Detailedseverity: MediumDraft
CAPEC-460HTTP Parameter Pollution (HPP)
Abstraction
Detailed
Status
Draft
Severity
Medium
Description
An adversary adds duplicate HTTP GET/POST parameters by injecting query string delimiters. Via HPP it may be possible to override existing hardcoded HTTP parameters, modify the application behaviors, access and, potentially exploit, uncontrollable variables, and bypass input validation checkpoints and WAF rules.
Related weaknesses· 3
Related attack patterns· 2
Exploits3
| Type | Target | Confidence | Tier |
|---|---|---|---|
| Weakness | Improper Neutralization of Input Terminatorscwe-147 | 100% | live |
| Weakness | Improper Handling of Extra Parameterscwe-235 | 100% | live |
| Weakness | Improper Neutralization of Argument Delimiters in a Command ('Argument Injection')cwe-88 | 100% | live |
Related by meaning· 6
Nearest entities by semantic similarity across the cs-graph corpus.