CAPEC-71: Using Unicode Encoding to Bypass Validation Logic

An attacker may provide a Unicode string to a system component that is not Unicode aware and use that to circumvent the filter or cause the classifying mechanism to fail to properly understanding the request. That may allow the attacker to slip malicious data past the content filter and/or possibly cause the application to route the request incorrectly.

Severity
High
Likelihood
Medium
10
/ 100
low-risk
Active Threat 8/50 · Minimal
Exploit Availability 2/50 · Minimal