|
|
|
|
CWE-27 Individual Dictionary Definition (Draft 9)
Weakness ID
| Status: Draft 27 (Weakness Variant) | | Description | Summary A software system that accepts input in the form of a directory doubled dot dot slash
('directory/../../filename') without appropriate validation can allow an attacker to traverse the
file system to access an arbitrary file. | | Potential Mitigations | see the vulnerability category "Path Traversal" | | Observed Examples | | | Relationships | | | Source Taxonomies | PLOVER - 'directory/../../filename | | Applicable Platforms | All |
|