Detailedlikelihood: Mediumseverity: HighDraft
CAPEC-11Cause Web Server Misclassification
Abstraction
Detailed
Status
Draft
Likelihood
Medium
Severity
High
Description
An attack of this type exploits a Web server's decision to take action based on filename or file extension. Because different file types are handled by different server processes, misclassification may force the Web server to take unexpected action, or expected actions in an unexpected sequence. This may cause the server to exhaust resources, supply debug or system data to the attacker, or bind an attacker to a remote process.
Related weaknesses· 1
MITRE ATT&CK crosswalk· 1
Related attack patterns· 1
Exploits1
| Type | Target | Confidence | Tier |
|---|---|---|---|
| Weakness | Deployment of Wrong Handlercwe-430 | 100% | live |
Related to1
| Type | Target | Confidence | Tier |
|---|---|---|---|
| SubTechnique | Space after Filenamet1036.006 | 100% | live |
Related by meaning· 6
Nearest entities by semantic similarity across the cs-graph corpus.