Fallos del tipo CWE-22

5892 resultados

Travessia de diretório (path traversal)

A aplicação constrói caminhos de arquivo a partir de entrada do usuário sem validar adequadamente sequências como '../' ou símbolos absolutos, permitindo que um atacante acesse arquivos fora do diretório permitido. Isso expõe dados sensíveis ou permite execução não autorizada de operações no sistema de arquivos.

Ejemplo

Um sistema web que serve documentos de um diretório específico recebe a requisição 'GET /doc?file=../../etc/passwd'. Se não validar a entrada, o código resolve o caminho para fora do diretório restrito e vaza o arquivo de senhas do sistema.

Cómo mitigar

Valide caminhos usando listas brancas de nomes de arquivo permitidos, normalize caminhos (remover '../' e símbolos), use APIs que isolem automaticamente operações em diretório base (ex: chroot, sandbox), e evite concatenar entrada direta em construtores de caminhos. Teste com payloads comuns de path traversal em testes de segurança.

CVE-2018-25184MEDIUMSurreal ToDo 0.6.1.2 Local File Inclusion via index.phpEPSS 0.8%CVE-2023-26820HIGHsiteproxy v1.0 was discovered to contain a path traversal vulnerability via the component index.js.EPSS 0.8%CVE-2022-23447HIGHAn improper limitation of a pathname to a restricted directory ('Path Traversal') vulnerability [CWE-22] in FortiExtender management interfaEPSS 0.8%CVE-2023-34645HIGHjfinal CMS 5.1.0 has an arbitrary file read vulnerability.EPSS 0.8%CVE-2026-9102CRITICALPath Traversal in Altium Enterprise Server ComparisonService Allows Arbitrary File WriteEPSS 0.8%CVE-2024-36814MEDIUMAn arbitrary file read vulnerability in Adguard Home before v0.107.52 allows authenticated attackers to access arbitrary files as root on thEPSS 0.8%CVE-2024-41310HIGHAndServer 2.1.12 is vulnerable to Directory Traversal.EPSS 0.8%CVE-2022-47747HIGHkraken <= 0.1.4 has an arbitrary file read vulnerability via the component testfs.EPSS 0.8%CVE-2023-28163MEDIUMWhen downloading files through the Save As dialog on Windows with suggested filenames containing environment variable names, Windows would hEPSS 0.8%CVE-2023-46346HIGHIn the module "Product Catalog (CSV, Excel, XML) Export PRO" (exportproducts) in versions up to 4.1.1 from MyPrestaModules for PrestaShop, aEPSS 0.8%CVE-2024-24591HIGHA path traversal vulnerability in versions 1.4.0 to 1.14.1 of the client SDK of Allegro AI’s ClearML platform enables a maliciously uploadedEPSS 0.8%CVE-2026-40526HIGHVolmarg Personal Management System Path Traversal via get-file EndpointEPSS 0.8%CVE-2026-64679HIGHAtlantis: Path Traversal in Atlantis Workspace Handling Allows Out-of-Bounds Directory Deletion/CreationEPSS 0.8%CVE-2026-64824CRITICALHome Assistant Core < 2026.7.0 Symlink Path Traversal RCE via backup-restoreEPSS 0.8%CVE-2023-29200MEDIUMcontao/core-bundle has path traversal vulnerability in the file managerEPSS 0.8%CVE-2025-2193MEDIUMMRCMS org.marker.mushroom.controller.FileController delete.do delete path traversalEPSS 0.8%CVE-2024-8898MEDIUMPath Traversal in parisneo/lollms-webuiEPSS 0.8%CVE-2019-25352HIGHGenivia Crystal Live HTTP Server 6.01 - 'Crystal Live HTTP Server' Path TraversalEPSS 0.8%CVE-2024-54004MEDIUMJenkins Filesystem List Parameter Plugin 0.0.14 and earlier does not restrict the path used for the File system objects list Parameter, alloEPSS 0.8%CVE-2026-29220MEDIUMApache OFBiz: Low-Privilege LFI in Content ComponentEPSS 0.8%