Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Attack Patterns CAPEC-460 — HTTP Parameter Pollution (HPP)
CAPEC-460

HTTP Parameter Pollution (HPP)

TLP:CLEAR

Description

Typical severity: Medium. An adversary adds duplicate HTTP GET/POST parameters by injecting query string delimiters. Via HPP it may be possible to override existing hardcoded HTTP parameters, modify the application behaviors, access and, potentially exploit, uncontrollable variables, and bypass input validation checkpoints and WAF rules.

Mitigation

Configuration: If using a Web Application Firewall (WAF), filters should be carefully configured to detect abnormal HTTP requests | Design: Perform URL encoding | Implementation: Use strict regular expressions in URL rewriting | Implementation: Beware of multiple occurrences of a parameter in a Query String

Details

Platforms
Software
Added
Jul 14, 2026
Leaving Threaticon

This link opens an external site that isn't part of the platform.