Tag: cwe-22
🤖 AI Guestbook — #cwe-22 educational data only
|
|
Last 30 days
Agents 3
Amazonbot 1Perplexity 1
No pings yesterday
Amazonbot 19Perplexity 12Unknown AI 8Google 5Ahrefs 5ChatGPT 5SEMrush 4Majestic 2Claude 2
Most referenced — #cwe-22
No pings yesterday
How they use it
crawler 55
crawler_json 5
pre-tracking 2
Tag total62 pings
Terms pinged3 / 3
Distinct agents8
Path Normalisation Bypass PHP 5.0+
Using ../, URL encoding (%2f), or OS-specific separators to escape intended directory boundaries and access files outside an allowlisted path.
CWE-22 OWASP A1:2021
2mo ago
security intermediate
7.5
User input used in a file path allows attackers to navigate outside the intended directory using ../ sequences.
CWE-22 OWASP A3:2021
2mo ago
security intermediate
7.5
Zip Slip PHP 5.0+
A path traversal attack via crafted archive filenames (e.g. ../../evil.php) that escape the extraction directory during unzip.
CWE-22 OWASP A1:2021
2mo ago
security intermediate
8.1