CAPEC-CAPEC-649 - CERT CVE
Naziv

Adding a Space to a File Extension

Sažetak An adversary adds a space character to the end of a file extension and takes advantage of an application that does not properly neutralize trailing special elements in file names. This extra space, which can be difficult for a user to notice, affects which default application is used to operate on the file and can be leveraged by the adversary to control execution.
Preduvjeti The use of the file must be controlled by the file extension.
Rješenja File extensions should be checked to see if non-visible characters are being included.