CWE-552
Files or Directories Accessible to External Parties
Description
The product makes files or directories accessible to unauthorized actors, even though they should not be.
Hierarchy (View 1000)
Related attack patterns (CAPEC)
CAPEC-150 · CAPEC-639
CVEs mapped to this weakness (493)
page 9 of 25| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2022-48161 | Hig | 0.49 | 7.5 | 0.01 | Feb 1, 2023 | Easy Images v2.0 was discovered to contain an arbitrary file download vulnerability via the component /application/down.php. This vulnerability is exploited via a crafted GET request. | ||
| CVE-2022-4106 | Hig | 0.49 | 7.5 | 0.01 | Dec 19, 2022 | The Wholesale Market for WooCommerce WordPress plugin before 1.0.7 does not have authorisation check, as well as does not validate user input used to generate system path, allowing unauthenticated attackers to download arbitrary file from the server. | ||
| CVE-2022-45227 | Hig | 0.49 | 7.5 | 0.01 | Dec 12, 2022 | The web portal of Dragino Lora LG01 18ed40 IoT v4.3.4 has the directory listing at the URL https://10.10.20.74/lib/. This address has a backup file which can be downloaded without any authentication. | ||
| CVE-2022-44356 | Hig | 0.49 | 7.5 | 0.03 | Nov 29, 2022 | WAVLINK Quantum D4G (WL-WN531G3) running firmware versions M31G3.V5030.201204 and M31G3.V5030.200325 has an access control issue which allows unauthenticated attackers to download configuration data and log files. | ||
| CVE-2022-3691 | Hig | 0.49 | 7.5 | 0.01 | Nov 21, 2022 | The DeepL Pro API translation plugin WordPress plugin before 1.7.5 discloses sensitive information (including the DeepL API key) in files that are publicly accessible to an external, unauthenticated visitor. | ||
| CVE-2022-44583 | Hig | 0.49 | 7.5 | 0.01 | Nov 18, 2022 | Unauth. Arbitrary File Download vulnerability in WatchTowerHQ plugin <= 3.6.15 on WordPress. | ||
| CVE-2022-36552 | Hig | 0.49 | 7.5 | 0.01 | Aug 30, 2022 | Tenda AC6(AC1200) v5.0 Firmware v02.03.01.114 and below contains an issue in the component /cgi-bin/DownloadFlash which allows attackers to steal all data such as source code and system files via a crafted GET request. | ||
| CVE-2022-2357 | Hig | 0.49 | 7.5 | 0.01 | Aug 8, 2022 | The WSM Downloader WordPress plugin through 1.4.0 allows any visitor to use its remote file download feature to download any local files, including sensitive ones like wp-config.php. | ||
| CVE-2022-1585 | Hig | 0.49 | 7.5 | 0.01 | Aug 1, 2022 | The Project Source Code Download WordPress plugin through 1.0.0 does not protect its backup generation and download functionalities, which may allow any visitors on the site to download the entire site, including sensitive files like wp-config.php. | ||
| CVE-2021-40150 | Hig | 0.49 | 7.5 | 0.04 | Jul 17, 2022 | The web server of the E1 Zoom camera through 3.0.0.716 discloses its configuration via the /conf/ directory that is mapped to a publicly accessible path. In this way an attacker can download the entire NGINX/FastCGI configurations by querying the /conf/nginx.conf or… | ||
| CVE-2022-29720 | Hig | 0.49 | 7.5 | 0.01 | May 26, 2022 | 74cmsSE v3.5.1 was discovered to contain an arbitrary file read vulnerability via the component \index\controller\Download.php. | ||
| CVE-2022-28462 | Hig | 0.49 | 7.5 | 0.01 | May 5, 2022 | novel-plus 3.6.0 suffers from an Arbitrary file reading vulnerability. | ||
| CVE-2022-0656 | Hig | 0.49 | 7.5 | 0.08 | Apr 25, 2022 | The Web To Print Shop : uDraw WordPress plugin before 3.3.3 does not validate the url parameter in its udraw_convert_url_to_base64 AJAX action (available to both unauthenticated and authenticated users) before using it in the file_get_contents function and returning its content… | ||
| CVE-2022-28002 | Hig | 0.49 | 7.5 | 0.02 | Apr 8, 2022 | Movie Seat Reservation v1 was discovered to contain an unauthenticated file disclosure vulnerability via /index.php?page=home. | ||
| CVE-2022-26271 | Hig | 0.49 | 7.5 | 0.05 | Mar 28, 2022 | 74cmsSE v3.4.1 was discovered to contain an arbitrary file read vulnerability via the $url parameter at \index\controller\Download.php. | ||
| CVE-2022-23377 | Hig | 0.49 | 7.5 | 0.02 | Mar 1, 2022 | Archeevo below 5.0 is affected by local file inclusion through file=~/web.config to allow an attacker to retrieve local files. | ||
| CVE-2022-25104 | Hig | 0.49 | 7.5 | 0.01 | Feb 24, 2022 | HorizontCMS v1.0.0-beta.2 was discovered to contain an arbitrary file download vulnerability via the component /admin/file-manager/. | ||
| CVE-2022-21236 | Hig | 0.49 | 7.5 | 0.02 | Jan 28, 2022 | An information disclosure vulnerability exists due to a web server misconfiguration in the Reolink RLC-410W v3.0.0.136_20121102. A specially-crafted HTTP request can lead to a disclosure of sensitive information. An attacker can send an HTTP request to trigger this vulnerability. | ||
| CVE-2021-44315 | Hig | 0.49 | 7.5 | 0.02 | Dec 16, 2021 | In Bus Pass Management System v1.0, Directory Listing/Browsing is enabled on the web server which allows an attacker to view the sensitive files of the application, for example: Any file which contains sensitive information of the user or server. | ||
| CVE-2021-41573 | Hig | 0.49 | 7.5 | 0.01 | Sep 29, 2021 | Hitachi Content Platform Anywhere (HCP-AW) 4.4.5 and later allows information disclosure. If authenticated user creates a link to a file or folder while the system was running version 4.3.x or earlier and then shares the link and then later deletes the file or folder without… |
- risk 0.49cvss 7.5epss 0.01
Easy Images v2.0 was discovered to contain an arbitrary file download vulnerability via the component /application/down.php. This vulnerability is exploited via a crafted GET request.
