|
|
|
|
CWE-349 Individual Dictionary Definition (Draft 9)
Weakness ID
| Status: Draft 349 (Weakness Base) | | Description | Summary The software, when processing trusted data, accepts any untrusted data that is also
included with the trusted data, treating the untrusted
data as if it were trusted. | | Observed Examples | | Reference | Description |
|---|
| CVE-2002-0018 | Does not verify that trusted entity is authoritative for all entities in its
response. |
| | Relationships | | | Source Taxonomies | PLOVER - Untrusted Data Appended with Trusted Data | | Applicable Platforms | All | | Related Attack Patterns | | CAPEC-ID | Attack Pattern Name |
|---|
| 75 | Manipulating Writeable Configuration Files |
|
|