CWE
Home > CWE List > CWE-615 Individual Dictionary Definition (Draft 9)   View the CWE List

CWE-615 Individual Dictionary Definition (Draft 9)

Information Leak Through Comments
Weakness ID
Status: Incomplete

615 (Weakness Variant)

Description

Summary

While adding general comments is very useful, some programmers tend to leave important data, such as: filenames related to the web application, old links or links which were not meant to be browsed by users, old code fragments, etc. An attacker who finds these comments can map the application's structure and files, expose hidden parts of the site, and study the fragments of code to reverse engineer the application, which may help develop further attacks against the site.

Relationships
NatureTypeIDName
ChildOfWeakness VariantWeakness VariantWeakness Variant540Information Leak Through Source Code
Source Taxonomies

Anonymous Tool Vendor (under NDA) -

Page Last Updated: April 22, 2008