COMMON ATTACK PATTERN ENUMERATION AND CLASSIFICATIONLive MITRE record
CAPEC-76
Manipulating Web Input to File System Calls
Abstraction
Detailed
Typical severity
Very High
Likelihood of attack
High
Understand the attack
What is this attack pattern?
Execution flow
How does the attack proceed, step by step?
Explore
Fingerprinting of the operating system
Techniques used
Survey the Application to Identify User-controllable Inputs
Techniques used
Experiment
Vary inputs, looking for malicious results
Techniques used
Exploit
Manipulate files accessible by the application
Techniques used
Requirements
What does the attack require?
Prerequisites
Skills required
Resources required
Not stated in the MITRE record.
Impact
What does a successful attack lead to?
Gain Privileges
Modify Data
Defence
How is it prevented and mitigated?
1
2
3
4
5
Real world