CWE-187: Partial String Comparison
VariantIncomplete
The product performs a comparison that only examines a portion of a factor before determining whether there is a match, such as a substring, leading to resultant weaknesses.
View on MITREBack to CWE Lookup
Extended Description
For example, an attacker might succeed in authentication by providing a small password that matches the associated portion of the larger, correct password.
Technical Details
- Structure
- Simple
Applicable To
Not Language-Specific