Resource Exhaustion | |
Deserialization of Untrusted Data | |
HTTP Request Smuggling | |
Improper Input Validation | |
Insufficiently Protected Credentials | |
Session Fixation | |
Cross-site Scripting (XSS) | |
Open Redirect | |
Loop with Unreachable Exit Condition ('Infinite Loop') | |
Improper Certificate Validation | |
Insecure Default Initialization of Resource | |
CVE-2018-1304 | |
CVE-2018-1305 | |
Security Features | |
Insufficient Verification of Data Authenticity | |
Error Handling | |
Improper Access Control | |
Access Restriction Bypass | |
Security Features | |
Information Exposure | |
Improper Handling of Exceptional Conditions | |
Information Exposure | |
Exposure of Resource to Wrong Sphere | |
Improper Access Control | |
Link Following | |
Access Restriction Bypass | |
Improper Input Validation | |
Loop with Unreachable Exit Condition ('Infinite Loop') | |
Improper Input Validation | |
Improper Access Control | |
Improper Input Validation | |
Cross-site Request Forgery (CSRF) | |
Information Exposure | |
CVE-2015-5346 | |
Access Restriction Bypass | |
Directory Traversal | |
Access Restriction Bypass | |
Directory Traversal | |
Improper Access Control | |
Resource Management Errors | |
Improper Data Handling | |
Improper Input Validation | |
Access Restriction Bypass | |
Access Restriction Bypass | |
Numeric Errors | |
Numeric Errors | |
Improper Input Validation | |
Improper Input Validation | |
Information Exposure | |