Detailedseverity: HighDraft
CAPEC-650Upload a Web Shell to a Web Server
Abstraction
Detailed
Status
Draft
Severity
High
Description
By exploiting insufficient permissions, it is possible to upload a web shell to a web server in such a way that it can be executed remotely. This shell can have various capabilities, thereby acting as a "gateway" to the underlying web server. The shell might execute at the higher permission level of the web server, providing the ability the execute malicious code at elevated levels.
Related weaknesses· 2
MITRE ATT&CK crosswalk· 1
Related attack patterns· 1
Exploits2
| Type | Target | Confidence | Tier |
|---|---|---|---|
| Weakness | Improper Authenticationcwe-287 | 100% | live |
| Weakness | Command Shell in Externally Accessible Directorycwe-553 | 100% | live |
Related to1
| Type | Target | Confidence | Tier |
|---|---|---|---|
| SubTechnique | Web Shellt1505.003 | 100% | live |
Related by meaning· 6
Nearest entities by semantic similarity across the cs-graph corpus.