CAPEC 107 Cross Site Tracing

Draft Detailed Medium Risk
Severity Very High

Description

Cross Site Tracing (XST) enables an adversary to steal the victim's session cookie and possibly other authentication credentials transmitted in the header of the HTTP request when the victim's browser communicates to a destination system's web server.

Attack Execution Flow

5

Mitigations

2

Consequences

Relationships

Resources Required

1