CWE
Home > CWE List > CWE-40 Individual Dictionary Definition (Draft 9)   View the CWE List

CWE-40 Individual Dictionary Definition (Draft 9)

Path Traversal: '\\UNC\share\name\' (Windows UNC Share)
Weakness ID
Status: Draft

40 (Weakness Variant)

Description

Summary

An attacker can inject a Windows UNC share ('\\UNC\share\name') into a software system to potentially redirect access to an unintended location or arbitrary file.

Potential Mitigations

see the vulnerability category "Path Traversal"

Observed Examples
ReferenceDescription
CVE-2001-0687
Relationships
NatureTypeIDName
ChildOfWeakness BaseWeakness BaseWeakness Base36Absolute Path Traversal
Source Taxonomies

PLOVER - '\\UNC\share\name\' (Windows UNC share)

Applicable Platforms

All

Page Last Updated: April 22, 2008