CWE-213 故意性的信息暴露

Intentional Information Exposure

结构: Simple

Abstraction: Base

状态: Draft

被利用可能性: unkown


A product's design or configuration explicitly requires the publication of information that could be regarded as sensitive by an administrator.


  • cwe_Nature: ChildOf cwe_CWE_ID: 200 cwe_View_ID: 1000 cwe_Ordinal: Primary

  • cwe_Nature: ChildOf cwe_CWE_ID: 200 cwe_View_ID: 699 cwe_Ordinal: Primary


Language: {'cwe_Class': 'Language-Independent', 'cwe_Prevalence': 'Undetermined'}


范围 影响 注释
Confidentiality Read Application Data


This code displays some information on a web page.

bad JSP

Social Security Number: <%= ssn %></br>Credit Card Number: <%= ccn %>

The code displays a user's credit card and social security numbers, even though they aren't absolutely necessary.


标识 说明 链接
CVE-2002-1725 Script calls phpinfo()
CVE-2004-0033 Script calls phpinfo()
CVE-2003-1181 Script calls phpinfo()
CVE-2004-1422 Script calls phpinfo()
CVE-2004-1590 Script calls phpinfo()
CVE-2003-1038 Product lists DLLs and full pathnames.
CVE-2005-1205 Telnet protocol allows servers to obtain sensitive environment information from clients.
CVE-2005-0488 Telnet protocol allows servers to obtain sensitive environment information from clients.


Relationship This overlaps other categories because some functionality might be intended by the developer, but is considered a weakness by the user or system administrator. In most cases, it is distinct from CWE-209: Information Exposure Through an Error Message because CWE-209 is often unintended. Other It's not always clear whether an information exposure is intentional or not. For example, CVE-2005-3261 identifies a PHP script that lists file versions, but it could be that the developer did not intend for this information to be public, but introduced a direct request issue instead. Theoretical In vulnerability theory terms, this covers cases in which the developer's Intended Policy allows the information to be made available, but the information might be in violation of a Universal Policy in which the product's administrator should have control over which information is considered sensitive and therefore should not be exposed.


映射的分类名 ImNode ID Fit Mapped Node Name
PLOVER Intended information leak