|
|
|
|
CWE-172 Individual Dictionary Definition (Draft 9)
Weakness ID
| Status: Draft 172 (Weakness Class) | | Description | Summary The software fails to properly handle encoding or decoding of the data, resulting in unexpected values. | | Context Notes | Partially overlaps path traversal and equivalence weaknesses. Many other types of encodings should be listed in this category. | | Relationships | | | Source Taxonomies | PLOVER - Encoding Error | | Applicable Platforms | All | | Related Attack Patterns | | CAPEC-ID | Attack Pattern Name |
|---|
| 80 | Using UTF-8 Encoding to Bypass Validation Logic | | 71 | Using Unicode Encoding to Bypass Validation Logic | | 53 | Postfix, Null Terminate, and Backslash | | 72 | URL Encoding | | 64 | Using Slashes and URL Encoding Combined to Bypass Validation Logic | | 3 | Using Leading 'Ghost' Character Sequences to Bypass Input Filters | | 78 | Using Escaped Slashes in Alternate Encoding | | 52 | Embedding NULL Bytes |
|
|