What MITRE CAPEC-460: HTTP Parameter Pollution (HPP) (Detailed Attack Pattern - Medium Severity) requires
MITRE CAPEC-460 (HTTP Parameter Pollution (HPP)) is a detailed-level attack pattern in the MITRE Common Attack Pattern Enumeration and Classification. An adversary adds duplicate HTTP GET/POST parameters by injecting query string delimiters. Via HPP it may be possible to override existing hardcoded HTTP parameters, modify the application behaviors, access and, potentially exploit, uncontrollable variables, and bypass input validation checkpoints and WAF rules. Likelihood of attack: Unknown. Typical severity: Medium. Maps to weaknesses CWE-88, CWE-147, CWE-235.
Pillar: Cybersecurity · Authority: MITRE Corporation · Version: 1.0.0 · Last updated:
Primary source: https://capec.mitre.org/data/definitions/460.html
SHA-256 integrity: fd3c4908cb592235b1e5e6d9bf8ba59124bc83280d7135db31115e0dab8fcff8
Primary Citations — 10 traced to source
- MITRE CAPEC-460: HTTP Parameter Pollution (HPP) (https://capec.mitre.org/data/definitions/460.html)
- CWE-88: underlying weakness (http://cwe.mitre.org/data/definitions/88.html)
+ 8 more citations (full bibliography, deterministic workflow, actionable schema and crosswalks) included in the vault unlock — $0.01 via Skyfire / L402 / Direct Base USDC.
Access
⚠ Important: Human Verification Required
Bidda compliance nodes are reference intelligence, not legal advice. Every node must be reviewed by a qualified compliance professional or legal counsel before implementation in any enterprise workflow, regulated system, or compliance programme. See bidda.com/disclaimer for full terms.