This is a general class of weakness, but most research is focused on more
specialized cases, such as path traversal (CWE-22) and symlink following
(CWE-61). A symbolic link has a name; in general, it appears like any other
file in the file system. However, the link includes a reference to another
file, often in another directory - perhaps in another sphere of control.
Many common library functions that accept filenames will "follow" a symbolic
link and use the link's target instead.
Content History
Submissions
Submission Date
Submitter
Organization
Source
Anonymous Tool Vendor (under NDA)
Externally Mined
Modifications
Modification Date
Modifier
Organization
Source
2008-09-08
CWE Content Team
MITRE
Internal
updated Relationships, Other Notes,
Taxonomy Mappings