CWE-707 - CERT CVE

CWE-707 - Improper Neutralization

The product does not ensure or incorrectly ensures that structured messages or data are well-formed and that certain security properties are met before being read from an upstream component or sent to a downstream component.

CAPEC ID Naziv
CAPEC-250 XML Injection
CAPEC-276 Inter-component Protocol Manipulation
CAPEC-277 Data Interchange Protocol Manipulation
CAPEC-278 Web Services Protocol Manipulation
CAPEC-279 SOAP Manipulation
CAPEC-3 Using Leading 'Ghost' Character Sequences to Bypass Input Filters
CAPEC-33 HTTP Request Smuggling
CAPEC-34 HTTP Response Splitting
CAPEC-43 Exploiting Multiple Input Interpretation Layers
CAPEC-468 Generic Cross-Browser Cross-Domain Theft
CAPEC-52 Embedding NULL Bytes
CAPEC-53 Postfix, Null Terminate, and Backslash
CAPEC-64 Using Slashes and URL Encoding Combined to Bypass Validation Logic
CAPEC-7 Blind SQL Injection
CAPEC-78 Using Escaped Slashes in Alternate Encoding
CAPEC-79 Using Slashes in Alternate Encoding
CAPEC-83 XPath Injection
CAPEC-84 XQuery Injection