Fallos del tipo CWE-22

5866 resultados

Travessia de diretório (path traversal)

A aplicação constrói caminhos de arquivo a partir de entrada do usuário sem validar adequadamente sequências como '../' ou símbolos absolutos, permitindo que um atacante acesse arquivos fora do diretório permitido. Isso expõe dados sensíveis ou permite execução não autorizada de operações no sistema de arquivos.

Ejemplo

Um sistema web que serve documentos de um diretório específico recebe a requisição 'GET /doc?file=../../etc/passwd'. Se não validar a entrada, o código resolve o caminho para fora do diretório restrito e vaza o arquivo de senhas do sistema.

Cómo mitigar

Valide caminhos usando listas brancas de nomes de arquivo permitidos, normalize caminhos (remover '../' e símbolos), use APIs que isolem automaticamente operações em diretório base (ex: chroot, sandbox), e evite concatenar entrada direta em construtores de caminhos. Teste com payloads comuns de path traversal em testes de segurança.

CVE-2024-44867HIGHphpok v3.0 was discovered to contain an arbitrary file read vulnerability via the component /autoload/file.php.EPSS 1.0%CVE-2022-39221HIGHImproper Limitation of a Pathname to a Restricted Directory ('Path Traversal') McWebserver Minecraft ModEPSS 1.0%CVE-2024-3311MEDIUMDreamer CMS ThemesController.java ZipUtils.unZipFiles path traversalEPSS 1.0%CVE-2026-33046HIGHIndico discloses local files resulting in Remote Code Execution through LaTeX injectionEPSS 1.0%CVE-2026-34653HIGHAdobe Commerce | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') (CWE-22)EPSS 1.0%CVE-2023-2315HIGHPath Traversal in OpenCart versions 4.0.0.0 to 4.0.2.2EPSS 1.0%CVE-2022-42188HIGHIn Lavalite 9.0.0, the XSRF-TOKEN cookie is vulnerable to path traversal attacks, enabling read access to arbitrary files on the server.EPSS 1.0%CVE-2019-25098MEDIUMsoerennb eXtplorer Archive archive.php path traversalEPSS 1.0%CVE-2022-41607MEDIUMETIC Telecom Remote Access Server Path TraversalEPSS 1.0%CVE-2021-21909MEDIUMSpecially-crafted command line arguments can lead to arbitrary file deletion in the del .cnt|.log file delete command. An attacker can proviEPSS 1.0%CVE-2022-40444MEDIUMZZCMS 2022 was discovered to contain a full path disclosure vulnerability via the page /admin/index.PHP? _server.EPSS 1.0%CVE-2023-26559MEDIUMA directory traversal vulnerability in Oxygen XML Web Author before 25.0.0.3 build 2023021715 and Oxygen Content Fusion before 5.0.3 build 2EPSS 1.0%CVE-2026-19264CRITICALUnauthenticated arbitrary file read via /uploads path traversal (URL-encoded separators) leading to instance takeoverEPSS 1.0%CVE-2023-25802HIGHRoxy-WI has Path Traversal vulnerabilityEPSS 1.0%CVE-2024-57669HIGHDirectory Traversal vulnerability in Zrlog backup-sql-file.jar v.3.0.31 allows a remote attacker to obtain sensitive information via the BacEPSS 1.0%CVE-2026-46402HIGHMicrosoft UFO uses untrusted task_name in log paths, allowing authenticated path traversal and log file creation outside the logs directoryEPSS 1.0%CVE-2024-38824CRITICALCVE-2024-38824 salt advisoryEPSS 1.0%CVE-2026-50548CRITICALCursor Desktop sandbox escape via agent-controlled working directoryEPSS 1.0%CVE-2023-1002MEDIUMMuYuCMS index.php path traversalEPSS 1.0%CVE-2024-4098CRITICALShariff Wrapper <= 4.6.13 - Unauthenticated Local File InclusionEPSS 1.0%