CAPEC 198 XSS Targeting Error Pages

Draft Detailed Unknown Risk
Severity Medium

Description

An adversary distributes a link (or possibly some other query structure) with a request to a third party web server that is malformed and also contains a block of exploit code in order to have the exploit become live code in the resulting error page.

Attack Execution Flow

4

Mitigations

3

Consequences

Relationships

Resources Required

1