Sensitive Data Under Web Root |
Weakness ID: 219 (Weakness Variant) | Status: Draft |
Description Summary
The application stores sensitive data under the web document root with insufficient access control, which might make it accessible to untrusted parties.
Reference | Description |
---|---|
CVE-2005-1835 | Data file under web root. |
CVE-2005-2217 | Data file under web root. |
CVE-2002-1449 | Username/password in data file under web root. |
CVE-2002-0943 | Database file under web root. |
CVE-2005-1645 | database file under web root. |
Avoid storing information under the web root directory. |
Access control permissions should be set to prevent reading/writing of sensitive files inside/outside of the web directory. |
Nature | Type | ID | Name | View(s) this relationship pertains to![]() |
---|---|---|---|---|
ChildOf | ![]() | 216 | Containment Errors (Container Errors) | Development Concepts (primary)699 Research Concepts1000 |
ChildOf | ![]() | 285 | Improper Access Control (Authorization) | Research Concepts (primary)1000 |
ChildOf | ![]() | 731 | OWASP Top Ten 2004 Category A10 - Insecure Configuration Management | Weaknesses in OWASP Top Ten (2004) (primary)711 |
CanPrecede | ![]() | 668 | Exposure of Resource to Wrong Sphere | Research Concepts1000 |
ParentOf | ![]() | 433 | Unparsed Raw Web Content Delivery | Research Concepts (primary)1000 |
Mapped Taxonomy Name | Node ID | Fit | Mapped Node Name |
---|---|---|---|
PLOVER | Sensitive Data Under Web Root | ||
OWASP Top Ten 2004 | A10 | CWE More Specific | Insecure Configuration Management |
Submissions | ||||
---|---|---|---|---|
Submission Date | Submitter | Organization | Source | |
PLOVER | Externally Mined | |||
Modifications | ||||
Modification Date | Modifier | Organization | Source | |
2008-07-01 | Eric Dalci | Cigital | External | |
updated Time of Introduction | ||||
2008-08-15 | Veracode | External | ||
Suggested OWASP Top Ten 2004 mapping | ||||
2008-09-08 | CWE Content Team | MITRE | Internal | |
updated Relationships, Taxonomy Mappings | ||||
2009-12-28 | CWE Content Team | MITRE | Internal | |
updated Relationships |