CAPEC 261 Fuzzing for garnering other adjacent user/sensitive data

Draft Detailed Unknown Risk
Severity Medium

Description

An adversary who is authorized to send queries to a target sends variants of expected queries in the hope that these modified queries might return information (directly or indirectly through error logs) beyond what the expected set of queries should provide.

Attack Execution Flow

4

Consequences

Relationships

Resources Required

1