Web Services API Signature Forgery Leveraging Hash Function Extension Weakness
CAPEC-461 · Standard · Draft
An adversary utilizes a hash function extension/padding weakness, to modify the parameters passed to the web service requesting authentication by generating their own call in order to generate a legitimate signature hash (as described in the notes), without knowledge of the secret token sometimes provided by the web service.
severity: High