Top 10 list of web application vulnerabilities released

Share this article:

Companies wanting to better secure their web applications and services can start the process by reviewing the newly released Top 10 list of critical web application security problems recently disseminated by the Open Web Application Security Project (OWASP).

The list, now in its second year, is organized into the types of vulnerabilities that frequently occur in web applications and is in line with the current draft web security definitions that will be incorporated into the soon-to-be-released OASIS WAS XML standard. This year's Top 10 also has a new category for web application denial of service vulnerabilities, which have become more prevalent during the last 12 months.

The categories in this year's Top 10 are Unvalidated Input, Broken Access Control, Broken Authentication and Session Management, Cross Site Scripting Flaws, Buffer Overflows, Injection Flaws, Improper Error Handling, Insecure Storage, Denial of Service, and Insecure Configuration Management. 

The complete Top 10 report is available for download at www.owasp.org

Share this article:
You must be a registered member of SC Magazine to post a comment.

Sign up to our newsletters

TOP COMMENTS

More in News

ISSA tackles workforce gap with career lifecycle program

ISSA tackles workforce gap with career lifecycle program ...

On Thursday, the group launched its Cybersecurity Career Lifecycle (CSCL) program.

Amplification DDoS attacks most popular, according to Symantec

Amplification DDoS attacks most popular, according to Symantec

The company noted in a whitepaper released on Tuesday that Domain Name Server amplification attacks have increased 183 percent between January and August.

Court shutters NY co. selling security software with "no value"

A federal court shut down Pairsys at the request of the Federal Trade Commission.