Skip to content

Latest commit

 

History

History
47 lines (35 loc) · 1.73 KB

File metadata and controls

47 lines (35 loc) · 1.73 KB

Attack Tree Analysis for nopsolutions/nopcommerce

Objective: [[Gain Unauthorized Administrative Access]]

Attack Tree Visualization

[[Gain Unauthorized Administrative Access]] /
/
[[Exploit Plugin]] [Exploit Core Functionality] [Vulnerabilities]] | | | | | [Exploit Deserialization Vulnerabilities] | | | | [[Known Plugin]] [Unsafe Use of ObjectDataProvider] [[Vulnerability]] | | [[Unpatched Plugin]] [[Vulnerability]] | | / / [Abuse nopCommerce Features] | | [Misconfigured Permissions]

[[Gain Unauthorized Administrative Access]] -> [[Exploit Plugin Vulnerabilities]] -> [[Known Plugin Vulnerability]]

[[Gain Unauthorized Administrative Access]] -> [[Exploit Plugin Vulnerabilities]] -> [[Unpatched Plugin Vulnerability]]

[[Gain Unauthorized Administrative Access]] -> [Exploit Core Functionality] -> [Exploit Deserialization Vulnerabilities] -> [Unsafe Use of ObjectDataProvider]

[[Gain Unauthorized Administrative Access]] -> [Abuse nopCommerce Features] -> [Misconfigured Permissions]