VYPR

CWE-552

Files or Directories Accessible to External Parties

BaseDraft

Description

The product makes files or directories accessible to unauthorized actors, even though they should not be.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-150 · CAPEC-639

CVEs mapped to this weakness (493)

page 10 of 25
  • CVE-2020-35340HigSep 15, 2021
    risk 0.49cvss 7.5epss 0.01

    A local file inclusion vulnerability in ExpertPDF 9.5.0 through 14.1.0 allows attackers to read the file contents from files that the running ExpertPDF process has access to read.

  • CVE-2020-22124HigAug 18, 2021
    risk 0.49cvss 7.5epss 0.01

    A vulnerability in the \inc\config.php component of joyplus-cms v1.6 allows attackers to access sensitive information.

  • CVE-2021-37348HigAug 13, 2021
    risk 0.49cvss 7.5epss 0.03

    Nagios XI before version 5.8.5 is vulnerable to local file inclusion through improper limitation of a pathname in index.php.

  • CVE-2021-36763HigAug 3, 2021
    risk 0.49cvss 7.5epss 0.01

    In CODESYS V3 web server before 3.5.17.10, files or directories are accessible to External Parties.

  • CVE-2021-33359HigJun 9, 2021
    risk 0.49cvss 7.5epss 0.01

    A vulnerability exists in gowitness < 2.3.6 that allows an unauthenticated attacker to perform an arbitrary file read using the file:// scheme in the url parameter to get an image of any file.

  • CVE-2018-10863HigMay 26, 2021
    risk 0.49cvss 7.5epss 0.01

    It was discovered that redhat-certification 7 is not properly configured and it lists all files and directories in the /var/www/rhcert/store/transfer directory, through the /rhcert-transfer URL. An unauthorized attacker may use this flaw to gather sensible information.

  • CVE-2021-29024HigMay 17, 2021
    risk 0.49cvss 7.5epss 0.02

    In InvoicePlane 1.5.11 a misconfigured web server allows unauthenticated directory listing and file download. Allowing an attacker to directory traversal and download files suppose to be private without authentication.

  • CVE-2020-26549HigNov 17, 2020
    risk 0.49cvss 7.5epss 0.02

    An issue was discovered in Aviatrix Controller before R5.4.1290. The htaccess protection mechanism to prevent requests to directories can be bypassed for file downloading.

  • CVE-2020-11976HigAug 11, 2020
    risk 0.49cvss 7.5epss 0.04

    By crafting a special URL it is possible to make Wicket deliver unprocessed HTML templates. This would allow an attacker to see possibly sensitive information inside a HTML template that is usually removed during rendering. Affected are Apache Wicket versions 7.16.0, 8.8.0 and…

  • CVE-2019-13941HigFeb 11, 2020
    risk 0.49cvss 7.5epss 0.02

    A vulnerability has been identified in OZW672 (All versions < V10.00), OZW772 (All versions < V10.00). Vulnerable versions of OZW Web Server use predictable path names for project files that legitimately authenticated users have created by using the application's export…

  • CVE-2019-17221HigNov 5, 2019
    risk 0.49cvss 7.5epss 0.03

    PhantomJS through 2.1.1 has an arbitrary file read vulnerability, as demonstrated by an XMLHttpRequest for a file:// URI. The vulnerability exists in the page.open() function of the webpage module, which loads a specified URL and calls a given callback. An attacker can supply a…

  • CVE-2019-10930HigJul 11, 2019
    risk 0.49cvss 7.5epss 0.02

    A vulnerability has been identified in All other SIPROTEC 5 device types with CPU variants CP300 and CP100 and the respective Ethernet communication modules (All versions ), DIGSI 5 engineering software (All versions < V7.90), SIPROTEC 5 device types 6MD85, 6MD86, 6MD89, 7UM85,…

  • CVE-2018-10869HigJul 19, 2018
    risk 0.49cvss 7.5epss 0.03

    redhat-certification does not properly restrict files that can be download through the /download page. A remote attacker may download any file accessible by the user running httpd.

  • CVE-2018-5112HigJun 11, 2018
    risk 0.49cvss 7.5epss 0.02

    Development Tools panels of an extension are required to load URLs for the panels as relative URLs from the extension manifest file but this requirement was not enforced in all instances. This could allow the development tools panel for the extension to load a URL that it should…

  • CVE-2017-12079HigDec 4, 2017
    risk 0.49cvss 7.5epss 0.02

    Files or directories accessible to external parties vulnerability in picasa.php in Synology Photo Station before 6.8.1-3458 and before 6.3-2970 allows remote attackers to obtain arbitrary files via prog_id field.

  • CVE-2017-2551HigSep 28, 2017
    risk 0.49cvss 7.5epss 0.02

    Vulnerability in Wordpress plugin BackWPup before v3.4.2 allows possible brute forcing of backup file for download.

  • CVE-2017-11746HigJul 30, 2017
    risk 0.49cvss 7.5epss 0.01

    Tenshi 0.15 creates a tenshi.pid file after dropping privileges to a non-root account, which might allow local users to kill arbitrary processes by leveraging access to this non-root account for tenshi.pid modification before a root script executes a "kill `cat…

  • CVE-2025-59054HigSep 12, 2025
    risk 0.48cvss epss 0.00

    dstack is a software development kit (SDK) to simplify the deployment of arbitrary containerized apps into trusted execution environments. In versions of dstack prior to 0.5.4, a malicious host may provide a crafted LUKS2 data volume to a dstack CVM for use as the `/data` mount.…

  • CVE-2024-34066HigMay 3, 2024
    risk 0.48cvss 8.4epss 0.01

    Pterodactyl wings is the server control plane for Pterodactyl Panel. If the Wings token is leaked either by viewing the node configuration or posting it accidentally somewhere, an attacker can use it to gain arbitrary file write and read access on the node the token is…

  • CVE-2022-30945HigMay 17, 2022
    risk 0.48cvss 8.5epss 0.01

    Jenkins Pipeline: Groovy Plugin 2689.v434009a_31b_f1 and earlier allows loading any Groovy source files on the classpath of Jenkins and Jenkins plugins in sandboxed pipelines.