Detailedlikelihood: Highseverity: HighDraft
CAPEC-72URL Encoding
Abstraction
Detailed
Status
Draft
Likelihood
High
Severity
High
Description
This attack targets the encoding of the URL. An adversary can take advantage of the multiple way of encoding an URL and abuse the interpretation of the URL.
Metadata: detailed CAPEC pattern, status draft, likelihood high, severity high. Underlying weaknesses: CWE-173, CWE-177, CWE-172, CWE-73, CWE-74 (and 1 more). Related CAPEC pattern: [object Object].
Related weaknesses· 6
Related attack patterns· 1
Exploits6
| Type | Target | Confidence | Tier |
|---|---|---|---|
| Weakness | Improper Handling of Alternate Encodingcwe-173 | 100% | live |
| Weakness | Improper Handling of URL Encoding (Hex Encoding)cwe-177 | 100% | live |
| Weakness | External Control of File Name or Pathcwe-73 | 100% | live |
| Weakness | Improper Input Validationcwe-20 | 100% | live |
| Weakness | Encoding Errorcwe-172 | 100% | live |
| Weakness | Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')cwe-74 | 100% | live |
Related by meaning· 6
Nearest entities by semantic similarity across the cs-graph corpus.