CWE
Home > CWE List > CWE-565 Individual Dictionary Definition (Draft 9)   View the CWE List

CWE-565 Individual Dictionary Definition (Draft 9)

Use of Cookies in Security Decision
Weakness ID
Status: Incomplete

565 (Weakness Base)

Description

Summary

Attackers can easily modify cookies, and reliance without detailed validation can lead to problems like SQL injection and other errors.

Context Notes

It is dangerous to use cookies to set a user's privileges. The cookie can be manipulated to escalate an attacker's privileges to an administrative level.

Relationships
NatureTypeIDName
ChildOfCategoryCategory254Security Features
ChildOfWeakness ClassWeakness ClassWeakness Class668Exposure of Resource to Wrong Sphere
Source Taxonomies

Anonymous Tool Vendor (under NDA) -

Related Attack Patterns
CAPEC-IDAttack Pattern Name
39Manipulating Opaque Client-based Data Tokens
31Accessing/Intercepting/Modifying HTTP Cookies
Page Last Updated: April 22, 2008