CWE-50

Overview
  • CWE ID
  • 50
  • CWE Name
  • Path Equivalence: '//multiple/leading/slash'
  • CWE Abstraction
  • Variant
  • CWE structure
  • Simple
  • CWE Status
  • Incomplete
Description
A software system that accepts path input in the form of multiple leading slash ('//multiple/leading/slash') without appropriate validation can lead to ambiguous path resolution and allow an attacker to traverse the file system to unintended locations or
Extended Description
Related CWEs
CWE ID View ID Nature Ordinal
41 1000 ChildOf Primary
161 1000 ChildOf
Related CVEs