CWE-73 - CERT CVE

CWE-73 - External Control of File Name or Path

The software allows user input to control or influence paths or file names that are used in filesystem operations.

CAPEC ID Naziv
CAPEC-13 Subverting Environment Variable Values
CAPEC-267 Leverage Alternate Encoding
CAPEC-64 Using Slashes and URL Encoding Combined to Bypass Validation Logic
CAPEC-72 URL Encoding
CAPEC-76 Manipulating Web Input to File System Calls
CAPEC-78 Using Escaped Slashes in Alternate Encoding
CAPEC-79 Using Slashes in Alternate Encoding
CAPEC-80 Using UTF-8 Encoding to Bypass Validation Logic