CWE
Home > CWE List > CWE- Individual Dictionary Definition (1.6)  

CWE-538: File and Directory Information Leaks

 
File and Directory Information Leaks
Weakness ID: 538 (Weakness Base)Status: Draft
+ Description

Description Summary

Weaknesses in this category are related to information leaks in files and directories.
+ Time of Introduction
  • Implementation
  • Operation
+ Applicable Platforms

Languages

All

+ Potential Mitigations
PhaseDescription

Do not expose file and directory information to the user.

+ Relationships
NatureTypeIDNameView(s) this relationship pertains toView(s)
ChildOfWeakness ClassWeakness Class200Information Leak (Information Disclosure)
Development Concepts (primary)699
Research Concepts (primary)1000
ParentOfWeakness VariantWeakness Variant527Information Leak Through CVS Repository
Development Concepts (primary)699
Research Concepts (primary)1000
ParentOfWeakness VariantWeakness Variant528Information Leak Through Core Dump Files
Development Concepts (primary)699
Research Concepts (primary)1000
ParentOfWeakness VariantWeakness Variant529Information Leak Through Access Control List Files
Development Concepts (primary)699
Research Concepts (primary)1000
ParentOfWeakness VariantWeakness Variant530Information Leak Through Backup (.~bk) Files
Development Concepts (primary)699
Research Concepts (primary)1000
ParentOfWeakness VariantWeakness Variant532Information Leak Through Log Files
Development Concepts (primary)699
Research Concepts (primary)1000
ParentOfWeakness VariantWeakness Variant539Information Leak Through Persistent Cookies
Development Concepts (primary)699
Research Concepts (primary)1000
ParentOfWeakness VariantWeakness Variant540Information Leak Through Source Code
Development Concepts (primary)699
Research Concepts (primary)1000
ParentOfWeakness VariantWeakness Variant548Information Leak Through Directory Listing
Development Concepts (primary)699
Research Concepts (primary)1000
ParentOfWeakness VariantWeakness Variant611Information Leak Through XML External Entity File Disclosure
Development Concepts (primary)699
Research Concepts1000
ParentOfWeakness VariantWeakness Variant651Information Leak through WSDL File
Development Concepts (primary)699
Research Concepts (primary)1000
+ Content History
Modifications
Modification DateModifierOrganizationSource
2008-07-01Eric DalciCigitalExternal
updated Potential Mitigations, Time of Introduction
2008-09-08CWE Content TeamMITREInternal
updated Relationships, Type
Page Last Updated: October 29, 2009