CWE
Home > CWE List > CWE-52 Individual Dictionary Definition (Draft 9)   View the CWE List

CWE-52 Individual Dictionary Definition (Draft 9)

Path Equivalence: '/multiple/trailing/slash//'
Weakness ID
Status: Incomplete

52 (Weakness Variant)

Description

Summary

A software system that accepts path input in the form of multiple trailing slash ('/multiple/trailing/slash//') without appropriate validation can lead to ambiguous path resolution and allow an attacker to traverse the file system to unintended locations or access arbitrary files.

Potential Mitigations

see the vulnerability category "Path Equivalence"

Observed Examples
ReferenceDescription
CVE-2002-1078Directory listings in web server using multiple trailing slash
Relationships
NatureTypeIDName
ChildOfWeakness ClassWeakness ClassWeakness Class41Failure to Resolve Path Equivalence
CanPrecedeWeakness VariantWeakness VariantWeakness Variant289Authentication Bypass by Alternate Name
Source Taxonomies

PLOVER - /multiple/trailing/slash// ('multiple trailing slash')

Applicable Platforms

All

Page Last Updated: April 22, 2008