Fallos del tipo CWE-22

5869 resultados

Travessia de diretório (path traversal)

A aplicação constrói caminhos de arquivo a partir de entrada do usuário sem validar adequadamente sequências como '../' ou símbolos absolutos, permitindo que um atacante acesse arquivos fora do diretório permitido. Isso expõe dados sensíveis ou permite execução não autorizada de operações no sistema de arquivos.

Ejemplo

Um sistema web que serve documentos de um diretório específico recebe a requisição 'GET /doc?file=../../etc/passwd'. Se não validar a entrada, o código resolve o caminho para fora do diretório restrito e vaza o arquivo de senhas do sistema.

Cómo mitigar

Valide caminhos usando listas brancas de nomes de arquivo permitidos, normalize caminhos (remover '../' e símbolos), use APIs que isolem automaticamente operações em diretório base (ex: chroot, sandbox), e evite concatenar entrada direta em construtores de caminhos. Teste com payloads comuns de path traversal em testes de segurança.

CVE-2021-32746MEDIUMPossible path traversal by use of the `doc` moduleEPSS 1.3%CVE-2022-39037HIGHFLOWRING Agentflow BPM - Path TraversalEPSS 1.3%CVE-2020-18331CRITICALDirectory traversal vulnerability in ChinaMobile PLC Wireless Router model GPN2.4P21-C-CN running the firmware version W2000EN-01(hardware pEPSS 1.3%CVE-2022-47526CRITICALFox-IT DataDiode (aka Fox DataDiode) 3.4.3 suffers from a path traversal vulnerability with resultant arbitrary writing of files. A remote aEPSS 1.3%CVE-2023-27588HIGHUnauthenticated path traversal vulnerability in Hasura GraphQL EngineEPSS 1.3%CVE-2010-10011MEDIUMAcritum Femitter Server path traversalEPSS 1.3%CVE-2024-0221CRITICALPhoto Gallery by 10Web - Mobile-Friendly Image Gallery <= 1.8.19 - Directory Traversal to Arbitrary File RenameEPSS 1.3%CVE-2023-35887MEDIUMApache MINA SSHD: Information disclosure bugs with RootedFilesystemEPSS 1.3%CVE-2026-2426MEDIUMWP-DownloadManager <= 1.69 - Authenticated (Administrator+) Path Traversal to Arbitrary File Deletion via 'file' ParameterEPSS 1.3%CVE-2023-28465HIGHThe package-decompression feature in HL7 (Health Level 7) FHIR Core Libraries before 5.6.106 allows attackers to copy arbitrary files to cerEPSS 1.3%CVE-2026-18274HIGHHeimdall Data Database Proxy uploadJar Directory Traversal Remote Code Execution VulnerabilityEPSS 1.3%CVE-2018-16478—A Path Traversal in simplehttpserver versions <=0.2.1 allows to list any file in another folder of web root.EPSS 1.3%CVE-2021-22804—A CWE-22: Improper Limitation of a Pathname to a Restricted Directory vulnerability exists that could cause disclosure of arbitrary files beEPSS 1.3%CVE-2023-40747HIGHDirectory traversal vulnerability exists in A.K.I Software's PMailServer/PMailServer2 products' CGIs included in Internal Simple Webserver. EPSS 1.3%CVE-2024-33502MEDIUMAn improper limitation of a pathname to a restricted directory ('path traversal') in Fortinet FortiManager, FortiAnalyzer versions 7.4.0 thrEPSS 1.3%CVE-2022-20822HIGHCisco Identity Services Engine Unauthorized File Access VulnerabilityEPSS 1.3%CVE-2023-42462HIGHFile deletion through document upload process in GLPIEPSS 1.3%CVE-2011-10009HIGHS40 CMS 0.4.2 Path TraversalEPSS 1.3%CVE-2026-53598HIGHPrompty: Arbitrary File Read via ${file:path} Reference ExpansionEPSS 1.3%CVE-2025-61666HIGHTraccar Unauthenticated Local File Inclusion on Windows - Leakage of Traccar Config FileEPSS 1.3%