| CAPEC-ID | Attack Pattern Name |
|---|
| 10 | Buffer Overflow via Environment Variables |
| 31 | Accessing/Intercepting/Modifying HTTP Cookies |
| 13 | Subverting Environment Variable Values |
| 32 | Embedding Scripts in HTTP Query Strings |
| 14 | Client-side Injection-induced Buffer Overflow |
| 52 | Embedding NULL Bytes |
| 71 | Using Unicode Encoding to Bypass Validation Logic |
| 53 | Postfix, Null Terminate, and Backslash |
| 72 | URL Encoding |
| 18 | Embedding Scripts in Nonscript Elements |
| 91 | XSS in IMG Tags |
| 73 | User-Controlled Filename |
| 78 | Using Escaped Slashes in Alternate Encoding |
| 79 | Using Slashes in Alternate Encoding |
| 99 | XML Parser Attack |
| 101 | Server Side Include (SSI) Injection |
| 22 | Exploiting Trust in Client (aka Make the Client Invisible) |
| 24 | Filter Failure through Buffer Overflow |
| 42 | MIME Conversion |
| 43 | Exploiting Multiple Input Interpretation Layers |
| 80 | Using UTF-8 Encoding to Bypass Validation Logic |
| 45 | Buffer Overflow via Symbolic Links |
| 63 | Simple Script Injection |
| 81 | Web Logs Tampering |
| 28 | Fuzzing |
| 46 | Overflow Variables and Tags |
| 64 | Using Slashes and URL Encoding Combined to Bypass Validation Logic |
| 47 | Buffer Overflow via Parameter Expansion |
| 83 | XPath Injection |
| 66 | SQL Injection |
| 67 | String Format Overflow in syslog() |
| 85 | Client Network Footprinting (using AJAX/XSS) |
| 86 | Embedding Script (XSS ) in HTTP Headers |
| 88 | OS Command Injection |
| 3 | Using Leading 'Ghost' Character Sequences to Bypass Input Filters |
| 7 | Blind SQL Injection |
| 8 | Buffer Overflow in an API Call |
| 9 | Buffer Overflow in Local Command-Line Utilities |