Standardlikelihood: Highseverity: HighDraft
CAPEC-87Forceful Browsing
Abstraction
Standard
Status
Draft
Likelihood
High
Severity
High
Description
An attacker employs forceful browsing (direct URL entry) to access portions of a website that are otherwise unreachable. Usually, a front controller or similar design pattern is employed to protect access to portions of a web application. Forceful browsing enables an attacker to access information, perform privileged operations and otherwise reach sections of the web application that have been improperly protected.
Related weaknesses· 3
Related attack patterns· 1
Exploits3
| Type | Target | Confidence | Tier |
|---|---|---|---|
| Weakness | Improper Authorizationcwe-285 | 100% | live |
| Weakness | Protection Mechanism Failurecwe-693 | 100% | live |
| Weakness | Direct Request ('Forced Browsing')cwe-425 | 100% | live |
Related by meaning· 6
Nearest entities by semantic similarity across the cs-graph corpus.