CWE-37: Path Traversal: '/absolute/pathname/here'
VariantDraft
The product accepts input in the form of a slash absolute path ('/absolute/pathname/here') without appropriate validation, which can allow an attacker to traverse the file system to unintended locations or access arbitrary files.
View on MITREBack to CWE Lookup
Technical Details
- Structure
- Simple
Applicable To
Not Language-Specific