CWE-552— Files or Directories Accessible to External Parties
341 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-552page 1 of 7
- CVE-2015-4715MEDIUMCVSS 4.9EG 4.92020-02-17
The fetch function in OAuth/Curl.php in Dropbox-PHP, as used in ownCloud Server before 6.0.8, 7.x before 7.0.6, and 8.x before 8.0.4 when an external Dropbox storage has been mounted, allows remote administrators of Dropbox.com to read arb…
- CVE-2016-10829MEDIUMCVSS 6.52019-08-01
cPanel before 55.9999.141 allows arbitrary file-read operations because of a multipart form processing error (SEC-99).
- CVE-2017-1602MEDIUMCVSS 4.32018-03-23
IBM RSA DM (IBM Rational Collaborative Lifecycle Management 5.0 and 6.0) could allow an authenticated user to access settings that they should not be able to using a specially crafted URL. IBM X-Force ID: 132625.
- CVE-2017-2621MEDIUMCVSS 5.52018-07-27
An access-control flaw was found in the OpenStack Orchestration (heat) service before 8.0.0, 6.1.0 and 7.0.2 where a service log directory was improperly made world readable. A malicious system user could exploit this flaw to access sensit…
- CVE-2017-2622MEDIUMCVSS 5.92018-07-27
An accessibility flaw was found in the OpenStack Workflow (mistral) service where a service log directory was improperly made world readable. A malicious system user could exploit this flaw to access sensitive information.
- CVE-2017-6922MEDIUMCVSS 6.52019-01-22
In Drupal core 8.x prior to 8.3.4 and Drupal core 7.x prior to 7.56; Private files that have been uploaded by an anonymous user but not permanently attached to content on the site should only be visible to the anonymous user that uploaded …
- CVE-2018-0106LOWCVSS 3.32018-01-18
A vulnerability in the ConfD server of the Cisco Elastic Services Controller (ESC) could allow an unauthenticated, local attacker to access sensitive information on a targeted system. The vulnerability is due to insufficient security restr…
- CVE-2018-1079HIGHCVSS 8.72018-04-12
pcs before version 0.9.164 and 0.10 is vulnerable to a privilege escalation via authorized user malicious REST call. The REST interface of the pcsd service did not properly sanitize the file name from the /remote/put_file query. If the /et…
- CVE-2018-10863HIGHCVSS 7.5EG 7.52021-05-26
It was discovered that redhat-certification 7 is not properly configured and it lists all files and directories in the /var/www/rhcert/store/transfer directory, through the /rhcert-transfer URL. An unauthorized attacker may use this flaw t…
- CVE-2018-10867CRITICALCVSS 9.1EG 9.12021-05-26
Files are accessible without restrictions from the /update/results page of redhat-certification 7 package, allowing an attacker to remove any file accessible by the apached user.
- CVE-2018-10869HIGHCVSS 7.52018-07-19
redhat-certification does not properly restrict files that can be download through the /download page. A remote attacker may download any file accessible by the user running httpd.
- CVE-2018-16946HIGHCVSS 7.52018-09-12
LG LNB*, LND*, LNU*, and LNV* smart network camera devices have broken access control. Attackers are able to download /updownload/t.report (aka Log & Report) files and download backup files (via download.php) without authenticating. These …
- CVE-2018-5112HIGHCVSS 7.52018-06-11
Development Tools panels of an extension are required to load URLs for the panels as relative URLs from the extension manifest file but this requirement was not enforced in all instances. This could allow the development tools panel for th…
- CVE-2018-9587HIGHCVSS 7.32019-02-11
In savePhotoFromUriToUri of ContactPhotoUtils.java in Android-7.0, Android-7.1.1, Android-7.1.2, Android-8.0, Android-8.1 and Android-9, there is possible unauthorized access to files within the contact app due to a confused deputy scenari…
- CVE-2019-0381MEDIUMCVSS 5.5EG 5.52019-10-08
A binary planting in SAP SQL Anywhere, before version 17.0, SAP IQ, before version 16.1, and SAP Dynamic Tier, before versions 1.0 and 2.0, can result in the inadvertent access of files located in directories outside of the paths specified…
- CVE-2019-10930HIGHCVSS 7.52019-07-11
A vulnerability has been identified in All other SIPROTEC 5 device types with CPU variants CP300 and CP100 and the respective Ethernet communication modules (All versions ), DIGSI 5 engineering software (All versions < V7.90), SIPROTEC 5 d…
- CVE-2019-12375MEDIUMCVSS 6.32019-06-03
Open directories in Ivanti LANDESK Management Suite (LDMS, aka Endpoint Manager) 10.0.1.168 Service Update 5 may lead to remote information disclosure and arbitrary code execution.
