Fallos del tipo CWE-22

5865 resultados

Travessia de diretório (path traversal)

A aplicação constrói caminhos de arquivo a partir de entrada do usuário sem validar adequadamente sequências como '../' ou símbolos absolutos, permitindo que um atacante acesse arquivos fora do diretório permitido. Isso expõe dados sensíveis ou permite execução não autorizada de operações no sistema de arquivos.

Ejemplo

Um sistema web que serve documentos de um diretório específico recebe a requisição 'GET /doc?file=../../etc/passwd'. Se não validar a entrada, o código resolve o caminho para fora do diretório restrito e vaza o arquivo de senhas do sistema.

Cómo mitigar

Valide caminhos usando listas brancas de nomes de arquivo permitidos, normalize caminhos (remover '../' e símbolos), use APIs que isolem automaticamente operações em diretório base (ex: chroot, sandbox), e evite concatenar entrada direta em construtores de caminhos. Teste com payloads comuns de path traversal em testes de segurança.

CVE-2020-5366HIGHDell EMC iDRAC9 versions prior to 4.20.20.20 contain a Path Traversal Vulnerability. A remote authenticated malicious user with low privilegEPSS 1.8%CVE-2023-27603CRITICALApache Linkis Mangaer module engineConn material upload exists Zip Slip issueEPSS 1.8%CVE-2025-67506CRITICALPipesHub Vulnerable to Path Traversal through Unauthenticated Arbitrary File UploadEPSS 1.8%CVE-2024-27977HIGHA Path Traversal vulnerability in web component of Ivanti Avalanche before 6.4.3 allows a remote authenticated attacker to delete arbitrary EPSS 1.8%CVE-2026-9506HIGHPath Traversal Vulnerability in BagistoEPSS 1.8%CVE-2026-50776HIGHDirectory Traversal vulnerability in Pronis Loisirs Billetterie CSE - < 04/2026 allows a remote attacker to obtain sensitive information andEPSS 1.8%CVE-2021-28172HIGHVangene deltaFlow E-platform - Path TraversalEPSS 1.8%CVE-2023-6265MEDIUMDrayTek Vigor2960 mainfunction.cgi dumpSyslog 'option' directory traversalEPSS 1.8%CVE-2022-39033CRITICALSmart eVision - Path Traversal -1EPSS 1.8%CVE-2017-16091—xtalk helps your browser talk to nodex, a simple web framework. xtalk is vulnerable to a directory traversal issue, giving an attacker accesEPSS 1.8%CVE-2026-34909CRITICALA malicious actor with access to the network could exploit a Path Traversal vulnerability found in UniFi OS devices to access files on the uEPSS 1.8%KEVCVE-2018-3712—serve node module before 6.4.9 suffers from a Path Traversal vulnerability due to not handling %2e (.) and %2f (/) and allowing them in pathEPSS 1.8%CVE-2019-3556—HHVM supports the use of an "admin" server which accepts administrative requests over HTTP. One of those request handlers, dump-pcre-cache, EPSS 1.8%CVE-2023-22887—Apache Airflow path traversal by authenticated userEPSS 1.8%CVE-2017-7424—A Path Traversal (CWE-22) vulnerability in esfadmingui in Micro Focus Enterprise Developer and Enterprise Server 2.3, 2.3 Update 1 before HoEPSS 1.8%CVE-2019-3737HIGHDell EMC Avamar Security Update for ADMe Web UI VulnerabilityEPSS 1.8%CVE-2024-11303HIGHPath TraversalEPSS 1.8%CVE-2020-26295HIGHCMS Editor code executionEPSS 1.8%CVE-2021-35962HIGHTAIWAN SECOM CO., LTD., Door Access Control and Personnel Attendance Management system - Path TraversalEPSS 1.8%CVE-2026-25055HIGHn8n Arbitrary File Write on Remote Systems via SSH NodeEPSS 1.8%