Fallos del tipo CWE-22

5891 resultados

Travessia de diretório (path traversal)

A aplicação constrói caminhos de arquivo a partir de entrada do usuário sem validar adequadamente sequências como '../' ou símbolos absolutos, permitindo que um atacante acesse arquivos fora do diretório permitido. Isso expõe dados sensíveis ou permite execução não autorizada de operações no sistema de arquivos.

Ejemplo

Um sistema web que serve documentos de um diretório específico recebe a requisição 'GET /doc?file=../../etc/passwd'. Se não validar a entrada, o código resolve o caminho para fora do diretório restrito e vaza o arquivo de senhas do sistema.

Cómo mitigar

Valide caminhos usando listas brancas de nomes de arquivo permitidos, normalize caminhos (remover '../' e símbolos), use APIs que isolem automaticamente operações em diretório base (ex: chroot, sandbox), e evite concatenar entrada direta em construtores de caminhos. Teste com payloads comuns de path traversal em testes de segurança.

CVE-2023-30268CRITICALCLTPHP <=6.0 is vulnerable to Improper Input Validation.EPSS 0.8%CVE-2023-41877HIGHGeoServer log file path traversal vulnerabilityEPSS 0.8%CVE-2024-12850MEDIUMDatabase Backup and check Tables Automated With Scheduler 2024 <= 2.32 - Authenticated (Admin+) Arbitrary File ReadEPSS 0.8%CVE-2026-69110CRITICALOpenCode Studio < 2.4.4 Unauthenticated File Read via /api/tmp and /api/musicEPSS 0.8%CVE-2026-41448CRITICALAdGuard Home Authentication Bypass via Path Traversal in Admin-Token CookieEPSS 0.8%CVE-2025-8343MEDIUMopenviglet shio ShStaticFileAPI.java shStaticFilePreUpload path traversalEPSS 0.8%CVE-2024-10948MEDIUMArbitrary File Read via Upload Function in binary-husky/gpt_academicEPSS 0.8%CVE-2026-74235MEDIUMGFI Exinda AI / ClearView < 7.6.5 Path Traversal via Configuration Download HandlerEPSS 0.8%CVE-2024-54452MEDIUMAn issue was discovered in Kurmi Provisioning Suite before 7.9.0.35 and 7.10.x through 7.10.0.18. A Directory Traversal and Local File IncluEPSS 0.8%CVE-2020-12509HIGHs::can moni::tools prone to path traversal in camera-file moduleEPSS 0.8%CVE-2024-22232HIGHSpecially crafted url can be created which leads to a directory traversal in the salt file serverEPSS 0.8%CVE-2020-12508HIGHs::can moni::tools prone to path traversal in image-relocator moduleEPSS 0.8%CVE-2024-46646MEDIUMeNMS up to 4.7.1 is vulnerable to Directory Traversal via /download/file.EPSS 0.8%CVE-2024-8163MEDIUMChengdu Everbrite Network Technology BeikeShop files destroyFiles path traversalEPSS 0.8%CVE-2025-50348HIGHPHPGurukul Pre-School Enrollment System Project V1.0 is vulnerable to Directory Traversal in update-class-pic.php.EPSS 0.8%CVE-2026-28406HIGHkaniko has tar archive path traversal in build context extraction allows writing files outside destination directoryEPSS 0.8%CVE-2026-72713HIGHXAgent Path Traversal Arbitrary File Read via /workspace/fileEPSS 0.8%CVE-2026-57296HIGHJenkins External Workspace Manager Plugin 1.3.2 and earlier does not reject path traversal sequences in the custom workspace path provided tEPSS 0.8%CVE-2024-5550MEDIUMExposure of Sensitive Information via Arbitrary System Path Lookup in h2oai/h2o-3EPSS 0.8%CVE-2022-23512HIGHMetersphere is vulnerable to Path Injection.EPSS 0.8%