CWE-1023
Incomplete Comparison with Missing Factors
Description
The product performs a comparison between entities that must consider multiple factors or characteristics of each entity, but the comparison does not include one or more of these factors.
Parent Weaknesses (ChildOf)
Common Consequences
Scope
Impact
Alter Execution Logic, Bypass Protection Mechanism
CVE-2005-2782PHP remote file inclusion in web application that filters "http" and "https" URLs, but not "ftp".
CVE-2014-6394Product does not prevent access to restricted directories due to partial string comparison with a public directory
Applicable Platforms
Security Training
Train your team to recognize and prevent security threats with our comprehensive security awareness program.
Start TrainingVulnerability Scanning
Discover vulnerabilities in your applications and infrastructure before attackers do.
Scan Now