WebApp Sec mailing list archives

Re: Top Ten Web App Sec Problems


From: zeno <bugtraq () cgisecurity net>
Date: Sat, 30 Nov 2002 12:37:07 -0500 (EST)


One of the things we are going to be doing on the OWASP portal when it

Well here are a few I can say will make the top five.

1. formail
2. phpnuke
3. cart32
4. postnuke




These others come to mind



quickstore shopping cart (cc scans)
dcshop (cc scans)
wwwboard variants (modified variants from matt wrights original  wwwboard)

Hope this helps. 

- zeno () cgisecurity com



 comes online in January is to keep track of vulnerabilities and build a
"top ten in the wild". 

Does anyone know if there have been any good statistical studies on
webappsec vulns (we know about the SANS top 20, but this is webappsec
specific) ?

Does anyone want to share their thoughts and top ten ?


-- 
Mark Curphey <mark () curphey com>




Current thread: