Difference between revisions of "Top 10 2013-A1-Injection"

From OWASP
Jump to: navigation, search
Line 23: Line 23:
 
{{Top_10_2010:SummaryTableEndTemplate}}
 
{{Top_10_2010:SummaryTableEndTemplate}}
  
{{Top_10_2010:SubsectionAdvancedTemplate|type={{Top_10_2010:StyleTemplate}}|number=1|risk=2|year=2013}}
+
          <table style="border: none; text-align: left; width: 100%; border-spacing:5px 5px;">
 +
 
 +
<tr>
 +
<td style="vertical-align: top; width: 50%; padding: 5px; border: 3px solid #b3d6ac; background-color: #FFFFFF">
 +
 
 +
<div style="font-style: bold; color: #000000; font-size: 150%;">My Title</div>
 
blank
 
blank
{{Top_10_2010:SubsectionAdvancedTemplate|type={{Top_10_2010:StyleTemplate}}|number=2|risk=2|year=2013}}
+
#blankBullet1
 +
#blankBullet2
 +
 
 +
</td>
 +
<td style="vertical-align: top; width: 50%; padding: 5px; border: 3px solid #b3d6ac; background-color: #FFFFFF">
 +
 
 +
<div style="font-style: bold; color: #000000; font-size: 150%;">My Title</div>
 
blank
 
blank
 
#blankBullet1
 
#blankBullet1
 
#blankBullet2
 
#blankBullet2
{{Top_10_2010:SubsectionAdvancedTemplate|type={{Top_10_2010:StyleTemplate}}|number=3|risk=2|year=2013}}
+
<tr>
 +
<td style="vertical-align: top; width: 50%; padding: 5px; border: 3px solid #b3d6ac; background-color: #FFFFFF">
 +
 
 +
<div style="font-style: bold; color: #000000; font-size: 150%;">My Title</div>
 
blank
 
blank
{{Top_10_2010:ExampleBeginTemplate}}<span style="color:red;">blank code</span>{{Top_10_2010:ExampleEndTemplate}}
+
#blankBullet1
 +
#blankBullet2
 +
 
 +
</td>
 +
<td style="vertical-align: top; width: 50%; padding: 5px; border: 3px solid #b3d6ac; background-color: #FFFFFF">
 +
 
 +
<div style="font-style: bold; color: #000000; font-size: 150%;">My Title</div>
 
blank
 
blank
{{Top_10_2010:ExampleBeginTemplate}}<nowiki>http://example.com/app/accountView?id=</nowiki><span style="color: red;">' or '1'='1</span>{{Top_10_2010:ExampleEndTemplate}}
+
#blankBullet1
blank
+
#blankBullet2
{{Top_10_2010:SubsectionAdvancedTemplate|type={{Top_10_2010:StyleTemplate}}|number=4|risk=2|year=2013}}
+
</td>
{{Top_10_2010:SubSubsectionOWASPReferencesTemplate}}
+
* [[SQL_Injection_Prevention_Cheat_Sheet | OWASP SQL Injection Prevention Cheat Sheet]]
+
* [http://owasp-esapi-java.googlecode.com/svn/trunk_doc/latest/org/owasp/esapi/Encoder.html ESAPI Encoder API]
+
{{Top_10_2010:SubSubsectionExternalReferencesTemplate}}
+
* [http://cwe.mitre.org/data/definitions/77.html CWE Entry 77 on Command Injection]
+
* [http://cwe.mitre.org/data/definitions/89.html CWE Entry 89 on SQL Injection]
+
  
 
{{Top_10_2013:BottomAdvancedTemplate
 
{{Top_10_2013:BottomAdvancedTemplate

Revision as of 16:17, 16 February 2013

[[Top 10 {{{year}}}-Injection|← Injection]]
2013 Table of Contents

2013 Top 10 List

[[Top 10 {{{year}}}-Broken Authentication and Session Management|Broken Authentication and Session Management →]]
Threat Agents Attack Vectors Security Weakness Technical Impacts Business Impacts
Application Specific Exploitability
EASY
Prevalence
COMMON
Detectability
AVERAGE
Impact
SEVERE
Application / Business Specific
blank. blank blank blank blank
</td></table>
My Title

blank

  1. blankBullet1
  2. blankBullet2
My Title

blank

  1. blankBullet1
  2. blankBullet2
My Title

blank

  1. blankBullet1
  2. blankBullet2
My Title

blank

  1. blankBullet1
  2. blankBullet2
[[Top 10 {{{year}}}-Injection|← Injection]]
2013 Table of Contents

2013 Top 10 List

[[Top 10 {{{year}}}-Broken Authentication and Session Management|Broken Authentication and Session Management →]]

© 2002-2013 OWASP Foundation This document is licensed under the Creative Commons Attribution-ShareAlike 3.0 license. Some rights reserved. CC-by-sa-3 0-88x31.png
[[Category:OWASP Top Ten {{{year}}} Project]]
Retrieved from "https://www.owasp.org/index.php?title=Top_10_2013-A1-Injection&oldid=144628"