Manipulating Writeable Configuration Files
CAPEC-75 · Standard · Draft
Generally these are manually edited files that are not in the preview of the system administrators, any ability on the attackers' behalf to modify these files, for example in a CVS repository, gives unauthorized access directly to the application, the same as authorized users.
likelihood: High
severity: Very High