| Double Encoding | 
                        
                            
                                
                            
                            
                                
                                    
                                        
                                            | 
                                                CWE-20
                                             | 
                                            
                                                Improper Input Validation
                                             | 
                                         
                                    
                                        
                                            | 
                                                CWE-74
                                             | 
                                            
                                                Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')
                                             | 
                                         
                                    
                                        
                                            | 
                                                CWE-172
                                             | 
                                            
                                                Encoding Error
                                             | 
                                         
                                    
                                        
                                            | 
                                                CWE-173
                                             | 
                                            
                                                Improper Handling of Alternate Encoding
                                             | 
                                         
                                    
                                        
                                            | 
                                                CWE-177
                                             | 
                                            
                                                Improper Handling of URL Encoding (Hex Encoding)
                                             | 
                                         
                                    
                                        
                                            | 
                                                CWE-181
                                             | 
                                            
                                                Incorrect Behavior Order: Validate Before Filter
                                             | 
                                         
                                    
                                        
                                            | 
                                                CWE-183
                                             | 
                                            
                                                Permissive List of Allowed Inputs
                                             | 
                                         
                                    
                                        
                                            | 
                                                CWE-184
                                             | 
                                            
                                                Incomplete List of Disallowed Inputs
                                             | 
                                         
                                    
                                        
                                            | 
                                                CWE-692
                                             | 
                                            
                                                Incomplete Denylist to Cross-Site Scripting
                                             | 
                                         
                                    
                                        
                                            | 
                                                CWE-697
                                             | 
                                            
                                                Incorrect Comparison
                                             | 
                                         
                                    
                                 
                             
                         | 
                    
                
                    
                        | Generic Cross-Browser Cross-Domain Theft | 
                        
                            
                                
                            
                            
                                
                                    
                                        
                                            | 
                                                CWE-149
                                             | 
                                            
                                                Improper Neutralization of Quoting Syntax
                                             | 
                                         
                                    
                                        
                                            | 
                                                CWE-177
                                             | 
                                            
                                                Improper Handling of URL Encoding (Hex Encoding)
                                             | 
                                         
                                    
                                        
                                            | 
                                                CWE-707
                                             | 
                                            
                                                Improper Neutralization
                                             | 
                                         
                                    
                                        
                                            | 
                                                CWE-838
                                             | 
                                            
                                                Inappropriate Encoding for Output Context
                                             | 
                                         
                                    
                                 
                             
                         | 
                    
                
                    
                        | Using Slashes and URL Encoding Combined to Bypass Validation Logic | 
                        
                            
                                
                            
                            
                                
                                    
                                        
                                            | 
                                                CWE-20
                                             | 
                                            
                                                Improper Input Validation
                                             | 
                                         
                                    
                                        
                                            | 
                                                CWE-22
                                             | 
                                            
                                                Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
                                             | 
                                         
                                    
                                        
                                            | 
                                                CWE-73
                                             | 
                                            
                                                External Control of File Name or Path
                                             | 
                                         
                                    
                                        
                                            | 
                                                CWE-74
                                             | 
                                            
                                                Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')
                                             | 
                                         
                                    
                                        
                                            | 
                                                CWE-172
                                             | 
                                            
                                                Encoding Error
                                             | 
                                         
                                    
                                        
                                            | 
                                                CWE-173
                                             | 
                                            
                                                Improper Handling of Alternate Encoding
                                             | 
                                         
                                    
                                        
                                            | 
                                                CWE-177
                                             | 
                                            
                                                Improper Handling of URL Encoding (Hex Encoding)
                                             | 
                                         
                                    
                                        
                                            | 
                                                CWE-697
                                             | 
                                            
                                                Incorrect Comparison
                                             | 
                                         
                                    
                                        
                                            | 
                                                CWE-707
                                             | 
                                            
                                                Improper Neutralization
                                             | 
                                         
                                    
                                 
                             
                         | 
                    
                
                    
                        | URL Encoding | 
                        
                            
                                
                            
                            
                                
                                    
                                        
                                            | 
                                                CWE-20
                                             | 
                                            
                                                Improper Input Validation
                                             | 
                                         
                                    
                                        
                                            | 
                                                CWE-73
                                             | 
                                            
                                                External Control of File Name or Path
                                             | 
                                         
                                    
                                        
                                            | 
                                                CWE-74
                                             | 
                                            
                                                Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')
                                             | 
                                         
                                    
                                        
                                            | 
                                                CWE-172
                                             | 
                                            
                                                Encoding Error
                                             | 
                                         
                                    
                                        
                                            | 
                                                CWE-173
                                             | 
                                            
                                                Improper Handling of Alternate Encoding
                                             | 
                                         
                                    
                                        
                                            | 
                                                CWE-177
                                             | 
                                            
                                                Improper Handling of URL Encoding (Hex Encoding)
                                             | 
                                         
                                    
                                 
                             
                         |