Fallos del tipo CWE-22

5890 resultados

Travessia de diretório (path traversal)

A aplicação constrói caminhos de arquivo a partir de entrada do usuário sem validar adequadamente sequências como '../' ou símbolos absolutos, permitindo que um atacante acesse arquivos fora do diretório permitido. Isso expõe dados sensíveis ou permite execução não autorizada de operações no sistema de arquivos.

Ejemplo

Um sistema web que serve documentos de um diretório específico recebe a requisição 'GET /doc?file=../../etc/passwd'. Se não validar a entrada, o código resolve o caminho para fora do diretório restrito e vaza o arquivo de senhas do sistema.

Cómo mitigar

Valide caminhos usando listas brancas de nomes de arquivo permitidos, normalize caminhos (remover '../' e símbolos), use APIs que isolem automaticamente operações em diretório base (ex: chroot, sandbox), e evite concatenar entrada direta em construtores de caminhos. Teste com payloads comuns de path traversal em testes de segurança.

CVE-2024-31487MEDIUMA improper limitation of a pathname to a restricted directory ('path traversal') vulnerability in Fortinet FortiSandbox 4.4.0 through 4.4.4,EPSS 0.9%CVE-2025-6167MEDIUMthemanojdesai python-a2a api.py create_workflow path traversalEPSS 0.9%CVE-2024-13409HIGHPost Grid, Slider & Carousel Ultimate – with Shortcode, Gutenberg Block & Elementor Widget <= 1.6.10 - Authenticated (Contributor+) Local File Inclusion via post_type_ajax_handler()EPSS 0.9%CVE-2022-46154HIGHArbitrary file access in KodExplorerEPSS 0.9%CVE-2025-54141HIGHViewVC's standalone server exposes arbitrary server filesystem contentEPSS 0.9%CVE-2022-2554—Enable Media Replace < 4.0.0 - Admin+ Path TraversalEPSS 0.9%CVE-2025-70952HIGHpf4j before 20c2f80 has a path traversal vulnerability in the extract() function of Unzip.java, where improper handling of zip entry names cEPSS 0.9%CVE-2024-1560HIGHPath Traversal Vulnerability in mlflow/mlflowEPSS 0.9%CVE-2025-0973MEDIUMCmsEasy index.php backAll_action path traversalEPSS 0.9%CVE-2015-10043MEDIUMabreen Apollo path traversalEPSS 0.9%CVE-2023-41356MEDIUMWisdomGarden Tronclass ilearn - Path TraversalEPSS 0.9%CVE-2026-50877HIGHAn issue in Zhoros SuperBin v1.0.0 allows attackers to execute a directory traversal via supplying files with names containing traversal chaEPSS 0.9%CVE-2025-50735HIGHDirectory traversal vulnerability in NextChat thru 2.16.0 due to the WebDAV proxy failing to canonicalize or reject dot path segments in itsEPSS 0.9%CVE-2026-42305HIGHDulwich has an arbitrary file write via NTFS-hostile tree entries on WindowsEPSS 0.9%CVE-2026-58166HIGHOpenBMB ChatDev - Unauthenticated Path Traversal in Upload Handler Allows Arbitrary File Write and DeleteEPSS 0.9%CVE-2024-11010HIGHFileOrganizer <= 1.1.4 - Authenticated (Administrator+) Local JavaScript File InclusionEPSS 0.9%CVE-2026-16915HIGHIBM Db2 Mirror for i is affected by multiple vulnerabilitiesEPSS 0.9%CVE-2024-27768CRITICALUnitronics Unistream Unilogic – Versions prior to 1.35.227 CWE-22: 'Path Traversal'EPSS 0.9%CVE-2026-18554HIGHIBM Db2 Mirror for i is affected by multiple vulnerabilitiesEPSS 0.9%CVE-2024-33109CRITICALDirectory Traversal in the web interface of the Tiptel IP 286 with firmware version 2.61.13.10 allows attackers to overwrite arbitrary filesEPSS 0.9%