Project: WASC Threat Classification

Threat Type: Attack

Reference ID: WASC-42

Abuse of Functionality

Abuse of Functionality is an attack technique that uses a web site’s own features and functionality to attack itself or others. Abuse of Functionality can be described as the abuse of an application’s intended functionality to perform an undesirable outcome. These attacks have varied results such as consuming resources, circumventing access controls, or leaking information. The potential and level of abuse will vary from web site to web site and application to application. Abuse of functionality attacks are often a combination of other attack types and/or utilize other attack vectors.

 

http://projects.webappsec.org/w/page/13246913/Abuse%20of%20Functionality