Compliance Node Overview
MITRE CAPEC-107 (Cross Site Tracing) is a detailed-level attack pattern in the MITRE Common Attack Pattern Enumeration and Classification. Cross Site Tracing (XST) enables an adversary to steal the victim's session cookie and possibly other authentication credentials transmitted in the header of the HTTP request when the victim's browser communicates to a destination system's web server. Likelihood of attack: Medium. Typical severity: Very High. Maps to weaknesses CWE-693, CWE-648.
Pillar: Cybersecurity · Authority: MITRE Corporation · Version: 1.0.0 · Last updated:
Primary source: https://capec.mitre.org/data/definitions/107.html
SHA-256 integrity: 780194715146800cfd44b9c22459d99412beaa809abdb0e00ad34bb87ebca008
Primary Citations — 9 traced to source
- MITRE CAPEC-107: Cross Site Tracing (https://capec.mitre.org/data/definitions/107.html)
- CWE-693: underlying weakness (http://cwe.mitre.org/data/definitions/693.html)
+ 7 more citations (full bibliography, deterministic workflow, actionable schema and crosswalks) included in the vault unlock — $0.01 via Skyfire / L402 / Direct Base USDC.
Access
⚠ Important: Human Verification Required
Bidda compliance nodes are reference intelligence, not legal advice. Every node must be reviewed by a qualified compliance professional or legal counsel before implementation in any enterprise workflow, regulated system, or compliance programme. See bidda.com/disclaimer for full terms.