CWE-45: Path Equivalence: 'file...name' (Multiple Internal Dot)

ID CWE-45
Abstraction Variant
Structure Simple
Status Incomplete
The product accepts path input in the form of multiple internal dot ('file...dir') without appropriate validation, which can lead to ambiguous path resolution and allow an attacker to traverse the file system to unintended locations or access arbitrary files.

Modes of Introduction

Phase Note
Implementation

Applicable Platforms

Type Class Name Prevalence
Language Not Language-Specific

Relationships

View Weakness
# ID View Status # ID Name Abstraction Structure Status
CWE-1000 Research Concepts Draft CWE-44 Path Equivalence: 'file.name' (Internal Dot) Variant Simple Incomplete
CWE-1000 Research Concepts Draft CWE-165 Improper Neutralization of Multiple Internal Special Elements Variant Simple Incomplete
Loading...
Loading...