VariantDraft
CWE-97Improper Neutralization of Server-Side Includes (SSI) Within a Web Page
Category: other
Description
The product generates a web page, but does not neutralize or incorrectly neutralizes user-controllable input that could be interpreted as a server-side include (SSI) directive.
Common consequences· 1
- Confidentiality / Integrity / Availability — Execute Unauthorized Code or Commands
Related CAPEC attack patterns· 2
References
Exploits (incoming)2
| Type | Target | Confidence | Tier |
|---|---|---|---|
| AttackPattern | Server Side Include (SSI) Injectioncapec-101 | 100% | live |
| AttackPattern | Leverage Executable Code in Non-Executable Filescapec-35 | 100% | live |
(incoming)1
| Type | Target | Confidence | Tier |
|---|---|---|---|
| Vulnerability | CVE-2025-35996cve-2025-35996 | 0% | live |
Related by meaning· 6
Nearest entities by semantic similarity across the cs-graph corpus.