Prerequisites
The victim must be tricked into navigating to the attackers' decoy site and performing the actions on the decoy page.
The victim's browser must support invisible Flash overlays.
Resources Required
The attacker must be able to force the Flash overlay over the decoy content.
Related Weaknesses
CWE-ID |
Weakness Name |
|
Improper Restriction of Rendered UI Layers or Frames The web application does not restrict or incorrectly restricts frame objects or UI layers that belong to another application or domain, which can lead to user confusion about which interface the user is interacting with. |
Submission
Name |
Organization |
Date |
Date release |
CAPEC Content Team |
The MITRE Corporation |
2014-06-23 +00:00 |
|
Modifications
Name |
Organization |
Date |
Comment |
CAPEC Content Team |
The MITRE Corporation |
2019-04-04 +00:00 |
Updated Related_Weaknesses |
CAPEC Content Team |
The MITRE Corporation |
2019-09-30 +00:00 |
Updated Related_Attack_Patterns |