CAPEC 59 Session Credential Falsification through Prediction

Draft Detailed High Risk
Severity High

Description

This attack targets predictable session ID in order to gain privileges. The attacker can predict the session ID used during a transaction to perform spoofing and session hijacking.

Attack Execution Flow

4

Mitigations

5

Consequences

Relationships