Fallos del tipo CWE-22

5906 resultados

Travessia de diretório (path traversal)

A aplicação constrói caminhos de arquivo a partir de entrada do usuário sem validar adequadamente sequências como '../' ou símbolos absolutos, permitindo que um atacante acesse arquivos fora do diretório permitido. Isso expõe dados sensíveis ou permite execução não autorizada de operações no sistema de arquivos.

Ejemplo

Um sistema web que serve documentos de um diretório específico recebe a requisição 'GET /doc?file=../../etc/passwd'. Se não validar a entrada, o código resolve o caminho para fora do diretório restrito e vaza o arquivo de senhas do sistema.

Cómo mitigar

Valide caminhos usando listas brancas de nomes de arquivo permitidos, normalize caminhos (remover '../' e símbolos), use APIs que isolem automaticamente operações em diretório base (ex: chroot, sandbox), e evite concatenar entrada direta em construtores de caminhos. Teste com payloads comuns de path traversal em testes de segurança.

CVE-2018-25059LOWpastebinit server.go pasteHandler path traversalEPSS 0.8%CVE-2026-25161HIGHAlist vulnerable to Path Traversal in multiple file operation handlersEPSS 0.8%CVE-2025-26615CRITICALPath Traversal endpoint 'examples.php' parameter 'src' in WeGIAEPSS 0.8%CVE-2026-6321HIGHfast-uri vulnerable to path traversal via percent-encoded dot segmentsEPSS 0.8%CVE-2026-30278CRITICALAn arbitrary file overwrite vulnerability in FLY is FUN Aviation Navigation v35.33 allows attackers to overwrite critical internal files viaEPSS 0.8%CVE-2024-27575HIGHINOTEC Sicherheitstechnik WebServer CPS220/64 3.3.19 allows a remote attacker to read arbitrary files via absolute path traversal, such as wEPSS 0.8%CVE-2026-40491MEDIUMgdown Affected by Arbitrary File Write via Path Traversal in gdown.extractallEPSS 0.8%CVE-2025-6465MEDIUMPath traversal in image upload with preview overwriteEPSS 0.8%CVE-2025-1543MEDIUMiteachyou Dreamer CMS ueditor-1.4.3.3 path traversalEPSS 0.8%CVE-2023-6190CRITICALAuthenicated Path Traversal in İzmir Katip Çelebi UniversityEPSS 0.8%CVE-2024-53523HIGHJSFinder commit d70ab9bc5221e016c08cffaf0d9ac79646c90645 is vulnerable to Directory Traversal in the find_by_file function.EPSS 0.8%CVE-2026-95701MEDIUMMISP Path Traversal via Organization Name in Org-Statistics Logo CheckEPSS 0.8%CVE-2025-0818MEDIUMMultiple elFinder Plugins <= (Various Versions) - Directory Traversal to Arbitrary File DeletionEPSS 0.8%CVE-2026-75482HIGHSWE-agent Trajectory Inspector Path Traversal File DisclosureEPSS 0.8%CVE-2026-1311HIGHWorry Proof Backup <= 0.2.4 - Authenticated (Subscriber+) Path Traversal via Backup UploadEPSS 0.8%CVE-2023-28833LOWUnrestricted filenames for logo or favicon as admin in the theming settings in nextcloud serverEPSS 0.8%CVE-2026-75594HIGHKirby: Access to image files and limited access to JSON files outside of the site root via path traversal in the media handlingEPSS 0.8%CVE-2025-70796HIGHAn unauthenticated path traversal vulnerability exists in the web management interface of WTI (Wireless Technology, Inc.) version 3.5.0.r 20EPSS 0.8%CVE-2023-45382HIGHIn the module "SoNice Retour" (sonice_retour) up to version 2.1.0 from Common-Services for PrestaShop, a guest can download personal informaEPSS 0.8%CVE-2023-25804HIGHRoxy-WI vulnerable to Limited Path Traversal in name parameterEPSS 0.8%