National Institute of Standards and Technology
Package illustrating a test case

Test case 156757

Description

Test will take in a value that is a path to a file under
the current working directory which will then be displayed. The input
is checked for .. characters, then URI-decoded. This misses
percent-encoded .. (%2E%2E) characters and allows arbitrary read access.
Metadata
- Base program: Apache Lucene
- Source Taint: SOCKET
- Data Type: SIMPLE
- Data Flow: ADDRESS_AS_FUNCTION_RETURN_VALUE
- Control Flow: INDIRECTLY_RECURSIVE

Flaws

Test Suites

Documentation

Have any comments on this test case? Please, send us an email.