|
|
|
|
CWE-26 Individual Dictionary Definition (Draft 9)
Weakness ID
| Status: Draft 26 (Weakness Variant) | | Description | Summary A software system that accepts input in the form of a leading directory dot dot slash
('/directory/../filename') without appropriate validation can allow an attacker to traverse the
file system to access an arbitrary file. | | Potential Mitigations | see the vulnerability category "Path Traversal" | | Relationships | | | Source Taxonomies | PLOVER - '/directory/../filename | | Applicable Platforms | All |
|