Standardlikelihood: Highseverity: HighDraft
CAPEC-267Leverage Alternate Encoding
Abstraction
Standard
Status
Draft
Likelihood
High
Severity
High
Description
An adversary leverages the possibility to encode potentially harmful input or content used by applications such that the applications are ineffective at validating this encoding standard.
Metadata: standard CAPEC pattern, status draft, likelihood high, severity high. Underlying weaknesses: CWE-173, CWE-172, CWE-180, CWE-181, CWE-73 (and 4 more). Mapped ATT&CK technique: [object Object]. Related CAPEC pattern: [object Object].
Related weaknesses· 9
MITRE ATT&CK crosswalk· 1
Related attack patterns· 1
Exploits9
| Type | Target | Confidence | Tier |
|---|---|---|---|
| Weakness | Improper Input Validationcwe-20 | 100% | live |
| Weakness | Incorrect Behavior Order: Validate Before Filtercwe-181 | 100% | live |
| Weakness | Incorrect Comparisoncwe-697 | 100% | live |
| Weakness | Incorrect Behavior Order: Validate Before Canonicalizecwe-180 | 100% | live |
| Weakness | Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')cwe-74 | 100% | live |
| Weakness | Incomplete Denylist to Cross-Site Scriptingcwe-692 | 100% | live |
| Weakness | External Control of File Name or Pathcwe-73 | 100% | live |
| Weakness | Improper Handling of Alternate Encodingcwe-173 | 100% | live |
| Weakness | Encoding Errorcwe-172 | 100% | live |
Related to1
| Type | Target | Confidence | Tier |
|---|---|---|---|
| Technique | Obfuscated Files or Informationt1027 | 100% | live |
Related by meaning· 6
Nearest entities by semantic similarity across the cs-graph corpus.