[Forgot Password]
Login  Register Subscribe

30479

 
 

423868

 
 

249461

 
 

909

 
 

195508

 
 

282

Paid content will be excluded from the download.


Download | Alert*
CWE
view XML

Sensitive Data Under FTP Root

ID: 220Date: (C)2012-05-14   (M)2022-10-10
Type: weaknessStatus: DRAFT
Abstraction Type: Variant





Description

The application stores sensitive data under the FTP document root with insufficient access control, which might make it accessible to untrusted parties.

Applicable Platforms
Language Class: All

Time Of Introduction

  • Operation
  • Architecture and Design

Common Consequences

ScopeTechnical ImpactNotes
Confidentiality
 
Read application data
 
 

Detection Methods
None

Potential Mitigations

PhaseStrategyDescriptionEffectivenessNotes
Implementation
System Configuration
 
 Avoid storing information under the FTP root directory.
 
  
System Configuration
 
 Access control permissions should be set to prevent reading/writing of sensitive files inside/outside of the FTP directory.
 
  

Relationships

Related CWETypeViewChain
CWE-220 ChildOf CWE-895 Category CWE-888  

Demonstrative Examples
None

White Box Definitions
None

Black Box Definitions
None

Taxynomy Mappings

TaxynomyIdNameFit
PLOVER  Sensitive Data Under FTP Root
 
 

References:
None

© SecPod Technologies