exploit
software, data or commands that use a bug or vulnerability to compromise a computer system
return-oriented programming
computer security exploit technique that manipulates the call stack to hijack control flow
session hijacking
exploitation of a valid computer session to gain unauthorized access to information or services in a computer system
privilege escalation
process to gain control of computer privileges that are not allowed to a user or application by default
XML external entity attack
type of attack on computer systems
server-side request forgery
type of computer exploit where an attacker abuses the functionality of a server causing it to access or manipulate information in the realm of that server that would otherwise not be directly accessible to the attacker
zero-click attack
computer security exploit that does not require user interaction
killer poke
software means of causing computer hardware damage
credential stuffing
type of cyberattack where stolen account credentials typically consisting of lists of usernames or email addresses and corresponding passwords are used to gain unauthorized access to user accounts through large-scale automated login requests
code injection
class of exploits in which a vulnerable computer program misinterprets data as code
account pre-hijacking
class of security exploit
prompt injection
computer security attack against language-processing systems
cross-site request forgery
type of malicious exploit of a website where unauthorized commands are transmitted from a user trusted by the web app, using image tags, hidden forms, XMLHttpRequest etc.
CRIME
security exploit against secret web cookies
zero-day
cyberattack that utilizes a recently-publicized computer software vulnerability on systems which are yet to be mitigated
video game exploit
use of video game bugs to gain unintended advantage
BREACH
security exploit on HTTPS