Standardlikelihood: Mediumseverity: HighDraft

CAPEC-104Cross Zone Scripting

Abstraction
Standard
Status
Draft
Likelihood
Medium
Severity
High

Description

An attacker is able to cause a victim to load content into their web-browser that bypasses security zone controls and gain access to increased privileges to execute scripting code or other web objects such as unsigned ActiveX controls or applets. This is a privilege elevation attack targeted at zone-based web-browser security.

Related weaknesses· 5

CWE-250CWE-638CWE-285CWE-116CWE-20

Related attack patterns· 1

CAPEC-233 (ChildOf)

Exploits5

TypeTargetConfidenceTier
WeaknessImproper Input Validationcwe-20100%live
WeaknessImproper Authorizationcwe-285100%live
WeaknessExecution with Unnecessary Privilegescwe-250100%live
WeaknessNot Using Complete Mediationcwe-638100%live
WeaknessImproper Encoding or Escaping of Outputcwe-116100%live

Related by meaning· 6

Nearest entities by semantic similarity across the cs-graph corpus.

CAPEC
Cross-Site Scripting (XSS)
CAPEC
Cross-Site Flashing
CAPEC
Cross Frame Scripting (XFS)
CAPEC
Exploit Script-Based APIs
CAPEC
Cross Site Request Forgery
CAPEC
Cross Site Tracing
Sourced from MITRE CAPEC. Curated by Adam Lundqvist, SQUR.