- CVE-2019-13140MEDIUMCVSS 6.5EG 6.52019-09-16
Inteno EG200 EG200-WU7P1U_ADAMO3.16.4-190226_1650 routers have a JUCI ACL misconfiguration that allows the "user" account to extract the 3DES key via JSON commands to ubus. The 3DES key is used to decrypt the provisioning file provided by …
- CVE-2019-13404HIGHCVSS 7.82019-07-08
The MSI installer for Python through 2.7.16 on Windows defaults to the C:\Python27 directory, which makes it easier for local users to deploy Trojan horse code. (This also affects old 3.x releases before 3.5.) NOTE: the vendor's position i…
- CVE-2019-13941HIGHCVSS 7.5EG 7.52020-02-11
A vulnerability has been identified in OZW672 (All versions < V10.00), OZW772 (All versions < V10.00). Vulnerable versions of OZW Web Server use predictable path names for project files that legitimately authenticated users have created by…
- CVE-2019-14273MEDIUMCVSS 5.3EG 5.32019-09-26
In SilverStripe assets 4.0, there is broken access control on files.
- CVE-2019-17112MEDIUMCVSS 4.3EG 4.32019-10-09
An issue was discovered in Zoho ManageEngine DataSecurity Plus before 5.0.1 5012. An exposed service allows a basic user ("Operator" access level) to access the configuration file of the mail server (except for the password).
- CVE-2019-17130MEDIUMCVSS 6.5EG 6.52019-10-04
vBulletin through 5.5.4 mishandles external URLs within the /core/vb/vurl.php file and the /core/vb/vurl directories.
- CVE-2019-17221HIGHCVSS 7.5EG 7.52019-11-05
PhantomJS through 2.1.1 has an arbitrary file read vulnerability, as demonstrated by an XMLHttpRequest for a file:// URI. The vulnerability exists in the page.open() function of the webpage module, which loads a specified URL and calls a g…
- CVE-2019-19018LOWCVSS 2.7EG 2.72019-12-02
An issue was discovered in TitanHQ WebTitan before 5.18. It exposes a database configuration file under /include/dbconfig.ini in the web administration interface, revealing what database the web application is using.
- CVE-2019-19843CRITICALCVSS 9.8EG 9.82020-01-22
Incorrect access control in the web interface in Ruckus Wireless Unleashed through 200.7.10.102.64 allows remote credential fetch via an unauthenticated HTTP request involving a symlink with /tmp and web/user/wps_tool_cache.
- CVE-2019-20529HIGHCVSS 7.5EG 7.52020-03-18
In core/doctype/prepared_report/prepared_report.py in Frappe 11 and 12, data files generated with Prepared Report were being stored as public files (no authentication is required to access; having a link is sufficient) instead of private f…
- CVE-2019-20593MEDIUMCVSS 5.3EG 5.32020-03-24
An issue was discovered on Samsung mobile devices with N(7.x) and O(8.x) software. Gallery leaks Private Mode thumbnails. The Samsung ID is SVE-2019-14208 (July 2019).
- CVE-2019-3569HIGHCVSS 7.52019-06-26
HHVM, when used with FastCGI, would bind by default to all available interfaces. This behavior could allow a malicious individual unintended direct access to the application, which could result in information disclosure. This issue affects…
- CVE-2019-3622HIGHCVSS 8.22019-07-24
Files or Directories Accessible to External Parties in McAfee Data Loss Prevention (DLPe) for Windows 11.x prior to 11.3.0 allows authenticated user to redirect DLPe log files to arbitrary locations via incorrect access control applied to …
- CVE-2019-3811MEDIUMCVSS 5.22019-01-15
A vulnerability was found in sssd. If a user was configured with no home directory set, sssd would return '/' (the root directory) instead of '' (the empty string / no home directory). This could impact services that restrict the user's fi…
- CVE-2019-3897MEDIUMCVSS 5.3EG 5.32021-03-16
It has been discovered in redhat-certification that any unauthorized user may download any file under /var/www/rhcert, provided they know its name. Red Hat Certification 6 and 7 is vulnerable to this issue.
- CVE-2019-4398LOWCVSS 3.3EG 3.32019-10-24
IBM Cloud Orchestrator and IBM Cloud Orchestrator Enterprise 2.5 through 2.5.0.9 and 2.4 through 2.4.0.5 could allow a local user to obtain sensitive information from SessionManagement cookies. IBM X-Force ID: 162259.
