CAPEC 597 Absolute Path Traversal

Draft Detailed Unknown Risk

Description

An adversary with access to file system resources, either directly or via application logic, will use various file absolute paths and navigation mechanisms such as \'..\' to extend their range of access to inappropriate areas of the file system. The goal of the adversary is to access directories and files that are intended to be restricted from their access.

Attack Execution Flow

4

Mitigations

12

Consequences

Relationships

Resources Required

1