New Patterns Added |
---|
CAPEC-459 | Creating a Rogue Certificate Authority Certificate |
CAPEC-460 | HTTP Parameter Pollution (HPP) |
CAPEC-461 | Web Services API Signature Forgery Leveraging Hash Function Extension Weakness |
CAPEC-462 | Cross-Domain Search Timing |
CAPEC-463 | Padding Oracle Crypto Attack |
CAPEC-464 | Evercookie |
CAPEC-465 | Socket Capable Browser Plugins Result In Transparent Proxy Abuse |
CAPEC-466 | Leveraging Active Man in the Middle Attacks to Bypass Single Origin Policy |
CAPEC-467 | Cross Site Identification |
CAPEC-468 | Generic Cross-Browser Cross-Domain Theft |
CAPEC-469 | HTTP DoS |
CAPEC-470 | Expanding Control over the Operating System from the Database |
CAPEC-471 | DLL Search Order Hijacking |
CAPEC-472 | Browser Fingerprinting |
CAPEC --> CWE Mappings Removed |
---|
CAPEC-132 Symlink Attacks |
--> | CWE-59 | Improper Link Resolution Before File Access ('Link Following') |
CAPEC-139 Relative Path Traversal |
--> | CWE-22 | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') |
CAPEC-147 XML Ping of Death |
--> | CWE-400 | Uncontrolled Resource Consumption ('Resource Exhaustion') |
--> | CWE-770 | Allocation of Resources Without Limits or Throttling |
CAPEC-163 Spear Phishing |
--> | CWE-184 | Incomplete Blacklist |
--> | CWE-247 | Reliance on DNS Lookups in a Security Decision |
--> | CWE-357 | Insufficient UI Warning of Dangerous Operations |
CAPEC-180 Exploiting Incorrectly Configured Access Control Security Levels |
--> | CWE-732 | Incorrect Permission Assignment for Critical Resource |
CAPEC-193 PHP Remote File Inclusion |
--> | CWE-98 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP File Inclusion') |
CAPEC-196 Session Credential Falsification through Forging |
--> | CWE-384 | Session Fixation |
CAPEC-197 XEE (XML Entity Expansion) |
--> | CWE-770 | Allocation of Resources Without Limits or Throttling |
CAPEC-199 Cross-Site Scripting Using Alternate Syntax |
--> | CWE-79 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') |
--> | CWE-87 | Improper Neutralization of Alternate XSS Syntax |
CAPEC-205 Lifting credential(s)/key material embedded in client distributions (thick or thin) |
--> | CWE-259 | Use of Hard-coded Password |
--> | CWE-311 | Missing Encryption of Sensitive Data |
--> | CWE-798 | Use of Hard-coded Credentials |
CAPEC-219 XML Routing Detour Attacks |
--> | CWE-441 | Unintended Proxy/Intermediary |
--> | CWE-610 | Externally Controlled Reference to a Resource in Another Sphere |
CAPEC-244 Cross-Site Scripting via Encoded URI Schemes |
--> | CWE-79 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') |
--> | CWE-84 | Improper Neutralization of Encoded URI Schemes in a Web Page |
CAPEC-275 DNS Rebinding |
--> | CWE-247 | Reliance on DNS Lookups in a Security Decision |