- CVE-2019-7305MEDIUMCVSS 5.8EG 5.82020-04-10
Information Exposure vulnerability in eXtplorer makes the /usr/ and /etc/extplorer/ system directories world-accessible over HTTP. Introduced in the Makefile patch file debian/patches/debian-changes-2.1.0b6+dfsg-1 or debian/patches/adds-a-…
- CVE-2019-7306MEDIUMCVSS 4.3EG 4.32020-04-17
Byobu Apport hook may disclose sensitive information since it automatically uploads the local user's .screenrc which may contain private hostnames, usernames and passwords. This issue affects: byobu
- CVE-2020-10105MEDIUMCVSS 5.3EG 5.32020-03-05
An issue was discovered in Zammad 3.0 through 3.2. It returns source code of static resources when submitting an OPTIONS request, rather than a GET request. Disclosure of source code allows for an attacker to formulate more precise attacks…
- CVE-2020-10516CRITICALCVSS 9.8EG 9.82020-06-03
An improper access control vulnerability was identified in the GitHub Enterprise Server API that allowed an organization member to escalate permissions and gain access to unauthorized repositories within an organization. This vulnerability…
- CVE-2020-11469HIGHCVSS 7.8EG 7.82020-04-01
Zoom Client for Meetings through 4.6.8 on macOS copies runwithroot to a user-writable temporary directory during installation, which allows a local process (with the user's privileges) to obtain root access by replacing runwithroot.
- CVE-2020-11641HIGHCVSS 7.7EG 6.52020-10-15
A local file inclusion vulnerability in B&R SiteManager versions <9.2.620236042 allows authenticated users to read sensitive files from SiteManager instances.
- CVE-2020-11642HIGHCVSS 7.7EG 6.52020-10-15
The local file inclusion vulnerability present in B&R SiteManager versions <9.2.620236042 allows authenticated users to impact availability of SiteManager instances.
- CVE-2020-11976HIGHCVSS 7.5EG 7.52020-08-11
By crafting a special URL it is possible to make Wicket deliver unprocessed HTML templates. This would allow an attacker to see possibly sensitive information inside a HTML template that is usually removed during rendering. Affected are Ap…
- CVE-2020-12470HIGHCVSS 7.2EG 7.22020-04-29
MonoX through 5.1.40.5152 allows administrators to execute arbitrary code by modifying an ASPX template.
- CVE-2020-12743CRITICALCVSS 9.8EG 9.82020-05-11
An issue was discovered in Gazie 7.32. A successful installation does not remove or block (or in any other way prevent use of) its own file /setup/install/setup.php, meaning that anyone can request it without authentication. This file allo…
- CVE-2020-13953MEDIUMCVSS 5.3EG 5.32020-09-30
In Apache Tapestry from 5.4.0 to 5.5.0, crafting specific URLs, an attacker can download files inside the WEB-INF folder of the WAR being run.
- CVE-2020-15175HIGHCVSS 7.4EG 7.42020-10-07
In GLPI before version 9.5.2, the `pluginimage.send.php` endpoint allows a user to specify an image from a plugin. The parameters can be maliciously crafted to instead delete the .htaccess file for the files directory. Any user becom…
- CVE-2020-15224MEDIUMCVSS 6.8EG 6.82020-10-14
In Open Enclave before version 0.12.0, an information disclosure vulnerability exists when an enclave application using the syscalls provided by the sockets.edl is loaded by a malicious host application. An attacker who successfully exploi…
- CVE-2020-1726MEDIUMCVSS 5.9EG 5.92020-02-11
A flaw was discovered in Podman where it incorrectly allows containers when created to overwrite existing files in volumes, even if they are mounted as read-only. When a user runs a malicious container or a container based on a malicious i…
- CVE-2020-17519HIGHCVSS 7.5EG 7.5⚠ KEV2021-01-05
A change introduced in Apache Flink 1.11.0 (and released in 1.11.1 and 1.11.2 as well) allows attackers to read any file on the local filesystem of the JobManager through the REST interface of the JobManager process. Access is restricted t…
- CVE-2020-1908MEDIUMCVSS 4.6EG 4.62020-11-03
Improper authorization of the Screen Lock feature in WhatsApp and WhatsApp Business for iOS prior to v2.20.100 could have permitted use of Siri to interact with the WhatsApp application even after the phone was locked.
- CVE-2020-22124HIGHCVSS 7.5EG 7.52021-08-18
A vulnerability in the \inc\config.php component of joyplus-cms v1.6 allows attackers to access sensitive information.
Map vulnerabilities like CWE-552 to your infrastructure
EchelonGraph correlates every CVE — across CWE-552 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →