|
|
|
|
CWE-30 Individual Dictionary Definition (Draft 9)
Weakness ID
| Status: Draft 30 (Weakness Variant) | | Description | Summary A software system that accepts input in the form of a leading directory dot dot backslash
('\directory\..\filename') without appropriate validation can allow an attacker to traverse the
file system to access an arbitrary file. | | Potential Mitigations | see the vulnerability category "Path Traversal" | | Observed Examples | | | Relationships | | | Source Taxonomies | PLOVER - 7 - '\directory\..\filename | | Applicable Platforms | All |
|