Incorrect Behavior Order: Authorization Before Parsing and Canonicalization

Properties


name
Incorrect Behavior Order: Authorization Before Parsing and Canonicalization
definition
If a web server does not fully parse requested URLs before it examines them for authorization, it may be possible for an attacker to bypass authorization protection.

Neighbors

CWE-551 has no direct neighbors in this release.

Inferred Relationships

This page is experimental and may change significantly in future releases.

Related Countermeasure Techniques

No related defensive techniques in this release.

Related Weaknesses

Related Offensive Techniques

No related offensive techniques in this release.