CAPEC 71 Using Unicode Encoding to Bypass Validation Logic

Draft Detailed Medium Risk
Severity High

Description

An attacker may provide a Unicode string to a system component that is not Unicode aware and use that to circumvent the filter or cause the classifying mechanism to fail to properly understanding the request. That may allow the attacker to slip malicious data past the content filter and/or possibly cause the application to route the request incorrectly.

Attack Execution Flow

2

Mitigations

3

Consequences

Indicators

1

Relationships