CWE-187: Partial String Comparison

VariantIncomplete

The product performs a comparison that only examines a portion of a factor before determining whether there is a match, such as a substring, leading to resultant weaknesses.

View on MITRE
Back to CWE Lookup

Extended Description

For example, an attacker might succeed in authentication by providing a small password that matches the associated portion of the larger, correct password.

Technical Details

Structure
Simple

Applicable To

Languages
Not Language-Specific
Platforms

Learn More