Standardlikelihood: Highseverity: Very HighDraft
CAPEC-75Manipulating Writeable Configuration Files
Abstraction
Standard
Status
Draft
Likelihood
High
Severity
Very High
Description
Generally these are manually edited files that are not in the preview of the system administrators, any ability on the attackers' behalf to modify these files, for example in a CVS repository, gives unauthorized access directly to the application, the same as authorized users.
Metadata: standard CAPEC pattern, status draft, likelihood high, severity very high. Underlying weaknesses: CWE-349, CWE-99, CWE-77, CWE-346, CWE-353 (and 1 more). Related CAPEC pattern: [object Object].
Related weaknesses· 6
Related attack patterns· 1
Exploits6
| Type | Target | Confidence | Tier |
|---|---|---|---|
| Weakness | Acceptance of Extraneous Untrusted Data With Trusted Datacwe-349 | 100% | live |
| Weakness | Improper Control of Resource Identifiers ('Resource Injection')cwe-99 | 100% | live |
| Weakness | Improper Neutralization of Special Elements used in a Command ('Command Injection')cwe-77 | 100% | live |
| Weakness | Origin Validation Errorcwe-346 | 100% | live |
| Weakness | Improper Validation of Integrity Check Valuecwe-354 | 100% | live |
| Weakness | Missing Support for Integrity Checkcwe-353 | 100% | live |
Related by meaning· 6
Nearest entities by semantic similarity across the cs-graph corpus.