CWE
Home > CWE List > CWE- Individual Dictionary Definition (1.1)  
Search by ID:

CWE-706: Use of Incorrectly-Resolved Name or Reference

Individual Definition in a New Window
Use of Incorrectly-Resolved Name or Reference
Status: Incomplete
Weakness ID: 706 (Weakness Class)
Description
Summary

The software uses a name or reference to access a resource, but the name/reference resolves to a resource that is outside of the intended control sphere.

Relationships
NatureTypeIDNameView(s) this relationship pertains toView(s)
PeerOfWeakness BaseWeakness BaseWeakness Base99Insufficient Control of Resource Identifiers (aka 'Resource Injection')
Research Concepts1000
MemberOfViewView1000Research Concepts
Research Concepts (primary)1000
ParentOfWeakness BaseWeakness BaseWeakness Base178Failure to Resolve Case Sensitivity
Research Concepts (primary)1000
ParentOfWeakness ClassWeakness ClassWeakness Class22Path Traversal
Research Concepts (primary)1000
ParentOfWeakness BaseWeakness BaseWeakness Base386Symbolic Name not Mapping to Correct Object
Research Concepts (primary)1000
ParentOfWeakness BaseWeakness BaseWeakness Base41Failure to Resolve Path Equivalence
Research Concepts (primary)1000
ParentOfWeakness BaseWeakness BaseWeakness Base59Failure to Resolve Links Before File Access (aka 'Link Following')
Research Concepts (primary)1000
ParentOfWeakness BaseWeakness BaseWeakness Base66Failure to Handle File Names that Identify Virtual Resources
Research Concepts (primary)1000
ParentOfCompound Element: CompositeCompound Element: Composite98Insufficient Control of Filename for Include/Require Statement in PHP Program (aka 'PHP File Inclusion')
Research Concepts (primary)1000
Applicable Platforms
Languages
All
Time of Introduction
* Architecture and Design
* Implementation
Content History
Modifications
Eric Dalci. Cigital. 2008-07-01. (External)
updated Time_of_Introduction
Page Last Updated: November 24, 2008