Falhas do tipo CWE-22

5.865 resultados

Travessia de diretório (Path Traversal)

A aplicação constrói caminhos de arquivo usando entrada do usuário sem validar adequadamente, permitindo que caracteres especiais como '../' façam o caminho "sair" do diretório permitido e acessar arquivos fora da zona restrita. Isso expõe dados sensíveis ou permite manipulação de arquivos críticos do sistema.

Exemplo

Um site permite download de documentos via URL como /download?file=relatorio.pdf, mas não valida o parâmetro. Um atacante usa /download?file=../../etc/passwd para ler o arquivo de senhas do servidor, ou /download?file=../../configuracao.db para acessar a base de dados da aplicação.

Como mitigar

Valide e normalize todos os caminhos de entrada (use funções nativas como realpath ou canonicalize), implemente uma whitelist de arquivos permitidos em vez de bloquear padrões perigosos, e configure permissões de arquivo restritivas no SO. Melhor ainda: nunca construa caminhos a partir de entrada do usuário — use índices ou IDs mapeados internamente.

CVE-2026-61800CRITICALWazuh cluster worker file sync allows arbitrary file write under /var/ossec (incomplete fix for CVE-2026-30893)EPSS 1.0%CVE-2024-48735HIGHDirectory Traversal in /SASStudio/sasexec/sessions/{sessionID}/workspace/{InternalPath} in SAS Studio 9.4 allows remote attacker to access iEPSS 1.0%CVE-2021-36425MEDIUMDirectory traversal vulnerability in phpcms 1.9.25 allows remote attackers to delete arbitrary files via unfiltered $file parameter to unlinEPSS 1.0%CVE-2023-47702MEDIUMIBM Security Guardium Key Lifecycle Manager directory traversalEPSS 1.0%CVE-2023-27501HIGHDirectory Traversal vulnerability in SAP NetWeaver AS for ABAP and ABAP Platform EPSS 1.0%CVE-2023-42232HIGHPat Infinite Solutions HelpdeskAdvanced <= 11.0.33 is vulnerable to Directory Traversal via the Navigator/Index function.EPSS 1.0%CVE-2023-33989HIGHDirectory Traversal vulnerability in SAP NetWeaver (BI CONT ADD ON)EPSS 1.0%CVE-2022-39347LOWMissing path sanitation with `drive` channel in FreeRDPEPSS 1.0%CVE-2026-50006CRITICALAnyquery: Arbitrary File Write (AFW) which could lead to Remote Code Execution (RCE) via Unrestricted ATTACH DATABASE in Server ModeEPSS 1.0%CVE-2023-47473HIGHDirectory Traversal vulnerability in fuwushe.org iFair versions 23.8_ad0 and before allows an attacker to obtain sensitive information via aEPSS 1.0%CVE-2025-32587HIGHWordPress WooCommerce Pickupp plugin <= 2.4.3 - Local File Inclusion vulnerabilityEPSS 1.0%CVE-2023-39964HIGH1Panel O&M management panel has a background arbitrary file reading vulnerabilityEPSS 1.0%CVE-2025-50971HIGHDirectory traversal vulnerability in AbanteCart version 1.4.2 allows unauthenticated attackers to gain access to sensitive system files via EPSS 1.0%CVE-2025-10708MEDIUMFour-Faith Water Conservancy Informatization Platform historyDownload.do;usrlogout.do path traversalEPSS 1.0%CVE-2025-10709MEDIUMFour-Faith Water Conservancy Informatization Platform historyDownload.do;otheruserLogin.do;getfile path traversalEPSS 1.0%CVE-2025-11018MEDIUMFour-Faith Water Conservancy Informatization Platform download.do;usrlogout.do.do path traversalEPSS 1.0%CVE-2026-56671HIGHComfyUI: Path traversal in /experiment/models/preview allows arbitrary image file readEPSS 1.0%CVE-2026-49818MEDIUMApache Airflow Samba provider: Path traversal in GCSToSambaOperator via GCS object namesEPSS 1.0%CVE-2023-43648MEDIUMbaserCMS Directory Traversal vulnerability in Form submission data management FeatureEPSS 1.0%CVE-2023-34298HIGHPulse Secure Client SetupService Directory Traversal Local Privilege Escalation VulnerabilityEPSS 1.0%