Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Attack Patterns CAPEC-107 — Cross Site Tracing
CAPEC-107

Cross Site Tracing

TLP:CLEAR

Description

Typical severity: Very High. Likelihood of attack: Medium. Cross Site Tracing (XST) enables an adversary to steal the victim's session cookie and possibly other authentication credentials transmitted in the header of the HTTP request when the victim's browser communicates to a destination system's web server.

Mitigation

Administrators should disable support for HTTP TRACE at the destination's web server. Vendors should disable TRACE by default. | Patch web browser against known security origin policy bypass exploits.

Details

Platforms
Software
Added
Jul 14, 2026
Leaving Threaticon

This link opens an external site that isn't part of the platform.