CAPEC --> CWE
Mappings Added
|
CAPEC-217 Exploiting Incorrectly Configured SSL Security Levels |
--> |
CWE-201 |
Information Exposure Through Sent Data |
CAPEC-230 Recursive Payloads Sent to XML Parsers |
--> |
CWE-19 |
Data Handling |
--> |
CWE-20 |
Improper Input Validation |
--> |
CWE-112 |
Missing XML Validation |
--> |
CWE-674 |
Uncontrolled Recursion |
--> |
CWE-770 |
Allocation of Resources Without Limits or Throttling |
CAPEC-231 Oversized Payloads Sent to XML Parsers |
--> |
CWE-19 |
Data Handling |
--> |
CWE-20 |
Improper Input Validation |
--> |
CWE-112 |
Missing XML Validation |
--> |
CWE-674 |
Uncontrolled Recursion |
--> |
CWE-770 |
Allocation of Resources Without Limits or Throttling |
CAPEC-236 Catching exception throw/signal from privileged block |
--> |
CWE-270 |
Privilege Context Switching Error |
CAPEC-250 XML Injection |
--> |
CWE-20 |
Improper Input Validation |
--> |
CWE-74 |
Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection') |
--> |
CWE-91 |
XML Injection (aka Blind XPath Injection) |
--> |
CWE-390 |
Detection of Error Condition Without Action |
--> |
CWE-707 |
Improper Enforcement of Message or Data Structure |
--> |
CWE-713 |
OWASP Top Ten 2007 Category A2 - Injection Flaws |
CAPEC-264 Environment Variable Manipulation |
--> |
CWE-20 |
Improper Input Validation |
--> |
CWE-471 |
Modification of Assumed-Immutable Data (MAID) |
CAPEC-265 Global variable manipulation |
--> |
CWE-20 |
Improper Input Validation |
--> |
CWE-471 |
Modification of Assumed-Immutable Data (MAID) |
CAPEC-484 XML Client-Side Attack |
--> |
CWE-19 |
Data Handling |
--> |
CWE-20 |
Improper Input Validation |
--> |
CWE-112 |
Missing XML Validation |