Fallos del tipo CWE-22

5928 resultados

Travessia de diretório (path traversal)

A aplicação constrói caminhos de arquivo a partir de entrada do usuário sem validar adequadamente sequências como '../' ou símbolos absolutos, permitindo que um atacante acesse arquivos fora do diretório permitido. Isso expõe dados sensíveis ou permite execução não autorizada de operações no sistema de arquivos.

Ejemplo

Um sistema web que serve documentos de um diretório específico recebe a requisição 'GET /doc?file=../../etc/passwd'. Se não validar a entrada, o código resolve o caminho para fora do diretório restrito e vaza o arquivo de senhas do sistema.

Cómo mitigar

Valide caminhos usando listas brancas de nomes de arquivo permitidos, normalize caminhos (remover '../' e símbolos), use APIs que isolem automaticamente operações em diretório base (ex: chroot, sandbox), e evite concatenar entrada direta em construtores de caminhos. Teste com payloads comuns de path traversal em testes de segurança.

CVE-2023-3698HIGHA Command injection vulnerability was found on Printer service of ADMEPSS 0.6%CVE-2025-9079HIGHAdmin RCE via prepackaged plugins by way of misconfigured imports directoryEPSS 0.6%CVE-2024-32869MEDIUMHono vulnerable to Restricted Directory Traversal in serveStatic with denoEPSS 0.6%CVE-2026-3051MEDIUMDataLinkDC dinky Project Name GitRepository.java getProjectDir path traversalEPSS 0.6%CVE-2016-20081HIGHWordPress Plugin HB Audio Gallery Lite 1.0.0 Path Traversal File DownloadEPSS 0.6%CVE-2017-20250HIGHWordPress Plugin Mac Photo Gallery 3.0 Arbitrary File DownloadEPSS 0.6%CVE-2023-38708MEDIUMPimcore Path Traversal Vulnerability in AssetController:importServerFilesActionEPSS 0.6%CVE-2025-65418HIGHdocuFORM Managed Print Service Client 11.11c is vulnerable to a directory traversal allowing attackers to read arbitrary files via crafted uEPSS 0.6%CVE-2025-29846HIGHA vulnerability in portenable cgi allows remote authenticated users to get the status of installed packages.EPSS 0.6%CVE-2017-20248HIGHWordPress Plugin Apptha Slider Gallery 1.0 Path Traversal File DownloadEPSS 0.6%CVE-2018-25326HIGHGoogle Drive for WordPress 2.2 Path Traversal RCE via gdrive-ajaxs.phpEPSS 0.6%CVE-2026-36767CRITICALA path traversal vulnerability in the /content/images/add endpoint of shopizer v3.2.5 allows attackers write arbitrary files to any writeablEPSS 0.6%CVE-2026-56445HIGHpydicom pynetdicom Library Path TraversalEPSS 0.6%CVE-2026-1921MEDIUMLoco Translate <= 2.8.2 - Authenticated (Translator+) Path Traversal to Limited File Read via 'ref' ParameterEPSS 0.6%CVE-2022-20725MEDIUMCisco IOx Application Hosting Environment VulnerabilitiesEPSS 0.6%CVE-2014-125068MEDIUMsaxman maps-js-icoads http-server.js path traversalEPSS 0.6%CVE-2020-37077MEDIUMBooked Scheduler 2.7.7 - Authenticated Directory TraversalEPSS 0.6%CVE-2026-25116HIGHRuntipi vulnerable to unauthenticated docker-compose.yml Overwrite via Path TraversalEPSS 0.6%CVE-2024-54453HIGHAn issue was discovered in Kurmi Provisioning Suite before 7.9.0.35, 7.10.x through 7.10.0.18, and 7.11.x through 7.11.0.15. A path traversaEPSS 0.6%CVE-2025-14520MEDIUMbaowzh hfly delfile path traversalEPSS 0.6%