CWE-615: Inclusion of Sensitive Information in Source Code Comments

ID CWE-615
Abstraction Variant
Structure Simple
Status Incomplete
While adding general comments is very useful, some programmers tend to leave important data, such as: filenames related to the web application, old links or links which were not meant to be browsed by users, old code fragments, etc.

An attacker who finds these comments can map the application's structure and files, expose hidden parts of the site, and study the fragments of code to reverse engineer the application, which may help develop further attacks against the site.

Modes of Introduction

Phase Note
Implementation

Relationships

View Weakness
# ID View Status # ID Name Abstraction Structure Status
CWE-1000 Research Concepts Draft CWE-540 Inclusion of Sensitive Information in Source Code Base Simple Incomplete
CWE-1000 Research Concepts Draft CWE-546 Suspicious Comment Variant Simple Draft
Loading...
Loading...