Umbra Wiki weakness weakness/CWE-433
Back to wiki

CWE-433 — Unparsed Raw Web Content Delivery

provenance: imported · CWE: CWE-433

CWE-433: Unparsed Raw Web Content Delivery

MITRE CWE weakness

Kind Weakness
Abstraction Variant
Status Incomplete
Likelihood of exploit —

Description

The product stores raw content or supporting code under the web document root with an extension that is not specifically handled by the server.

If code is stored in a file with an extension such as ".inc" or ".pl", and the web server does not have a handler for that extension, then the server will likely send the contents of the file directly to the requester without the pre-processing that was expected. When that file contains sensitive information such as database credentials, this may allow the attacker to compromise the application or associated components.

Common consequences

  • Confidentiality: Read Application Data

Mitigations

Architecture and Design — Perform a type check before interpreting files.

Architecture and Design — Do not store sensitive information in files which may be misinterpreted.

References

  • CWE page: https://cwe.mitre.org/data/definitions/433.html
  • CWE list: https://cwe.mitre.org/data/index.html

See all 1,245 pages under Weakness classes (CWE) →

Related pages