Path Equivalence: '//multiple/leading/slash' |
Weakness ID: 50 (Weakness Variant) | Status: Incomplete |
Description Summary
A software system that accepts path input in the form of multiple leading slash ('//multiple/leading/slash') without appropriate validation can lead to ambiguous path resolution and allow an attacker to traverse the file system to unintended locations or access arbitrary files.
Reference | Description |
---|---|
CVE-2002-1483 | |
CVE-1999-1456 | |
CVE-2004-0578 | |
CVE-2002-0275 | |
CVE-2004-1032 | |
CVE-2002-1238 | |
CVE-2004-1878 | |
CVE-2005-1365 | |
CVE-2000-1050 | Access directory using multiple leading slash. |
CVE-2001-1072 | Bypass access restrictions via multiple leading slash, which causes a regular expression to fail. |
CVE-2004-0235 | Archive extracts to arbitrary files using multiple leading slash in filenames in the archive. |
Nature | Type | ID | Name | View(s) this relationship pertains to |
---|---|---|---|---|
ChildOf | Weakness Base | 41 | Improper Resolution of Path Equivalence | Development Concepts (primary)699 Research Concepts (primary)1000 |
ChildOf | Weakness Variant | 161 | Improper Sanitization of Multiple Leading Special Elements | Research Concepts1000 |
Mapped Taxonomy Name | Node ID | Fit | Mapped Node Name |
---|---|---|---|
PLOVER | //multiple/leading/slash ('multiple leading slash') |
Submissions | ||||
---|---|---|---|---|
Submission Date | Submitter | Organization | Source | |
PLOVER | Externally Mined | |||
Modifications | ||||
Modification Date | Modifier | Organization | Source | |
2008-07-01 | Eric Dalci | Cigital | External | |
updated Time of Introduction | ||||
2008-09-08 | CWE Content Team | MITRE | Internal | |
updated Relationships, Taxonomy Mappings | ||||
Previous Entry Names | ||||
Change Date | Previous Entry Name | |||
2008-04-11 | Path Issue - Multiple Leading Slash - //multiple/leading/slash | |||