|
|
|
|
CWE-565 Individual Dictionary Definition (Draft 9)
Weakness ID
| Status: Incomplete 565 (Weakness Base) | | Description | Summary Attackers can easily modify cookies, and reliance without detailed validation can lead to
problems like SQL injection and other errors. | | Context Notes | It is dangerous to use cookies to set a user's privileges. The cookie can be
manipulated to escalate an attacker's privileges to an administrative level. | | Relationships | | | Source Taxonomies | Anonymous Tool Vendor (under NDA) - | | Related Attack Patterns | | CAPEC-ID | Attack Pattern Name |
|---|
| 39 | Manipulating Opaque Client-based Data Tokens | | 31 | Accessing/Intercepting/Modifying HTTP Cookies |
|
|