CAPEC 105 HTTP Request Splitting

Stable Detailed Medium Risk
Severity High

Description

{'xhtml:p': ['An adversary abuses the flexibility and discrepancies in the parsing and interpretation of HTTP Request messages by different intermediary HTTP agents (e.g., load balancer, reverse proxy, web caching proxies, application firewalls, etc.) to split a single HTTP request into multiple unauthorized and malicious HTTP requests to a back-end HTTP agent (e.g., web server).', 'See CanPrecede relationships for possible consequences.']}

Attack Execution Flow

4

Mitigations

10

Consequences

Indicators

1

Relationships

Resources Required

1