Reliance on Untrusted Inputs in a Security Decision | |
Reliance on Untrusted Inputs in a Security Decision | |
Information Exposure Through Log Files | |
Cross-site Scripting (XSS) | |
Cross-site Scripting (XSS) | |
Cross-site Scripting (XSS) | |
Information Exposure | |
SQL Injection | |
Information Exposure | |
Deserialization of Untrusted Data | |
Cross-site Scripting (XSS) | |
Cross-site Scripting (XSS) | |
XML External Entity (XXE) Injection | |
Information Exposure | |
Use of a Broken or Risky Cryptographic Algorithm | |
Improper Access Control | |
Missing Required Cryptographic Step | |
Missing Required Cryptographic Step | |
Information Exposure | |
Covert Timing Channel | |
Incorrect Calculation | |
Missing Required Cryptographic Step | |
Missing Required Cryptographic Step | |
Missing Required Cryptographic Step | |
Directory Traversal | |
Use of Cryptographically Weak Pseudo-Random Number Generator (PRNG) | |
Improper Certificate Validation | |
CVE-2013-6668 | |
Information Exposure | |
Improper Input Validation | |
Incorrect Permission Assignment for Critical Resource | |
Cleartext Storage of Sensitive Information | |
Improper Authentication | |
Information Exposure | |
Improper Authorization | |
Cleartext Transmission of Sensitive Information | |
Improper Certificate Validation | |
Improper Input Validation | |
Improper Input Validation | |
Cross-site Scripting (XSS) | |
Cross-site Scripting (XSS) | |
Use of Externally-Controlled Input to Select Classes or Code ('Unsafe Reflection') | |
Omission of Security-relevant Information | |
Information Exposure | |
Resource Exhaustion | |
Incomplete Blacklist | |
Directory Traversal | |
Resource Exhaustion | |
HTTP Response Splitting | |
Arbitrary Argument Injection | |
Out-of-Bounds | |
Improper Neutralization of Special Elements | |
Deserialization of Untrusted Data | |
CVE-2016-6346 | |
Improper Neutralization of Special Elements | |
Access Restriction Bypass | |
Improper Data Handling | |
Improper Data Handling | |
Deserialization of Untrusted Data | |
Algorithmic Complexity | |