Falhas do tipo CWE-22

5.839 resultados

Travessia de diretório (Path Traversal)

A aplicação constrói caminhos de arquivo usando entrada do usuário sem validar adequadamente, permitindo que caracteres especiais como '../' façam o caminho "sair" do diretório permitido e acessar arquivos fora da zona restrita. Isso expõe dados sensíveis ou permite manipulação de arquivos críticos do sistema.

Exemplo

Um site permite download de documentos via URL como /download?file=relatorio.pdf, mas não valida o parâmetro. Um atacante usa /download?file=../../etc/passwd para ler o arquivo de senhas do servidor, ou /download?file=../../configuracao.db para acessar a base de dados da aplicação.

Como mitigar

Valide e normalize todos os caminhos de entrada (use funções nativas como realpath ou canonicalize), implemente uma whitelist de arquivos permitidos em vez de bloquear padrões perigosos, e configure permissões de arquivo restritivas no SO. Melhor ainda: nunca construa caminhos a partir de entrada do usuário — use índices ou IDs mapeados internamente.

CVE-2022-48483HIGH3CX before 18 Hotfix 1 build 18.0.3.461 on Windows allows unauthenticated remote attackers to read %WINDIR%\system32 files via /Electron/dowEPSS 1.7%CVE-2022-2926MEDIUMDownload Manager < 3.2.55 - Admin+ Arbitrary File/Folder Access via Path TraversalEPSS 1.7%CVE-2022-32199MEDIUMdb_convert.php in ScriptCase through 9.9.008 is vulnerable to Arbitrary File Deletion by an admin via a directory traversal sequence in the EPSS 1.7%CVE-2024-50329HIGHPath traversal in Ivanti Endpoint Manager before 2024 November Security Update or 2022 SU6 November Security Update allows a remote unauthenEPSS 1.7%CVE-2025-1743MEDIUMzyx0814 Pichome index.php path traversalEPSS 1.7%CVE-2020-7522—Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability exists in SFAPV9601 - APC Easy UPS On-Line SoftEPSS 1.7%CVE-2020-7521—Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability exists in SFAPV9601 - APC Easy UPS On-Line SoftEPSS 1.7%CVE-2019-7007HIGHAvaya Equinox Conferencing Management (iView) Directory Traversal VulnerabilityEPSS 1.7%CVE-2023-32309HIGHArbitrary file inclusion with the pymdowm-snippets extensionEPSS 1.7%CVE-2019-13157—nsGreen.dll in Naver Vaccine 2.1.4 allows remote attackers to overwrite arbitary files via directory traversal sequences in a filename withiEPSS 1.7%CVE-2022-39296HIGHPath traversal in MelisAssetManagerEPSS 1.7%CVE-2022-37866HIGHApache Ivy allows path traversal in the presence of a malicious repositoryEPSS 1.7%CVE-2015-10134HIGHSimple Backup <= 2.7.10 - Arbitrary File Download via Path TraversalEPSS 1.7%CVE-2021-38452HIGHMoxa MXview Network Management SoftwareEPSS 1.7%CVE-2018-16479—Path traversal vulnerability in http-live-simulator <1.0.7 causes unauthorized access to arbitrary files on disk by appending extra slashes EPSS 1.7%CVE-2023-27067HIGHDirectory Traversal vulnerability in Sitecore Experience Platform through 10.2 allows remote attackers to download arbitrary files via craftEPSS 1.6%CVE-2026-54917HIGHSeaweedFS: Path traversal in the S3 and Iceberg REST gateways allows cross-bucket accessEPSS 1.6%CVE-2021-43795HIGHImproper Limitation of a Pathname to a Restricted Directory ('Path Traversal') in com.linecorp.armeria:armeriaEPSS 1.6%CVE-2022-1657HIGHJupiterX Theme <= 2.0.6 and Jupiter Theme <= 6.10.1 - Authenticated Path Traversal and Local File InclusionEPSS 1.6%CVE-2024-5017MEDIUMWhatsUp Gold AppProfileImport path traversal vulnerabilityEPSS 1.6%