- risk 0.49cvss 7.5epss 0.01
The Wholesale Market for WooCommerce WordPress plugin before 1.0.7 does not have authorisation check, as well as does not validate user input used to generate system path, allowing unauthenticated attackers to download arbitrary file from the server.
- risk 0.49cvss 7.5epss 0.01
The web portal of Dragino Lora LG01 18ed40 IoT v4.3.4 has the directory listing at the URL https://10.10.20.74/lib/. This address has a backup file which can be downloaded without any authentication.
- risk 0.49cvss 7.5epss 0.03
WAVLINK Quantum D4G (WL-WN531G3) running firmware versions M31G3.V5030.201204 and M31G3.V5030.200325 has an access control issue which allows unauthenticated attackers to download configuration data and log files.
- risk 0.49cvss 7.5epss 0.01
The DeepL Pro API translation plugin WordPress plugin before 1.7.5 discloses sensitive information (including the DeepL API key) in files that are publicly accessible to an external, unauthenticated visitor.
- risk 0.49cvss 7.5epss 0.01
Unauth. Arbitrary File Download vulnerability in WatchTowerHQ plugin <= 3.6.15 on WordPress.
- risk 0.49cvss 7.5epss 0.01
Tenda AC6(AC1200) v5.0 Firmware v02.03.01.114 and below contains an issue in the component /cgi-bin/DownloadFlash which allows attackers to steal all data such as source code and system files via a crafted GET request.
- risk 0.49cvss 7.5epss 0.01
The WSM Downloader WordPress plugin through 1.4.0 allows any visitor to use its remote file download feature to download any local files, including sensitive ones like wp-config.php.
- risk 0.49cvss 7.5epss 0.01
The Project Source Code Download WordPress plugin through 1.0.0 does not protect its backup generation and download functionalities, which may allow any visitors on the site to download the entire site, including sensitive files like wp-config.php.
- risk 0.49cvss 7.5epss 0.04
The web server of the E1 Zoom camera through 3.0.0.716 discloses its configuration via the /conf/ directory that is mapped to a publicly accessible path. In this way an attacker can download the entire NGINX/FastCGI configurations by querying the /conf/nginx.conf or…
- risk 0.49cvss 7.5epss 0.01
74cmsSE v3.5.1 was discovered to contain an arbitrary file read vulnerability via the component \index\controller\Download.php.
- risk 0.49cvss 7.5epss 0.01
novel-plus 3.6.0 suffers from an Arbitrary file reading vulnerability.
- risk 0.49cvss 7.5epss 0.08
The Web To Print Shop : uDraw WordPress plugin before 3.3.3 does not validate the url parameter in its udraw_convert_url_to_base64 AJAX action (available to both unauthenticated and authenticated users) before using it in the file_get_contents function and returning its content…
- risk 0.49cvss 7.5epss 0.02
Movie Seat Reservation v1 was discovered to contain an unauthenticated file disclosure vulnerability via /index.php?page=home.
- risk 0.49cvss 7.5epss 0.05
74cmsSE v3.4.1 was discovered to contain an arbitrary file read vulnerability via the $url parameter at \index\controller\Download.php.
- risk 0.49cvss 7.5epss 0.02
Archeevo below 5.0 is affected by local file inclusion through file=~/web.config to allow an attacker to retrieve local files.
- risk 0.49cvss 7.5epss 0.01
HorizontCMS v1.0.0-beta.2 was discovered to contain an arbitrary file download vulnerability via the component /admin/file-manager/.
- risk 0.49cvss 7.5epss 0.02
An information disclosure vulnerability exists due to a web server misconfiguration in the Reolink RLC-410W v3.0.0.136_20121102. A specially-crafted HTTP request can lead to a disclosure of sensitive information. An attacker can send an HTTP request to trigger this vulnerability.
- risk 0.49cvss 7.5epss 0.02
In Bus Pass Management System v1.0, Directory Listing/Browsing is enabled on the web server which allows an attacker to view the sensitive files of the application, for example: Any file which contains sensitive information of the user or server.
- risk 0.49cvss 7.5epss 0.01
Hitachi Content Platform Anywhere (HCP-AW) 4.4.5 and later allows information disclosure. If authenticated user creates a link to a file or folder while the system was running version 4.3.x or earlier and then shares the link and then later deletes the file or folder without…