WASC Threat Classification 2.0
View ID: 333 (View: Graph)Status: Draft
+ View Data

View Structure: Graph

View Objective

CAPEC nodes in this view (graph) are associated with the WASC Threat Classification 2.0.

+ Relationships
NatureTypeIDNameDescriptionView(s) this relationship pertains toView\(s\)
HasMemberCategoryCategory334WASC Threat Classification 2.0 - WASC-01 - Insufficient Authentication 
WASC Threat Classification 2.0333
HasMemberCategoryCategory335WASC Threat Classification 2.0 - WASC-02 - Insufficient Authorization 
WASC Threat Classification 2.0333
HasMemberCategoryCategory336WASC Threat Classification 2.0 - WASC-03 - Integer Overflows 
WASC Threat Classification 2.0333
HasMemberCategoryCategory337WASC Threat Classification 2.0 - WASC-04 - Insufficient Transport Layer Protection 
WASC Threat Classification 2.0333
HasMemberCategoryCategory338WASC Threat Classification 2.0 - WASC-05 - Remote File Inclusion 
WASC Threat Classification 2.0333
HasMemberCategoryCategory339WASC Threat Classification 2.0 - WASC-06 - Format String 
WASC Threat Classification 2.0333
HasMemberCategoryCategory340WASC Threat Classification 2.0 - WASC-07 - Buffer Overflow 
WASC Threat Classification 2.0333
HasMemberCategoryCategory341WASC Threat Classification 2.0 - WASC-08 - Cross-Site Scripting 
WASC Threat Classification 2.0333
HasMemberCategoryCategory342WASC Threat Classification 2.0 - WASC-09 - Cross-Site Request Forgery 
WASC Threat Classification 2.0333
HasMemberCategoryCategory343WASC Threat Classification 2.0 - WASC-10 - Denial of Service 
WASC Threat Classification 2.0333
HasMemberCategoryCategory344WASC Threat Classification 2.0 - WASC-11 - Brute Force 
WASC Threat Classification 2.0333
HasMemberCategoryCategory345WASC Threat Classification 2.0 - WASC-12 - Content Spoofing 
WASC Threat Classification 2.0333
HasMemberCategoryCategory346WASC Threat Classification 2.0 - WASC-13 - Information Leakage 
WASC Threat Classification 2.0333
HasMemberCategoryCategory347WASC Threat Classification 2.0 - WASC-14 - Server Misconfiguration 
WASC Threat Classification 2.0333
HasMemberCategoryCategory348WASC Threat Classification 2.0 - WASC-15 - Application Misconfiguration 
WASC Threat Classification 2.0333
HasMemberCategoryCategory349WASC Threat Classification 2.0 - WASC-16 - Directory Indexing 
WASC Threat Classification 2.0333
HasMemberCategoryCategory350WASC Threat Classification 2.0 - WASC-17 - Improper Filesystem Permissions 
WASC Threat Classification 2.0333
HasMemberCategoryCategory351WASC Threat Classification 2.0 - WASC-18 - Credential/Session Prediction 
WASC Threat Classification 2.0333
HasMemberCategoryCategory352WASC Threat Classification 2.0 - WASC-19 - SQL Injection 
WASC Threat Classification 2.0333
HasMemberCategoryCategory353WASC Threat Classification 2.0 - WASC-20 - Improper Input Handling 
WASC Threat Classification 2.0333
HasMemberCategoryCategory354WASC Threat Classification 2.0 - WASC-21 - Insufficient Anti-automation 
WASC Threat Classification 2.0333
HasMemberCategoryCategory355WASC Threat Classification 2.0 - WASC-22 - Improper Output Handling 
WASC Threat Classification 2.0333
HasMemberCategoryCategory356WASC Threat Classification 2.0 - WASC-23 - XML Injection 
WASC Threat Classification 2.0333
HasMemberCategoryCategory357WASC Threat Classification 2.0 - WASC-24 - HTTP Request Splitting 
