Fallos del tipo CWE-22

5906 resultados

Travessia de diretório (path traversal)

A aplicação constrói caminhos de arquivo a partir de entrada do usuário sem validar adequadamente sequências como '../' ou símbolos absolutos, permitindo que um atacante acesse arquivos fora do diretório permitido. Isso expõe dados sensíveis ou permite execução não autorizada de operações no sistema de arquivos.

Ejemplo

Um sistema web que serve documentos de um diretório específico recebe a requisição 'GET /doc?file=../../etc/passwd'. Se não validar a entrada, o código resolve o caminho para fora do diretório restrito e vaza o arquivo de senhas do sistema.

Cómo mitigar

Valide caminhos usando listas brancas de nomes de arquivo permitidos, normalize caminhos (remover '../' e símbolos), use APIs que isolem automaticamente operações em diretório base (ex: chroot, sandbox), e evite concatenar entrada direta em construtores de caminhos. Teste com payloads comuns de path traversal em testes de segurança.

CVE-2026-52607MEDIUMA directory traversal vulnerability in reportico-web <= 8.1.0 allows remote attackers to expose or execute arbitrary php files on the web seEPSS 0.7%CVE-2025-53632HIGHChall-Manager's scenario decoding process does not check for zip slipsEPSS 0.7%CVE-2023-26101HIGHIn Progress Flowmon Packet Investigator before 12.1.0, a Flowmon user with access to Flowmon Packet Investigator could leverage a path-traveEPSS 0.7%CVE-2020-8144—The UniFi Video Server v3.9.3 and prior (for Windows 7/8/10 x64) web interface Firmware Update functionality, under certain circumstances, dEPSS 0.7%CVE-2023-27055HIGHAver Information Inc PTZApp2 v20.01044.48 allows attackers to access sensitive files via a crafted GET request.EPSS 0.7%CVE-2023-22772MEDIUMAuthenticated Path Traversal in ArubaOS Web-based Management Interface Allows for Arbitrary File DeletionEPSS 0.7%CVE-2026-86775HIGHknowns before 0.30.0 Path Traversal via Document APIEPSS 0.7%CVE-2023-31131HIGHArbitrary File Write when Extracting Tarballs in greenplum-dbEPSS 0.7%CVE-2005-10002MEDIUMalmosteffortless secure-files Plugin secure-files.php sf_downloads path traversalEPSS 0.7%CVE-2026-2419LOWWP-DownloadManager <= 1.69 - Authenticated (Administrator+) Path Traversal to Arbitrary File Read via 'download_path' ParameterEPSS 0.7%CVE-2024-52292HIGHCraft Allows Attackers to Read Arbitrary System FilesEPSS 0.7%CVE-2024-52054MEDIUMApplication Creation Path Traversal in Wowza Streaming EngineEPSS 0.7%CVE-2022-4885MEDIUMsviehb jefferson path traversalEPSS 0.7%CVE-2024-13920MEDIUMOrder Export & Order Import for WooCommerce <= 2.6.0 - Directory Traversal to Authenticated (Administrator+) Limited Arbitrary File Read via download_file FunctionEPSS 0.7%CVE-2023-0290MEDIUMRapid7 Velociraptor directory traversal in client ID parameter EPSS 0.7%CVE-2024-54259MEDIUMWordPress DELUCKS SEO plugin <= 2.7.0 - Arbitrary File Download vulnerabilityEPSS 0.7%CVE-2026-16137HIGHPath traversal via unsanitized upload filename leads to arbitrary file write in Progress ShareFile Storage Zones ControllerEPSS 0.7%CVE-2025-57644CRITICALAccela Automation Platform 22.2.3.0.230103 contains multiple vulnerabilities in the Test Script feature. An authenticated administrative useEPSS 0.7%CVE-2026-72602HIGHAsyncFuncAI deepwiki-open - Path TraversalEPSS 0.7%CVE-2021-47849HIGHMini Mouse 9.3.0 - Local File inclusion / Path TraversalEPSS 0.7%