.01

    An improper limitation of a pathname to a restricted directory ('Path Traversal') vulnerability [CWE-22] in FortiWeb management interface 6.4.1 and below, 6.3.15 and below, 6.2.x, 6.1.x, 6.0.x, 5.9.x and 5.8.x may allow an authenticated attacker to perform an arbitrary file and…

  • CVE-2021-21909HigDec 22, 2021
    risk 0.53cvss 8.1epss 0.01

    Specially-crafted command line arguments can lead to arbitrary file deletion in the del .cnt|.log file delete command. An attacker can provide malicious inputs to trigger this vulnerability

  • CVE-2021-34762HigOct 27, 2021
    risk 0.53cvss 8.1epss 0.02

    A vulnerability in the web-based management interface of Cisco Firepower Management Center (FMC) Software could allow an authenticated, remote attacker to perform a directory traversal attack on an affected device. The attacker would require valid device credentials. The…