CWE-42: Path Equivalence: 'filename.' (Trailing Dot)
Path Equivalence: 'filename.' (Trailing Dot)
Weakness ID: 42 (Weakness Variant) Status: Incomplete
Description
Description Summary
A software system that accepts path input in the form of trailing dot ('filedir.') without appropriate validation can lead to ambiguous path resolution and allow an attacker to traverse the file system to unintended locations or access arbitrary files.
Time of Introduction
Common Consequences
Scope Effect
Access Control
Technical Impact: Bypass protection
mechanism
Observed Examples
Potential Mitigations
see the vulnerability category "Path Equivalence"
Relationships
Taxonomy Mappings
Mapped Taxonomy Name Node ID Fit Mapped Node Name
PLOVER Trailing Dot - 'filedir.'
Content History
Submissions Submission Date Submitter Organization Source PLOVER Externally Mined Modifications Modification Date Modifier Organization Source 2008-07-01 Eric Dalci Cigital External updated Time_of_Introduction 2008-09-08 CWE Content Team MITRE Internal updated Relationships,
Taxonomy_Mappings 2011-06-01 CWE Content Team MITRE Internal updated Common_Consequences Previous Entry Names Change Date Previous Entry
Name 2008-04-11 Path Issue - Trailing Dot -
'filedir.'