Standardlikelihood: Highseverity: HighDraft
CAPEC-73User-Controlled Filename
Abstraction
Standard
Status
Draft
Likelihood
High
Severity
High
Description
An attack of this type involves an adversary inserting malicious characters (such as a XSS redirection) into a filename, directly or indirectly that is then used by the target software to generate HTML text or other potentially executable content. Many websites rely on user-generated content and dynamically build resources like files, filenames, and URL links directly from user supplied data. In this attack pattern, the attacker uploads code that can execute in the client browser and/or redirect the client browser to a site that the attacker owns. All XSS attack payload variants can be used to pass and exploit these vulnerabilities.
Related weaknesses· 8
Related attack patterns· 2
Exploits8
| Type | Target | Confidence | Tier |
|---|---|---|---|
| Weakness | Improper Neutralization of Invalid Characters in Identifiers in Web Pagescwe-86 | 100% | live |
| Weakness | Improper Input Validationcwe-20 | 100% | live |
| Weakness | Reliance on Reverse DNS Resolution for a Security-Critical Actioncwe-350 | 100% | live |
| Weakness | Improper Neutralization of Directives in Statically Saved Code ('Static Code Injection')cwe-96 | 100% | live |
| Weakness | Improper Encoding or Escaping of Outputcwe-116 | 100% | live |
| Weakness | Use of Less Trusted Sourcecwe-348 | 100% | live |
| Weakness | Incorrect Comparisoncwe-697 | 100% | live |
| Weakness | Incomplete List of Disallowed Inputscwe-184 | 100% | live |
Related by meaning· 6
Nearest entities by semantic similarity across the cs-graph corpus.