CAPEC Definitions

    CAPEC Definitions / CAPEC-250

    CAPEC-250: XML Injection

    An attacker utilizes crafted XML user-controllable input to probe, attack, and inject data into the XML database, using techniques similar to SQL injection. The user-controllable input can allow for unauthorized viewing of data, bypassing authentication or the front-end application for direct XML database access, and possibly altering database information.

    Severity:
    Possibility:High

    Extended Description

    No Extended Description.

    Mitigations

    Strong input validation - All user-controllable input must be validated and filtered for illegal characters as well as content that can be interpreted in the context of an XML data or a query.

    Use of custom error pages - Attackers can glean information about the nature of queries from descriptive error messages. Input validation must be coupled with customized error pages that inform about an error without disclosing information about the database or application.

    Relationships with other CAPECs

    CAPEC-248: Command Injection

    Prerequisites

    XML queries used to process user input and retrieve information stored in XML documents

    User-controllable input not properly sanitized

    Related Weaknesses

    CWE-91: XML Injection (aka Blind XPath Injection)

    CWE-74: Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')

    CWE-20: Improper Input Validation

    CWE-707: Improper Neutralization