Standardlikelihood: Highseverity: HighDraft
CAPEC-6Argument Injection
Abstraction
Standard
Status
Draft
Likelihood
High
Severity
High
Description
An attacker changes the behavior or state of a targeted application through injecting data or command syntax through the targets use of non-validated and non-filtered arguments of exposed services or methods.
Metadata: standard CAPEC pattern, status draft, likelihood high, severity high. Underlying weaknesses: CWE-74, CWE-146, CWE-184, CWE-78, CWE-185 (and 1 more). Related CAPEC pattern: [object Object].
Related weaknesses· 6
Related attack patterns· 1
Exploits6
| Type | Target | Confidence | Tier |
|---|---|---|---|
| Weakness | Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')cwe-74 | 100% | live |
| Weakness | Incorrect Comparisoncwe-697 | 100% | live |
| Weakness | Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')cwe-78 | 100% | live |
| Weakness | Improper Neutralization of Expression/Command Delimiterscwe-146 | 100% | live |
| Weakness | Incorrect Regular Expressioncwe-185 | 100% | live |
| Weakness | Incomplete List of Disallowed Inputscwe-184 | 100% | live |
Related by meaning· 6
Nearest entities by semantic similarity across the cs-graph corpus.