Fallos del tipo CWE-22

5926 resultados

Travessia de diretório (path traversal)

A aplicação constrói caminhos de arquivo a partir de entrada do usuário sem validar adequadamente sequências como '../' ou símbolos absolutos, permitindo que um atacante acesse arquivos fora do diretório permitido. Isso expõe dados sensíveis ou permite execução não autorizada de operações no sistema de arquivos.

Ejemplo

Um sistema web que serve documentos de um diretório específico recebe a requisição 'GET /doc?file=../../etc/passwd'. Se não validar a entrada, o código resolve o caminho para fora do diretório restrito e vaza o arquivo de senhas do sistema.

Cómo mitigar

Valide caminhos usando listas brancas de nomes de arquivo permitidos, normalize caminhos (remover '../' e símbolos), use APIs que isolem automaticamente operações em diretório base (ex: chroot, sandbox), e evite concatenar entrada direta em construtores de caminhos. Teste com payloads comuns de path traversal em testes de segurança.

CVE-2024-57549HIGHCMSimple 5.16 allows the user to read cms source code through manipulation of the file name in the file parameter of a GET request.EPSS 0.7%CVE-2026-17266MEDIUMIBM i is Affected By Multiple Vulnerabilities in Navigator for iEPSS 0.7%CVE-2026-17173MEDIUMIBM Db2 Mirror for i is affected by multiple vulnerabilitiesEPSS 0.7%CVE-2022-4878MEDIUMJATOS ZIP ZipUtil.java ZipUtil path traversalEPSS 0.7%CVE-2025-59711HIGHAn issue was discovered in Biztalk360 before 11.5. Because of mishandling of user-provided input in an upload mechanism, an authenticated atEPSS 0.7%CVE-2026-68062MEDIUMSKYSEA Client View and SKYMEC IT Manager contain a path traversal vulnerability. If this vulnerability is exploited, an attacker who can logEPSS 0.7%CVE-2025-12638HIGHPath Traversal Vulnerability in keras-team/keras via Tar Archive Extraction in keras.utils.get_file()EPSS 0.7%CVE-2026-9195CRITICALCross-site scripting in Progress MarkLogic Server Query ConsoleEPSS 0.7%CVE-2025-41428MEDIUMImproper limitation of a pathname to a restricted directory ('Path Traversal') issue exists in TimeWorks 10.0 to 10.3. If exploited, arbitraEPSS 0.7%CVE-2024-48224HIGHFunadmin v5.0.2 has an arbitrary file read vulnerability in /curd/index/editfile.EPSS 0.7%CVE-2024-10585MEDIUMInfiniteWP Client <= 1.13.0 - Unauthenticated Limited Directory Traversal to Arbitrary .txt File ReadingEPSS 0.7%CVE-2026-25525MEDIUMOpenMage LTS has Path Traversal Filter Bypass in Dataflow ModuleEPSS 0.7%CVE-2025-22152CRITICALImproper Path Validation Enables Path Traversal in Multiple Components in AtheosEPSS 0.7%CVE-2025-69770CRITICALA zip slip vulnerability in the /DesignTools/SkinList.aspx endpoint of MojoPortal CMS v2.9.0.1 allows attackers to execute arbitrary commandEPSS 0.7%CVE-2024-32023MEDIUMKohya_ss vulnerable to path injection in `common_gui.py` `find_and_replace` function (`GHSL-2024-024`)EPSS 0.7%CVE-2025-65077HIGHRelative path traversal vulnerability in Embedded Solutions FrameworkEPSS 0.7%CVE-2021-47977HIGHWordPress Anti-Malware Security Bruteforce Firewall <= 4.20.72 Directory TraversalEPSS 0.7%CVE-2026-45727HIGHCloakBrowser: Unauthenticated path traversal via fingerprint parameter in cloakserve leads to arbitrary directory deletionEPSS 0.7%CVE-2026-41058HIGHAVideo has an incomplete fix for CVE-2026-33293 (Path Traversal) in AVideoEPSS 0.7%CVE-2026-63312HIGHNLTK StreamBackedCorpusView Bypasses pathsec.ENFORCE Arbitrary File ReadEPSS 0.7%