CWE-25, also known as 'Path Traversal: Improper Neutralization of Special Elements Used in Path Expression', occurs when an application uses external input to construct a pathname that is intended to identify a file or directory that is located underneath a restricted parent directory, but the application does not properly neutralize special elements within the pathname that can cause the pathname to resolve to a location that is outside of the restricted directory. This can allow attackers to access or manipulate files and directories outside of the intended scope, potentially leading to sensitive information disclosure, arbitrary code execution, or denial of service. A common use case involves web applications where a user-supplied filename is used to construct a file path on the server; without proper sanitization, an attacker might use '..' sequences to traverse up the directory structure and access files outside the web root.
Whether you're looking to get your foot in the door, find the right person to talk to, or close the deal — accurate, detailed, trustworthy, and timely information about the organization you're selling to is invaluable.
Use Sumble to: