Detailedlikelihood: Highseverity: Very HighDraft
CAPEC-76Manipulating Web Input to File System Calls
Abstraction
Detailed
Status
Draft
Likelihood
High
Severity
Very High
Description
An attacker manipulates inputs to the target software which the target software passes to file system calls in the OS. The goal is to gain access to, and perhaps modify, areas of the file system that the target software did not intend to be accessible.
Metadata: detailed CAPEC pattern, status draft, likelihood high, severity very high. Underlying weaknesses: CWE-23, CWE-22, CWE-73, CWE-77, CWE-346 (and 6 more). Related CAPEC pattern: [object Object].
Related weaknesses· 11
Related attack patterns· 1
Exploits11
| Type | Target | Confidence | Tier |
|---|---|---|---|
| Weakness | Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')cwe-74 | 100% | live |
| Weakness | Improper Authorizationcwe-285 | 100% | live |
| Weakness | External Control of File Name or Pathcwe-73 | 100% | live |
| Weakness | Origin Validation Errorcwe-346 | 100% | live |
| Weakness | Improper Link Resolution Before File Access ('Link Following')cwe-59 | 100% | live |
| Weakness | Relative Path Traversalcwe-23 | 100% | live |
| Weakness | Use of Less Trusted Sourcecwe-348 | 100% | live |
| Weakness | Improper Neutralization of Special Elements used in a Command ('Command Injection')cwe-77 | 100% | live |
| Weakness | External Control of System or Configuration Settingcwe-15 | 100% | live |
| Weakness | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')cwe-22 | 100% | live |
| Weakness | Least Privilege Violationcwe-272 | 100% | live |
Related by meaning· 6
Nearest entities by semantic similarity across the cs-graph corpus.