Detailedlikelihood: Highseverity: HighDraft
CAPEC-93Log Injection-Tampering-Forging
Abstraction
Detailed
Status
Draft
Likelihood
High
Severity
High
Description
This attack targets the log files of the target host. The attacker injects, manipulates or forges malicious log entries in the log file, allowing them to mislead a log audit, cover traces of attack, or perform other malicious actions. The target host is not properly controlling log access. As a result tainted data is resulting in the log files leading to a failure in accountability, non-repudiation and incident forensics capability.
Related weaknesses· 3
Related attack patterns· 2
Exploits3
| Type | Target | Confidence | Tier |
|---|---|---|---|
| Weakness | Improper Neutralization of Escape, Meta, or Control Sequencescwe-150 | 100% | live |
| Weakness | Improper Output Neutralization for Logscwe-117 | 100% | live |
| Weakness | Failure to Sanitize Special Elements into a Different Plane (Special Element Injection)cwe-75 | 100% | live |
Related by meaning· 6
Nearest entities by semantic similarity across the cs-graph corpus.