[Forgot Password]
Login  Register Subscribe

30479

 
 

423868

 
 

248392

 
 

909

 
 

195452

 
 

282

Paid content will be excluded from the download.


Download | Alert*
CWE
view XML

Sensitive Data Under Web Root

ID: 219Date: (C)2012-05-14   (M)2022-10-10
Type: weaknessStatus: DRAFT
Abstraction Type: Variant





Description

The application stores sensitive data under the web document root with insufficient access control, which might make it accessible to untrusted parties.

Applicable Platforms
Language Class: All

Time Of Introduction

  • Operation
  • Implementation

Common Consequences

ScopeTechnical ImpactNotes
Confidentiality
 
Read application data
 
 

Detection Methods
None

Potential Mitigations

PhaseStrategyDescriptionEffectivenessNotes
Implementation
System Configuration
 
 Avoid storing information under the web root directory.
 
  
System Configuration
 
 Access control permissions should be set to prevent reading/writing of sensitive files inside/outside of the web directory.
 
  

Relationships

Related CWETypeViewChain
CWE-219 ChildOf CWE-895 Category CWE-888  

Demonstrative Examples
None

Observed Examples

  1. CVE-2005-1835 : Data file under web root.
  2. CVE-2005-2217 : Data file under web root.
  3. CVE-2002-1449 : Username/password in data file under web root.
  4. CVE-2002-0943 : Database file under web root.
  5. CVE-2005-1645 : database file under web root.

For more examples, refer to CVE relations in the bottom box.

White Box Definitions
None

Black Box Definitions
None

Taxynomy Mappings

TaxynomyIdNameFit
PLOVER  Sensitive Data Under Web Root
 
 
OWASP Top Ten 2004 A10
 
Insecure Configuration Management
 
CWE_More_Specific
 

References:
None

© SecPod Technologies