CWE-45Path Equivalence: 'file...name' (Multiple Internal Dot)

PUBLISHEDweakness record
released 2006-07-19 · last modified 2025-12-11

Metadata

CWE ID:
CWE-45
摘要:
Variant
结构:
Simple
状态:
Incomplete
发布日期:
2006-07-19
更新日期:
2025-12-11

名称

Path Equivalence: 'file...name' (Multiple Internal Dot)

描述

The product accepts path input in the form of multiple internal dot ('file...dir') without appropriate validation, which can lead to ambiguous path resolution and allow an attacker to traverse the file system to unintended locations or access arbitrary files.

常见后果

范围:
Confidentiality, Integrity
影响:
Read Files or Directories, Modify Files or Directories

相关 CWE