CWE-73

High likelihood

External Control of File Name or Path

Parent: CWE-642 - External Control of Critical State Data

The product allows user input to control or influence paths or file names that are used in filesystem operations.

519 vulnerabilities with CWE-73
CVE-2024-2917 MEDIUM
Campcodes House Rental Management System 1.0 - File Inclusion
CVSS 5.4
CVE-2024-1603 HIGH
PaddlePaddle Paddle <2.6.0 - Info Disclosure
CVSS 7.5
CVE-2024-23634 MEDIUM
GeoServer < 2.23.5 and 2.24.2 - Authenticated Arbitrary File Renaming via REST Coverage Store or Data Store API
CVSS 6.0
CVE-2024-26185 MEDIUM
Windows Compressed Folder Tampering - Info Disclosure
CVSS 6.5
CVE-2024-2155 MEDIUM
SourceCodester Best POS Management System 1.0 - File Inclusion
CVSS 4.3
CVE-2024-2150 MEDIUM
SourceCodester Insurance Management System 1.0 - File Inclusion
CVSS 5.3
CVE-2024-25117 MEDIUM
php-svg-lib <0.5.2 - Remote Code Execution via PHAR font-family URL
CVSS 6.8
CVE-2024-0728 MEDIUM
ForU CMS <2020-06-23 - File Inclusion
CVSS 4.7
CVE-2024-20652 HIGH
Windows HTML Platforms < - Privilege Escalation
CVSS 8.1
CVE-2024-0265 MEDIUM
SourceCodester Clinic Queuing System 1.0 - File Inclusion
CVSS 6.3
CVE-2023-45588 HIGH
FortiClientMac <7.2.3 - Path Traversal
CVSS 8.2
CVE-2023-5816 MEDIUM
Code Explorer <1.4.5 - Info Disclosure
CVSS 4.9
CVE-2023-47147 MEDIUM
IBM Sterling Secure Proxy <6.1.0 - Info Disclosure
CVSS 5.9
CVE-2023-26282 MEDIUM
IBM Watson CP4D Data Stores <4.6.4 - Privilege Escalation
CVSS 4.2
CVE-2023-49864 MEDIUM
WWBN AVideo - Arbitrary File Read via aVideoEncoderReceiveImage.json.php downloadURL_image Parameter
CVSS 6.5
CVE-2023-49863 MEDIUM
WWBN AVideo - Arbitrary File Read via aVideoEncoderReceiveImage.json.php downloadURL_webpimage Parameter
CVSS 6.5
CVE-2023-49862 MEDIUM
WWBN AVideo - Arbitrary File Read via aVideoEncoderReceiveImage.json.php downloadURL_gifimage Parameter
CVSS 6.5
CVE-2023-49738 HIGH
WWBN AVideo - Arbitrary File Read via image404Raw.php
CVSS 7.5
CVE-2023-47862 CRITICAL
WWBN AVideo - Local File Inclusion and Remote Code Execution via getLanguageFromBrowser
CVSS 9.8
CVE-2023-47171 MEDIUM
WWBN AVideo 11.6 and dev master commit 15fed957fb - Arbitrary File Read via aVideoEncoder.json.php chunkFile Path
CVSS 6.5
CVE-2023-6569 HIGH
h2o - Path Traversal
CVSS 8.2
CVE-2023-36019 CRITICAL
Microsoft Power Platform Connector - Open Redirect
CVSS 9.6
CVE-2023-6618 MEDIUM
SourceCodester Simple Student Attendance System 1.0 - File Inclusion
CVSS 5.5
CVE-2023-5247 HIGH
Mitsubishi Electric GX Works3 - Malicious Code Execution via Crafted Project File
CVSS 7.8
CVE-2023-40194 HIGH
Foxit Reader 12.1.3.15356 - Code Injection
CVSS 8.8
Details
Vulnerabilities 519
Exploit Likelihood High