CAPEC-107: Cross Site Tracing

Cross Site Tracing (XST) enables an adversary to steal the victim's session cookie and possibly other authentication credentials transmitted in the header of the HTTP request when the victim's browser communicates to a destination system's web server.

Severity
Very High
Likelihood
Medium
5
/ 100
low-risk
Active Threat 3/50 · Minimal
Exploit Availability 2/50 · Minimal