Home / Vulnerability Database / JavaScript : Path manipulation
JavaScript

JavaScript : Path manipulation

Overview

Using data from an untrusted source when working with the file system may give an attacker access to important system files.

By manipulating variables that reference files with “dot-dot-slash (../)” sequences and its variations or by using absolute file paths, it may be possible to access arbitrary files and directories stored on file system including application source code or configuration and critical system files.

CRITICAL

DerScanner Severity Score

Do you want to fix JavaScript : Path manipulation in your application?

See also

JavaScript

JavaScript : Null salt

JavaScript

JavaScript : Empty encryption key

JavaScript

JavaScript : Unsafe Azure access control