This page is experimental and may change significantly in future releases.
Path Equivalence: '//multiple/leading/slash'
Properties
id: d3f:CWE-50
- name
- Path Equivalence: '//multiple/leading/slash'
- definition
- The product accepts path input in the form of multiple leading slash ('//multiple/leading/slash') without appropriate validation, which can lead to ambiguous path resolution and allow an attacker to traverse the file system to unintended locations or access arbitrary files.
Neighbors
CWE-50 has no direct neighbors in this release.Inferred Relationships
Related Countermeasure Techniques
Related Weaknesses
CWE-50 has no related weaknesses in this release.