|
Status: Incomplete Weakness ID: 56 (Weakness Variant)Description Summary A software system that accepts path input in the form of asterisk wildcard ('filedir*') without appropriate validation can lead to ambiguous path resolution and allow an attacker to traverse the file system to unintended locations or access arbitrary files. Potential Mitigations see the vulnerability category "Path Equivalence" Observed Examples
Relationships
Taxonomy Mappings
Applicable Platforms Languages All Time of Introduction ImplementationContent History Submissions PLOVER. (Externally Mined) Modifications Eric Dalci. Cigital. 2008-07-01. (External) updated Time_of_Introduction CWE Content Team. MITRE. 2008-09-08. (Internal) updated Relationships, Taxonomy_Mappings Previous Entry Names Path Issue - Asterisk Wildcard - filedir* (changed 2008-04-11) |
|
|
|||