CWE
Home > CWE List > CWE-36 Individual Dictionary Definition (Draft 9)   View the CWE List

CWE-36 Individual Dictionary Definition (Draft 9)

Absolute Path Traversal
Weakness ID
Status: Draft

36 (Weakness Base)

Description

Summary

The software, when constructing file or directory names from input, does not properly sanitize absolute path sequences such as "/path/here."

Potential Mitigations

see "Path Traversal" (CWE-22)

Relationships
NatureTypeIDName
ChildOfWeakness ClassWeakness ClassWeakness Class22Path Traversal
ParentOfWeakness VariantWeakness VariantWeakness Variant37Path Traversal: '/absolute/pathname/here'
ParentOfWeakness VariantWeakness VariantWeakness Variant38Path Traversal: '\absolute\pathname\here'
ParentOfWeakness VariantWeakness VariantWeakness Variant39Path Traversal: 'C:dirname'
ParentOfWeakness VariantWeakness VariantWeakness Variant40Path Traversal: '\\UNC\share\name\' (Windows UNC Share)
Source Taxonomies

PLOVER - Absolute Path Traversal

Applicable Platforms

All

Page Last Updated: April 22, 2008