CWE Database
/

CWE-344

Back to CWE list

CWE-344

Use of Invariant Value in Dynamically Changing Context

Base
Draft

Description

The product uses a constant value, name, or reference, but this value can (or should) vary across different environments.

Common Consequences

Scope

Other

Impact

Varies by Context

CVE-2002-0980

Component for web browser writes an error message to a known location, which can then be referenced by attackers to process HTML/script in a less restrictive context

Applicable Platforms

Not Language-Specific

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now