Fallos del tipo CWE-22

5865 resultados

Travessia de diretório (path traversal)

A aplicação constrói caminhos de arquivo a partir de entrada do usuário sem validar adequadamente sequências como '../' ou símbolos absolutos, permitindo que um atacante acesse arquivos fora do diretório permitido. Isso expõe dados sensíveis ou permite execução não autorizada de operações no sistema de arquivos.

Ejemplo

Um sistema web que serve documentos de um diretório específico recebe a requisição 'GET /doc?file=../../etc/passwd'. Se não validar a entrada, o código resolve o caminho para fora do diretório restrito e vaza o arquivo de senhas do sistema.

Cómo mitigar

Valide caminhos usando listas brancas de nomes de arquivo permitidos, normalize caminhos (remover '../' e símbolos), use APIs que isolem automaticamente operações em diretório base (ex: chroot, sandbox), e evite concatenar entrada direta em construtores de caminhos. Teste com payloads comuns de path traversal em testes de segurança.

CVE-2023-52333CRITICALAllegra saveFile Directory Traversal Remote Code Execution VulnerabilityEPSS 1.9%CVE-2018-4861—A vulnerability has been identified in SCALANCE M875 (All versions). An authenticated remote attacker with access to the web interface (443/EPSS 1.9%CVE-2021-28205MEDIUMASUS BMC's firmware: path traversal - Delete SOL video file functionEPSS 1.9%CVE-2021-28208MEDIUMASUS BMC's firmware: path traversal - Get video file functionEPSS 1.9%CVE-2021-28206MEDIUMASUS BMC's firmware: path traversal - Record video file functionEPSS 1.9%CVE-2021-28209MEDIUMASUS BMC's firmware: path traversal - Delete video file functionEPSS 1.9%CVE-2021-28207MEDIUMASUS BMC's firmware: path traversal - Get Help file functionEPSS 1.9%CVE-2022-26835MEDIUMOn F5 BIG-IP 16.1.x versions prior to 16.1.2.2, 15.1.x versions prior to 15.1.5.1, 14.1.x versions prior to 14.1.4.6, 13.1.x versions prior EPSS 1.9%CVE-2020-6974—Honeywell Notifier Web Server (NWS) Version 3.50 is vulnerable to a path traversal attack, which allows an attacker to bypass access to restEPSS 1.9%CVE-2022-39058HIGHChanging Information Technology Inc. RAVA certificate validation system - Path TraversalEPSS 1.9%CVE-2021-24363—Photo Gallery < 1.5.75 - File Upload Path TraversalEPSS 1.9%CVE-2022-1000HIGHPath Traversal in prasathmani/tinyfilemanagerEPSS 1.9%CVE-2022-37865CRITICALApache Ivy allows creating/overwriting any file on the systemEPSS 1.9%CVE-2025-11466MEDIUMAllegra DatabaseBackupBL Directory Traversal Information Disclosure VulnerabilityEPSS 1.9%CVE-2022-41154HIGHA directory traversal vulnerability exists in the m2m DELETE_FILE cmd functionality of Siretta QUARTZ-GOLD G5.0.1.5-210720-141020. A specialEPSS 1.9%CVE-2021-21886MEDIUMA directory traversal vulnerability exists in the Web Manager FSBrowsePage functionality of Lantronix PremierWave 2050 8.9.0.0R4. A speciallEPSS 1.9%CVE-2024-53586MEDIUMAn issue in the relPath parameter of WebFileSys version 2.31.0 allows attackers to perform directory traversal via a crafted HTTP request. BEPSS 1.9%CVE-2020-15239LOWDirectory Traversal in xmpp-http-uploadEPSS 1.9%CVE-2024-32258HIGHThe network server of fceux 2.7.0 has a path traversal vulnerability, allowing attackers to overwrite any files on the server without authenEPSS 1.9%CVE-2024-3571MEDIUMPath Traversal in langchain-ai/langchainEPSS 1.9%