Fallos del tipo CWE-22

5888 resultados

Travessia de diretório (path traversal)

A aplicação constrói caminhos de arquivo a partir de entrada do usuário sem validar adequadamente sequências como '../' ou símbolos absolutos, permitindo que um atacante acesse arquivos fora do diretório permitido. Isso expõe dados sensíveis ou permite execução não autorizada de operações no sistema de arquivos.

Ejemplo

Um sistema web que serve documentos de um diretório específico recebe a requisição 'GET /doc?file=../../etc/passwd'. Se não validar a entrada, o código resolve o caminho para fora do diretório restrito e vaza o arquivo de senhas do sistema.

Cómo mitigar

Valide caminhos usando listas brancas de nomes de arquivo permitidos, normalize caminhos (remover '../' e símbolos), use APIs que isolem automaticamente operações em diretório base (ex: chroot, sandbox), e evite concatenar entrada direta em construtores de caminhos. Teste com payloads comuns de path traversal em testes de segurança.

CVE-2026-16078MEDIUMWCPOS <= 1.9.8 - Authenticated (Shop Manager+) Path Traversal to Arbitrary File Read via 'type' ParameterEPSS 0.9%CVE-2024-2294MEDIUMBackuply – Backup, Restore, Migrate and Clone <= 1.2.7 - Authenticated (Admin+) Directory TraversalEPSS 0.9%CVE-2025-10488HIGHDirectorist: AI-Powered Business Directory Plugin with Classified Ads Listings <= 8.4.8 - Authenticated (Subscriber+) Arbitrary File MoveEPSS 0.9%CVE-2024-39399HIGH[Paris] Path Traversal lead to local file readEPSS 0.9%CVE-2026-34790HIGHEndian Firewall /cgi-bin/backup.cgi remove ARCHIVE Directory TraversalEPSS 0.9%CVE-2026-85199HIGHEclipse aeriOS Self-orchestrator versions prior to 1.2.1 contain a path traversal vulnerability in the REST API. User-controlled identifiersEPSS 0.9%CVE-2026-32140CRITICALDataease: Redshift JDBC RCE BypassEPSS 0.9%CVE-2023-34238MEDIUM Local File Inclusion vulnerability in GatsbyEPSS 0.9%CVE-2021-42022—A vulnerability has been identified in SIMATIC eaSie PCS 7 Skill Package (All versions < V21.00 SP3). When downloading files, the affected sEPSS 0.9%CVE-2025-29420HIGHPerfreeBlog v4.0.11 has a directory traversal vulnerability in the getThemeFilesByName function.EPSS 0.9%CVE-2024-8769CRITICALArbitrary File Deletion via Relative Path Traversal in aimhubio/aimEPSS 0.9%CVE-2025-54926HIGHCWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability exists that could cause remote code exeEPSS 0.9%CVE-2023-1191MEDIUMfastcms ZIP File TemplateController.java path traversalEPSS 0.9%CVE-2026-58015MEDIUMGlib: path traversal in glib/gio/gdbusauthmechanismsha1.c via keyring_lookup_entry and mechanism_client_data_receiveEPSS 0.9%CVE-2023-28382HIGHDirectory traversal vulnerability in ESS REC Agent Server Edition series allows an authenticated attacker to view or alter an arbitrary fileEPSS 0.9%CVE-2024-27946MEDIUMA vulnerability has been identified in RUGGEDCOM CROSSBOW (All versions < V5.5). Downloading files overwrites files with the same name in thEPSS 0.9%CVE-2023-28344HIGHAn issue was discovered in Faronics Insight 10.0.19045 on Windows. The Insight Teacher Console application allows unauthenticated attackers EPSS 0.9%CVE-2023-32676MEDIUMAutolab tar slip in Install Assessment functionality (`GHSL-2023-081`)EPSS 0.9%CVE-2026-34607HIGHEmlog: Path Traversal in emUnZip() allows arbitrary file write leading to RCEEPSS 0.9%CVE-2024-44825HIGHDirectory Traversal vulnerability in Centro de Tecnologia da Informaco Renato Archer InVesalius3 v3.1.99995 allows attackers to write arbitrEPSS 0.9%