| Home > CAPEC List > CAPEC-650: Upload a Web Shell to a Web Server (Version 3.9) |
|
High
| Nature | Type | ID | Name |
|---|---|---|---|
| ChildOf | Standard Attack PatternStandard Attack Pattern - A standard level attack pattern in CAPEC is focused on a specific methodology or technique used in an attack. It is often seen as a singular piece of a fully executed attack. A standard attack pattern is meant to provide sufficient details to understand the specific technique and how it attempts to accomplish a desired goal. A standard level attack pattern is a specific type of a more abstract meta level attack pattern. | 17 | Using Malicious Files |
| View Name | Top Level Categories |
|---|---|
| Domains of Attack | Software |
| Mechanisms of Attack | Subvert Access Control |
| Scope | Impact | Likelihood |
|---|---|---|
Confidentiality | Read Data | |
Confidentiality Access Control Authorization | Gain Privileges | |
Confidentiality Integrity Availability | Execute Unauthorized Commands |
| CWE-ID | Weakness Name |
|---|---|
| 287 | Improper Authentication |
| 553 | Command Shell in Externally Accessible Directory |
| Entry ID | Entry Name |
|---|---|
| 1505.003 | Server Software Component:Web Shell |
| Submissions | ||
|---|---|---|
| Submission Date | Submitter | Organization |
| 2018年05月31日 (Version 2.11) | CAPEC Content Team | The MITRE Corporation |
| Modifications | ||
| Modification Date | Modifier | Organization |
| 2019年04月04日 (Version 3.1) | CAPEC Content Team | The MITRE Corporation |
| Updated Related_Weaknesses | ||
| 2020年07月30日 (Version 3.3) | CAPEC Content Team | The MITRE Corporation |
| Updated Mitigations, Taxonomy_Mappings | ||
| 2020年12月17日 (Version 3.4) | CAPEC Content Team | The MITRE Corporation |
| Updated Mitigations | ||
|
Use of the Common Attack Pattern Enumeration and Classification (CAPEC), and the associated references from this website are subject to the Terms of Use. Copyright © 2007–2025, The MITRE Corporation. CAPEC and the CAPEC logo are trademarks of The MITRE Corporation. |
||