Back to Labs
Weakness (CWE)

CWE-44

Path Equivalence: 'file.name' (Internal Dot)

About

The product accepts path input in the form of internal dot ('file.ordir') without appropriate validation, which can lead to ambiguous path resolution and allow an attacker to traverse the file system to unintended locations or access arbitrary files.

Common consequences

  • Confidentiality, Integrity → Read Files or Directories, Modify Files or Directories

CVEs with this weakness

Frequently asked questions

What is CWE-44?

The product accepts path input in the form of internal dot ('file.ordir') without appropriate validation, which can lead to ambiguous path resolution and allow an attacker to traverse the file system to unintended locations or access arbitrary files. Common consequences Confidentiality, Integrity → Read Files or Directories, Modify Files or Directories

How many CVEs does Rainforest track for CWE-44?

Rainforest Labs currently tracks 1 published CVEs mapped to CWE-44. They are listed on this page.

Empower Your Security Strategy with Rainforest

Discover vulnerabilities early, prioritize critical threats, and protect what truly matters. Rainforest streamlines your security operations, saving you time and reducing costs, so you can focus on what drives your business forward.