CWE-827

Overview
  • CWE ID
  • 827
  • CWE Name
  • Improper Control of Document Type Definition
  • CWE Abstraction
  • Variant
  • CWE structure
  • Simple
  • CWE Status
  • Incomplete
Description
The software does not restrict a reference to a Document Type Definition (DTD) to the intended control sphere. This might allow attackers to reference arbitrary DTDs, possibly causing the software to expose files, consume excessive system resources, or ex
Extended Description
Related CWEs
CWE ID View ID Nature Ordinal
706 1000 ChildOf Primary
829 1000 ChildOf
776 1000 CanPrecede
Related CVEs