Wednesday, May 03, 2006

Common Web application vulnerabilities

SecurityFocus provides an indepth look at some of Five common Web application vulnerabilities.

This article looks at five common Web application attacks, primarily for PHP applications, and then presents a case study of a vulnerable Website that was found through Google and easily exploited. Each of the attacks we'll cover are part of a wide field of study, and readers are advised to follow the references listed in each section for further reading. It is important for Web developers and administrators to have a thorough knowledge of these attacks.

The attacks explained in this article are:
  1. Remote code execution
  2. SQL injection
  3. Format string vulnerabilities
  4. Cross Site Scripting (XSS)
  5. Username enumeration

This article gives a very good idea of some of the vulnerabilities, if you are someone who gets affected by this on a regular basis, take a look.

Five common Web application vulnerabilities


