CWE-73

High likelihood

External Control of File Name or Path

Parent: CWE-642 - External Control of Critical State Data

The product allows user input to control or influence paths or file names that are used in filesystem operations.

450 vulnerabilities with CWE-73
CVE-2024-33860 MEDIUM
Logpoint SIEM < 7.4.0 - Local File Inclusion via File System Collector
CVSS 6.5
CVE-2024-33671 HIGH
Veritas Backup Exec <22.2 - Privilege Escalation
CVSS 7.7
CVE-2024-31492 HIGH
FortiClientMac <7.2.3, <7.0.10 - Code Injection
CVSS 8.2
CVE-2024-30265 HIGH
Collabora Online - Local File Inclusion
CVSS 7.5
CVE-2024-22178 MEDIUM
Open Automation Software OAS Platform <19.00.0057 - File Write
CVSS 4.9
CVE-2024-21870 MEDIUM
Open Automation Software OAS Platform <19.00.0057 - File Write
CVSS 4.9
CVE-2024-2917 MEDIUM
Campcodes House Rental Management System 1.0 - File Inclusion
CVSS 5.4
CVE-2024-1603 HIGH
PaddlePaddle Paddle <2.6.0 - Info Disclosure
CVSS 7.5
CVE-2024-23634 MEDIUM
GeoServer < 2.23.5 and 2.24.2 - Authenticated Arbitrary File Renaming via REST Coverage Store or Data Store API
CVSS 6.0
CVE-2024-26185 MEDIUM
Windows Compressed Folder Tampering - Info Disclosure
CVSS 6.5
CVE-2024-2155 MEDIUM
SourceCodester Best POS Management System 1.0 - File Inclusion
CVSS 4.3
CVE-2024-2150 MEDIUM
SourceCodester Insurance Management System 1.0 - File Inclusion
CVSS 5.3
CVE-2024-25117 MEDIUM
php-svg-lib <0.5.2 - Remote Code Execution via PHAR font-family URL
CVSS 6.8
CVE-2024-0728 MEDIUM
ForU CMS <2020-06-23 - File Inclusion
CVSS 4.7
CVE-2024-20652 HIGH
Windows HTML Platforms < - Privilege Escalation
CVSS 8.1
CVE-2024-0265 MEDIUM
SourceCodester Clinic Queuing System 1.0 - File Inclusion
CVSS 6.3
CVE-2023-45588 HIGH
FortiClientMac <7.2.3 - Path Traversal
CVSS 8.2
CVE-2023-5816 MEDIUM
Code Explorer <1.4.5 - Info Disclosure
CVSS 4.9
CVE-2023-47147 MEDIUM
IBM Sterling Secure Proxy <6.1.0 - Info Disclosure
CVSS 5.9
CVE-2023-26282 MEDIUM
IBM Watson CP4D Data Stores <4.6.4 - Privilege Escalation
CVSS 4.2
CVE-2023-49864 MEDIUM
WWBN AVideo - Arbitrary File Read via aVideoEncoderReceiveImage.json.php downloadURL_image Parameter
CVSS 6.5
CVE-2023-49863 MEDIUM
WWBN AVideo - Arbitrary File Read via aVideoEncoderReceiveImage.json.php downloadURL_webpimage Parameter
CVSS 6.5
CVE-2023-49862 MEDIUM
WWBN AVideo - Arbitrary File Read via aVideoEncoderReceiveImage.json.php downloadURL_gifimage Parameter
CVSS 6.5
CVE-2023-49738 HIGH
WWBN AVideo - Arbitrary File Read via image404Raw.php
CVSS 7.5
CVE-2023-47862 CRITICAL
WWBN AVideo - Local File Inclusion and Remote Code Execution via getLanguageFromBrowser
CVSS 9.8
Details
Vulnerabilities 450
Exploit Likelihood High