目标达成 感谢每一位支持者 — 我们达成了 100% 目标!

目标: 1000 元 · 已筹: 1359 元

100%

CWE-28 路径遍历:’..filedir’ 类漏洞列表 1

CWE-28 路径遍历:’..filedir’ 类弱点 1 条 CVE 漏洞汇总,含 AI 中文分析。

CWE-28 属于路径遍历漏洞,指程序未正确过滤外部输入中的“..\”序列,导致构造的路径突破受限目录限制。攻击者利用此缺陷遍历文件系统,访问敏感文件或目录。开发者应通过严格验证输入、使用白名单机制或规范化路径来消除非法序列,确保文件访问始终限定在预期范围内,从而有效防御此类安全风险。

MITRE CWE 官方描述
CWE:CWE-28 路径遍历 (Path Traversal):'..\filedir' 英文:产品使用外部输入来构建一个应位于受限目录内的路径名,但它未能正确中和 "..\" 序列,而这些序列可能解析到该目录之外的位置。 这允许攻击者遍历文件系统,以访问受限目录之外的文件或目录。"..\\" 操作是针对使用 "\" 作为目录分隔符的操作系统(如 Windows)的标准操作。然而,它对于绕过仅假设 "/" 分隔符有效的路径遍历保护方案也很有用。
常见影响 (1)
Confidentiality, Integrity Read Files or Directories, Modify Files or Directories
缓解措施 (2)
Implementation Assume all input is malicious. Use an "accept known good" input validation strategy, i.e., use a list of acceptable inputs that strictly conform to specifications. Reject any input that does not strictly conform to specifications, or transform it into something that does. When performing input validation, consider all potentially relevant properties, including length, type of input, the full range…
Implementation Inputs should be decoded and canonicalized to the application's current internal representation before being validated (CWE-180). Make sure that the application does not decode the same input twice (CWE-174). Such errors could be used to bypass allowlist validation schemes by introducing dangerous inputs after they have been checked.
CVE ID 标题 CVSS 风险等级 Published
CVE-2023-2059 DedeCMS 安全漏洞 — DedeCMS 4.3 Medium 2023-04-14

CWE-28(路径遍历:’..filedir’) 是常见的弱点类别,本平台收录该类弱点关联的 1 条 CVE 漏洞。