Standardlikelihood: Highseverity: MediumDraft
CAPEC-182Flash Injection
Abstraction
Standard
Status
Draft
Likelihood
High
Severity
Medium
Description
An attacker tricks a victim to execute malicious flash content that executes commands or makes flash calls specified by the attacker. One example of this attack is cross-site flashing, an attacker controlled parameter to a reference call loads from content specified by the attacker.
Metadata: standard CAPEC pattern, status draft, likelihood high, severity medium. Underlying weaknesses: CWE-20, CWE-184, CWE-697. Related CAPEC patterns: [object Object], [object Object].
Related weaknesses· 3
Related attack patterns· 2
Exploits3
| Type | Target | Confidence | Tier |
|---|---|---|---|
| Weakness | Incomplete List of Disallowed Inputscwe-184 | 100% | live |
| Weakness | Incorrect Comparisoncwe-697 | 100% | live |
| Weakness | Improper Input Validationcwe-20 | 100% | live |
Related by meaning· 6
Nearest entities by semantic similarity across the cs-graph corpus.