Weakness ID: 51 (Weakness Variant)Status: Incomplete
A software system that accepts path input in the form of multiple internal slash ('/multiple//internal/slash/') without appropriate validation can lead to ambiguous path resolution and allow an attacker to traverse the file system to unintended locations or access arbitrary files.
+ Time of Introduction
  • Implementation
+ Observed Examples
CVE-2002-1483Read files with full pathname using multiple internal slash.
+ Potential Mitigations

see the vulnerability category "Path Equivalence"

+ Relationships
ChildOfWeakness BaseWeakness Base41Improper Resolution of Path Equivalence
Development Concepts (primary)699
Research Concepts (primary)1000
+ Taxonomy Mappings
PLOVER/multiple//internal/slash ('multiple internal slash')