WASC Threat Classification 2.0333
HasMemberCategoryCategory358WASC Threat Classification 2.0 - WASC-25 - HTTP Response Splitting 
WASC Threat Classification 2.0333
HasMemberCategoryCategory359WASC Threat Classification 2.0 - WASC-26 - HTTP Request Smuggling 
WASC Threat Classification 2.0333
HasMemberCategoryCategory360WASC Threat Classification 2.0 - WASC-27 - HTTP Response Smuggling 
WASC Threat Classification 2.0333
HasMemberCategoryCategory361WASC Threat Classification 2.0 - WASC-28 - Null Byte Injection 
WASC Threat Classification 2.0333
HasMemberCategoryCategory362WASC Threat Classification 2.0 - WASC-29 - LDAP Injection 
WASC Threat Classification 2.0333
HasMemberCategoryCategory363WASC Threat Classification 2.0 - WASC-30 - Mail Command Injection 
WASC Threat Classification 2.0333
HasMemberCategoryCategory364WASC Threat Classification 2.0 - WASC-31 - OS Commanding 
WASC Threat Classification 2.0333
HasMemberCategoryCategory365WASC Threat Classification 2.0 - WASC-32 - Routing Detour 
WASC Threat Classification 2.0333
HasMemberCategoryCategory366WASC Threat Classification 2.0 - WASC-33 - Path Traversal 
WASC Threat Classification 2.0333
HasMemberCategoryCategory367WASC Threat Classification 2.0 - WASC-34 - Predictable Resource Location 
WASC Threat Classification 2.0333
HasMemberCategoryCategory368WASC Threat Classification 2.0 - WASC-35 - SOAP Array Abuse 
WASC Threat Classification 2.0333
HasMemberCategoryCategory369WASC Threat Classification 2.0 - WASC-36 - SSI Injection 
WASC Threat Classification 2.0333
HasMemberCategoryCategory370WASC Threat Classification 2.0 - WASC-37 - Session Fixation 
WASC Threat Classification 2.0333
HasMemberCategoryCategory371WASC Threat Classification 2.0 - WASC-38 - URL Redirector Abuse 
WASC Threat Classification 2.0333
HasMemberCategoryCategory372WASC Threat Classification 2.0 - WASC-39 - XPath Injection 
WASC Threat Classification 2.0333
HasMemberCategoryCategory373WASC Threat Classification 2.0 - WASC-40 - Insufficient Process Validation 
WASC Threat Classification 2.0333
HasMemberCategoryCategory374WASC Threat Classification 2.0 - WASC-41 - XML Attribute Blowup 
WASC Threat Classification 2.0333
HasMemberCategoryCategory375WASC Threat Classification 2.0 - WASC-42 - Abuse of Functionality 
WASC Threat Classification 2.0333
HasMemberCategoryCategory376WASC Threat Classification 2.0 - WASC-43 - XML External Entities 
WASC Threat Classification 2.0333
HasMemberCategoryCategory377WASC Threat Classification 2.0 - WASC-44 - XML Entity Expansion 
WASC Threat Classification 2.0333
HasMemberCategoryCategory378WASC Threat Classification 2.0 - WASC-45 - Fingerprinting 
WASC Threat Classification 2.0333
HasMemberCategoryCategory379WASC Threat Classification 2.0 - WASC-46 - XQuery Injection 
WASC Threat Classification 2.0333
HasMemberCategoryCategory380WASC Threat Classification 2.0 - WASC-47 - Insufficient Session Expiration 
WASC Threat Classification 2.0333
HasMemberCategoryCategory381WASC Threat Classification 2.0 - WASC-48 - Insecure Indexing 
WASC Threat Classification 2.0333
HasMemberCategoryCategory382WASC Threat Classification 2.0 - WASC-49 - Insufficient Password Recovery 
WASC Threat Classification 2.0333
CAPECs in this viewTotal CAPECs
Total84out of384
Views0out of6
Categories55out of67
Attack Patterns36out of311