CWE-285 - CERT CVE

CWE-285 - Improper Authorization

The software does not perform or incorrectly performs an authorization check when an actor attempts to access a resource or perform an action.

CAPEC ID Naziv
CAPEC-1 Accessing Functionality Not Properly Constrained by ACLs
CAPEC-104 Cross Zone Scripting
CAPEC-127 Directory Indexing
CAPEC-13 Subverting Environment Variable Values
CAPEC-17 Using Malicious Files
CAPEC-39 Manipulating Opaque Client-based Data Tokens
CAPEC-402 Bypassing ATA Password Security
CAPEC-45 Buffer Overflow via Symbolic Links
CAPEC-5 Blue Boxing
CAPEC-51 Poison Web Service Registry
CAPEC-59 Session Credential Falsification through Prediction
CAPEC-60 Reusing Session IDs (aka Session Replay)
CAPEC-647 Collect Data from Registries
CAPEC-76 Manipulating Web Input to File System Calls
CAPEC-77 Manipulating User-Controlled Variables
CAPEC-87 Forceful Browsing