The OWASP Top Ten provides a powerful awareness document for web application security. The OWASP Top Ten represents a broad consensus about what the most critical web application security flaws are. Project members include a variety of security experts from around the world who have shared their expertise to produce this list.
OWASP Top Ten for 2013:
OWASP Top Ten for 2013:
- Injection
- Broken Authentication and Session Management CHANGED
- Cross-Site Scripting (XSS) CHANGED
- Insecure Direct Object References
- Security Misconfiguration CHANGED
- Sensitive Data Exposure CHANGED
- Missing Function Level Access Control CHANGED
- Cross-Site Request Forgery (CSRF) CHANGED
- Using Known Vulnerable Components NEW
- Unvalidated Redirects and Forwards
No comments:
Post a Comment