CWE-213 故意性的信息暴露

admin 2022年1月5日21:01:56CWE(弱点枚举)评论15 views2441字阅读8分8秒阅读模式

CWE-213 故意性的信息暴露

Intentional Information Exposure

结构: Simple

Abstraction: Base

状态: Draft

被利用可能性: unkown


A product's design or configuration explicitly requires the publication of information that could be regarded as sensitive by an administrator.


  • cwe_Nature: ChildOf cwe_CWE_ID: 200 cwe_View_ID: 1000 cwe_Ordinal: Primary

  • cwe_Nature: ChildOf cwe_CWE_ID: 200 cwe_View_ID: 699 cwe_Ordinal: Primary


Language: {'cwe_Class': 'Language-Independent', 'cwe_Prevalence': 'Undetermined'}


范围 影响 注释
Confidentiality Read Application Data


This code displays some information on a web page.

bad JSP

Social Security Number: Credit Card Number:

The code displays a user's credit card and social security numbers, even though they aren't absolutely necessary.


标识 说明 链接
CVE-2002-1725 Script calls phpinfo()
CVE-2004-0033 Script calls phpinfo()
CVE-2003-1181 Script calls phpinfo()
CVE-2004-1422 Script calls phpinfo()
CVE-2004-1590 Script calls phpinfo()
CVE-2003-1038 Product lists DLLs and full pathnames.
CVE-2005-1205 Telnet protocol allows servers to obtain sensitive environment information from clients.
CVE-2005-0488 Telnet protocol allows servers to obtain sensitive environment information from clients.


This overlaps other categories because some functionality might be intended by the developer, but is considered a weakness by the user or system administrator. In most cases, it is distinct from CWE-209: Information Exposure Through an Error Message because CWE-209 is often unintended.
It's not always clear whether an information exposure is intentional or not. For example, CVE-2005-3261 identifies a PHP script that lists file versions, but it could be that the developer did not intend for this information to be public, but introduced a direct request issue instead.
In vulnerability theory terms, this covers cases in which the developer's Intended Policy allows the information to be made available, but the information might be in violation of a Universal Policy in which the product's administrator should have control over which information is considered sensitive and therefore should not be exposed.


映射的分类名 ImNode ID Fit Mapped Node Name
PLOVER Intended information leak


特别标注: 本站(CN-SEC.COM)所有文章仅供技术研究,若将其信息做其他用途,由用户承担全部法律及连带责任,本站不承担任何法律及连带责任,请遵守中华人民共和国安全法.
  • 我的微信
  • 微信扫一扫
  • weinxin
  • 我的微信公众号
  • 微信扫一扫
  • weinxin
  • 本文由 发表于 2022年1月5日21:01:56
  • 转载请保留本文链接(CN-SEC中文网:感谢原作者辛苦付出):
                  CWE-213 故意性的信息暴露


匿名网友 填写信息

:?: :razz: :sad: :evil: :!: :smile: :oops: :grin: :eek: :shock: :???: :cool: :lol: :mad: :twisted: :roll: :wink: :idea: :arrow: :neutral: :cry: :mrgreen: