Fallos del tipo CWE-22

5906 resultados

Travessia de diretório (path traversal)

A aplicação constrói caminhos de arquivo a partir de entrada do usuário sem validar adequadamente sequências como '../' ou símbolos absolutos, permitindo que um atacante acesse arquivos fora do diretório permitido. Isso expõe dados sensíveis ou permite execução não autorizada de operações no sistema de arquivos.

Ejemplo

Um sistema web que serve documentos de um diretório específico recebe a requisição 'GET /doc?file=../../etc/passwd'. Se não validar a entrada, o código resolve o caminho para fora do diretório restrito e vaza o arquivo de senhas do sistema.

Cómo mitigar

Valide caminhos usando listas brancas de nomes de arquivo permitidos, normalize caminhos (remover '../' e símbolos), use APIs que isolem automaticamente operações em diretório base (ex: chroot, sandbox), e evite concatenar entrada direta em construtores de caminhos. Teste com payloads comuns de path traversal em testes de segurança.

CVE-2024-55213MEDIUMDirectory Traversal vulnerability in dhtmlxFileExplorer v.8.4.6 allows a remote attacker to obtain sensitive information via the File ListinEPSS 0.8%CVE-2025-23343HIGHThe NVIDIA NVDebug tool contains a vulnerability that may allow an actor to write files to restricted components. A successful exploit of thEPSS 0.8%CVE-2025-34395HIGHBarracuda RMM < 2025.1.1 Service Center .NET Remoting Path Traversal RCEEPSS 0.8%CVE-2022-43748MEDIUMImproper limitation of a pathname to a restricted directory ('Path Traversal') vulnerability in file operation management in Synology PrestoEPSS 0.8%CVE-2025-65897HIGHzdh_web is a data collection, processing, monitoring, scheduling, and management platform. In zdh_web thru 5.6.17, insufficient validation oEPSS 0.8%CVE-2023-42488HIGH EisBaer Scada - CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')EPSS 0.8%CVE-2024-9032MEDIUMSourceCodester Simple Forum-Discussion System index.php path traversalEPSS 0.8%CVE-2023-40587MEDIUMPyramid static view path traversal up one directoryEPSS 0.8%CVE-2026-2672MEDIUMTsinghua Unigroup Electronic Archives System downLoad download path traversalEPSS 0.8%CVE-2026-0963CRITICALImproper Limitation of a Pathname to a Restricted Directory ('Path Traversal') in Crafty ControllerEPSS 0.8%CVE-2025-30841CRITICALWordPress Countdown & Clock plugin <=2.8.8 - Remote Code Execution (RCE) vulnerabilityEPSS 0.8%CVE-2026-11940HIGHtarfile extraction filter bypass allows escaping the destination directoryEPSS 0.8%CVE-2024-8706MEDIUMJFinalCMS com.cms.util.TemplateUtils update path traversalEPSS 0.7%CVE-2024-21799MEDIUMPath traversal for some Intel(R) Extension for Transformers software before version 1.5 may allow an authenticated user to potentially enablEPSS 0.7%CVE-2026-53486CRITICALdecompress: Archive extraction can create files and links outside the target directoryEPSS 0.7%CVE-2024-23182HIGHRelative path traversal vulnerability in a-blog cms Ver.3.1.x series versions prior to Ver.3.1.7, Ver.3.0.x series versions prior to Ver.3.0EPSS 0.7%CVE-2026-13347HIGHHide My WP Lite <= 1.3 - Unauthenticated Path Traversal to Arbitrary File Read via 'he_wrapper_js' ParameterEPSS 0.7%CVE-2023-29986MEDIUMspring-boot-actuator-logview 0.2.13 allows Directory Traversal to sibling directories via LogViewEndpoint.view.EPSS 0.7%CVE-2024-47820MEDIUMMarkUs vulnerable to Path TraversalEPSS 0.7%CVE-2026-52607MEDIUMA directory traversal vulnerability in reportico-web <= 8.1.0 allows remote attackers to expose or execute arbitrary php files on the web seEPSS 0.7%