CAPEC-75: Manipulating Writeable Configuration Files

Generally these are manually edited files that are not in the preview of the system administrators, any ability on the attackers' behalf to modify these files, for example in a CVS repository, gives unauthorized access directly to the application, the same as authorized users.

Severity
Very High
Likelihood
High
18
/ 100
low-risk
Active Threat 17/50 · Low
Exploit Availability 1/50 · Minimal