CAPEC-134: Email Injection

Standard Draft 严重程度: Medium

CAPEC版本: 3.9

更新日期: 2023-01-24

攻击模式描述

An adversary manipulates the headers and content of an email message by injecting data via the use of delimiter characters native to the protocol.

前提条件

  • The target application must allow the user to send email to some recipient, to specify the content at least one header field in the message, and must fail to sanitize against the injection of command separators.
  • The adversary must have the ability to access the target mail application.

所需资源

  • None: No specialized resources are required to execute this type of attack.

分类映射

分类名称 条目ID 条目名称
WASC 30 Mail Command Injection
关键信息

CAPEC ID: CAPEC-134

抽象级别: Standard

状态: Draft

典型严重程度: Medium

相关攻击模式
相关CWE弱点