CWE-37Path Traversal: '/absolute/pathname/here'

PUBLISHEDweakness record
released 2006-07-19 · last modified 2025-12-11

Metadata

CWE ID:
CWE-37
摘要:
Variant
结构:
Simple
状态:
Draft
发布日期:
2006-07-19
更新日期:
2025-12-11

名称

Path Traversal: '/absolute/pathname/here'

描述

The product accepts input in the form of a slash absolute path ('/absolute/pathname/here') without appropriate validation, which can allow an attacker to traverse the file system to unintended locations or access arbitrary files.

常见后果

范围:
Confidentiality, Integrity
影响:
Read Files or Directories, Modify Files or Directories

相关 CWE