Category-21: 路径名遍历和等值错误

admin 2021年12月4日16:23:40评论67 views字数 832阅读2分46秒阅读模式

Category-21: 路径名遍历和等值错误

ID: 21
Status: Incomplete


Weaknesses in this category can be used to access files outside of a restricted directory (path traversal) or to perform operations on files that would otherwise be restricted (path equivalence). Files, directories, and folders are so central to information technology that many different weaknesses and variants have been discovered. The manipulations generally involve special characters or sequences in pathnames, or the use of alternate references or channels.


CWE-22 对路径名的限制不恰当(路径遍历)
CWE-41 对路径等价的解析不恰当
CWE-59 在文件访问前对链接解析不恰当(链接跟随)
CWE-66 标识虚拟资源的文件名处理不恰当

Taxonomy Mappings

Mapped Taxonomy Name Node ID Fit Mapped Node Name
PLOVER Pathname Traversal and Equivalence Errors


相关推荐: View-630: DEPRECATED: Weaknesses Examined by SAMATE

View-630: DEPRECATED: Weaknesses Examined by SAMATE ID: 630 Type: Explicit Status: Deprecated Objective This view has been depreca…

  • 左青龙
  • 微信扫一扫
  • weinxin
  • 右白虎
  • 微信扫一扫
  • weinxin
  • 本文由 发表于 2021年12月4日16:23:40
  • 转载请保留本文链接(CN-SEC中文网:感谢原作者辛苦付出):
                   Category-21: 路径名遍历和等值错误


匿名网友 填写信息