|
|
|
|
CWE-302 Individual Dictionary Definition (Draft 9)
Weakness ID
| Status: Incomplete 302 (Weakness Variant) | | Description | Summary The authentication scheme or implementation uses key data elements that are assumed to be
immutable, but can be controlled or modified by the attacker, e.g. if a web application relies on
a cookie "Authenticated=1" | | Observed Examples | | | Relationships | | | Source Taxonomies | PLOVER - Authentication Bypass via Assumed-Immutable Data | | Applicable Platforms | All | | Related Attack Patterns | | CAPEC-ID | Attack Pattern Name |
|---|
| 45 | Buffer Overflow via Symbolic Links | | 10 | Buffer Overflow via Environment Variables | | 21 | Exploitation of Session Variables, Resource IDs and other Trusted Credentials | | 39 | Manipulating Opaque Client-based Data Tokens | | 31 | Accessing/Intercepting/Modifying HTTP Cookies | | 13 | Subverting Environment Variable Values | | 77 | Manipulating User-Controlled Variables |
|
|