Fallos del tipo CWE-22

5865 resultados

Travessia de diretório (path traversal)

A aplicação constrói caminhos de arquivo a partir de entrada do usuário sem validar adequadamente sequências como '../' ou símbolos absolutos, permitindo que um atacante acesse arquivos fora do diretório permitido. Isso expõe dados sensíveis ou permite execução não autorizada de operações no sistema de arquivos.

Ejemplo

Um sistema web que serve documentos de um diretório específico recebe a requisição 'GET /doc?file=../../etc/passwd'. Se não validar a entrada, o código resolve o caminho para fora do diretório restrito e vaza o arquivo de senhas do sistema.

Cómo mitigar

Valide caminhos usando listas brancas de nomes de arquivo permitidos, normalize caminhos (remover '../' e símbolos), use APIs que isolem automaticamente operações em diretório base (ex: chroot, sandbox), e evite concatenar entrada direta em construtores de caminhos. Teste com payloads comuns de path traversal em testes de segurança.

CVE-2023-29478CRITICALBiblioCraft before 2.4.6 does not sanitize path-traversal characters in filenames, allowing restricted write access to almost anywhere on thEPSS 1.7%CVE-2021-32532HIGHQSAN XEVO - Path TraversalEPSS 1.7%CVE-2021-39109HIGHThe renderWidgetResource resource in Atlasian Atlasboard before version 1.1.9 allows remote attackers to read arbitrary files via a path traEPSS 1.7%CVE-2021-32516HIGHQSAN Storage Manager - Path TraversalEPSS 1.7%CVE-2022-48483HIGH3CX before 18 Hotfix 1 build 18.0.3.461 on Windows allows unauthenticated remote attackers to read %WINDIR%\system32 files via /Electron/dowEPSS 1.7%CVE-2022-2926MEDIUMDownload Manager < 3.2.55 - Admin+ Arbitrary File/Folder Access via Path TraversalEPSS 1.7%CVE-2022-32199MEDIUMdb_convert.php in ScriptCase through 9.9.008 is vulnerable to Arbitrary File Deletion by an admin via a directory traversal sequence in the EPSS 1.7%CVE-2024-50329HIGHPath traversal in Ivanti Endpoint Manager before 2024 November Security Update or 2022 SU6 November Security Update allows a remote unauthenEPSS 1.7%CVE-2025-1743MEDIUMzyx0814 Pichome index.php path traversalEPSS 1.7%CVE-2020-7522—Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability exists in SFAPV9601 - APC Easy UPS On-Line SoftEPSS 1.7%CVE-2020-7521—Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability exists in SFAPV9601 - APC Easy UPS On-Line SoftEPSS 1.7%CVE-2019-7007HIGHAvaya Equinox Conferencing Management (iView) Directory Traversal VulnerabilityEPSS 1.7%CVE-2023-32309HIGHArbitrary file inclusion with the pymdowm-snippets extensionEPSS 1.7%CVE-2019-13157—nsGreen.dll in Naver Vaccine 2.1.4 allows remote attackers to overwrite arbitary files via directory traversal sequences in a filename withiEPSS 1.7%CVE-2015-10134HIGHSimple Backup <= 2.7.10 - Arbitrary File Download via Path TraversalEPSS 1.7%CVE-2022-39296HIGHPath traversal in MelisAssetManagerEPSS 1.7%CVE-2022-37866HIGHApache Ivy allows path traversal in the presence of a malicious repositoryEPSS 1.7%CVE-2018-16479—Path traversal vulnerability in http-live-simulator <1.0.7 causes unauthorized access to arbitrary files on disk by appending extra slashes EPSS 1.7%CVE-2021-38452HIGHMoxa MXview Network Management SoftwareEPSS 1.7%CVE-2023-27067HIGHDirectory Traversal vulnerability in Sitecore Experience Platform through 10.2 allows remote attackers to download arbitrary files via craftEPSS 1.6%