CAPEC 87 Forceful Browsing

Draft Standard High Risk
Severity High

Description

An attacker employs forceful browsing (direct URL entry) to access portions of a website that are otherwise unreachable. Usually, a front controller or similar design pattern is employed to protect access to portions of a web application. Forceful browsing enables an attacker to access information, perform privileged operations and otherwise reach sections of the web application that have been improperly protected.

Attack Execution Flow

4

Mitigations

2

Consequences

Relationships

Resources Required

1