结构: Simple
Abstraction: Base
状态: Draft
被利用可能性: unkown
The application does not record or display information that would be important for identifying the source or nature of an attack, or determining if an action is safe.
cwe_Nature: ChildOf cwe_CWE_ID: 221 cwe_View_ID: 1000 cwe_Ordinal: Primary
cwe_Nature: ChildOf cwe_CWE_ID: 221 cwe_View_ID: 699 cwe_Ordinal: Primary
Language: {'cwe_Class': 'Language-Independent', 'cwe_Prevalence': 'Undetermined'}
范围 | 影响 | 注释 |
---|---|---|
Non-Repudiation | Hide Activities | The source of an attack will be difficult or impossible to determine. This can allow attacks to the system to continue without notice. |
This code logs suspicious multiple login attempts.
bad PHP
This code only logs failed login attempts when a certain limit is reached. If an attacker knows this limit, they can stop their attack from being discovered by avoiding the limit.
标识 | 说明 | 链接 |
---|---|---|
CVE-1999-1029 | Login attempts not recorded if user disconnects before maximum number of tries. | https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-1999-1029 |
CVE-2002-1839 | Sender's IP address not recorded in outgoing e-mail. | https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2002-1839 |
CVE-2000-0542 | Failed authentication attempt not recorded if later attempt succeeds. | https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2000-0542 |
映射的分类名 | ImNode ID | Fit | Mapped Node Name |
---|---|---|---|
PLOVER | Omission of Security-relevant Information |