| New Patterns Added |
|---|
| CAPEC-459 | Creating a Rogue Certificate Authority Certificate |
| CAPEC-460 | HTTP Parameter Pollution (HPP) |
| CAPEC-461 | Web Services API Signature Forgery Leveraging Hash Function Extension Weakness |
| CAPEC-462 | Cross-Domain Search Timing |
| CAPEC-463 | Padding Oracle Crypto Attack |
| CAPEC-464 | Evercookie |
| CAPEC-465 | Socket Capable Browser Plugins Result In Transparent Proxy Abuse |
| CAPEC-466 | Leveraging Active Man in the Middle Attacks to Bypass Single Origin Policy |
| CAPEC-467 | Cross Site Identification |
| CAPEC-468 | Generic Cross-Browser Cross-Domain Theft |
| CAPEC-469 | HTTP DoS |
| CAPEC-470 | Expanding Control over the Operating System from the Database |
| CAPEC-471 | DLL Search Order Hijacking |
| CAPEC-472 | Browser Fingerprinting |
| CAPEC --> CWE Mappings Removed |
|---|
| CAPEC-132 Symlink Attacks |
| --> | CWE-59 | Improper Link Resolution Before File Access ('Link Following') |
| CAPEC-139 Relative Path Traversal |
| --> | CWE-22 | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') |
| CAPEC-147 XML Ping of Death |
| --> | CWE-400 | Uncontrolled Resource Consumption ('Resource Exhaustion') |
| --> | CWE-770 | Allocation of Resources Without Limits or Throttling |
| CAPEC-163 Spear Phishing |
| --> | CWE-184 | Incomplete Blacklist |
| --> | CWE-247 | Reliance on DNS Lookups in a Security Decision |
| --> | CWE-357 | Insufficient UI Warning of Dangerous Operations |
| CAPEC-180 Exploiting Incorrectly Configured Access Control Security Levels |
| --> | CWE-732 | Incorrect Permission Assignment for Critical Resource |
| CAPEC-193 PHP Remote File Inclusion |
| --> | CWE-98 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP File Inclusion') |
| CAPEC-196 Session Credential Falsification through Forging |
| --> | CWE-384 | Session Fixation |
| CAPEC-197 XEE (XML Entity Expansion) |
| --> | CWE-770 | Allocation of Resources Without Limits or Throttling |
| CAPEC-199 Cross-Site Scripting Using Alternate Syntax |
| --> | CWE-79 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') |
| --> | CWE-87 | Improper Neutralization of Alternate XSS Syntax |
| CAPEC-205 Lifting credential(s)/key material embedded in client distributions (thick or thin) |
| --> | CWE-259 | Use of Hard-coded Password |
| --> | CWE-311 | Missing Encryption of Sensitive Data |
| --> | CWE-798 | Use of Hard-coded Credentials |
| CAPEC-219 XML Routing Detour Attacks |
| --> | CWE-441 | Unintended Proxy/Intermediary |
| --> | CWE-610 | Externally Controlled Reference to a Resource in Another Sphere |
| CAPEC-244 Cross-Site Scripting via Encoded URI Schemes |
| --> | CWE-79 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') |
| --> | CWE-84 | Improper Neutralization of Encoded URI Schemes in a Web Page |
| CAPEC-275 DNS Rebinding |
| --> | CWE-247 | Reliance on DNS Lookups in a Security Decision |