CWE
Home > CWE List > CWE-39 Individual Dictionary Definition (Draft 9)   View the CWE List

CWE-39 Individual Dictionary Definition (Draft 9)

Path Traversal: 'C:dirname'
Weakness ID
Status: Draft

39 (Weakness Variant)

Description

Summary

An attacker can inject a drive letter or Windows volume letter ('C:dirname') into a software system to potentially redirect access to an unintended location or arbitrary file.

Potential Mitigations

see the vulnerability category "Path Traversal"

Observed Examples
ReferenceDescription
CVE-2001-0038
CVE-2001-0255
CVE-2001-0687
CVE-2001-0933
CVE-2002-0466
CVE-2002-1483
CVE-2004-2488FTP server read/access arbitrary files using "C:\" filenames
Relationships
NatureTypeIDName
ChildOfWeakness BaseWeakness BaseWeakness Base36Absolute Path Traversal
Source Taxonomies

PLOVER - 'C:dirname' or C: (Windows volume or 'drive letter')

Applicable Platforms

All

Page Last Updated: April 22, 2008