Time-of-check Time-of-use (TOCTOU) | |
Missing Release of Resource after Effective Lifetime | |
Loop with Unreachable Exit Condition ('Infinite Loop') | |
Deserialization of Untrusted Data | |
HTTP Request Smuggling | |
Improper Input Validation | |
Insufficiently Protected Credentials | |
Session Fixation | |
Cross-site Scripting (XSS) | |
Open Redirect | |
Loop with Unreachable Exit Condition ('Infinite Loop') | |
Improper Certificate Validation | |
Insecure Default Initialization of Resource | |
CVE-2018-1304 | |
CVE-2018-1305 | |
Unrestricted Upload of File with Dangerous Type | |
Security Features | |
Insufficient Verification of Data Authenticity | |
Improper Access Control | |
Error Handling | |
Information Exposure | |
Access Restriction Bypass | |
Security Features | |
Improper Handling of Exceptional Conditions | |
Information Exposure | |
Exposure of Resource to Wrong Sphere | |
Improper Access Control | |
Access Restriction Bypass | |
Link Following | |
Improper Input Validation | |
Improper Input Validation | |
Improper Access Control | |
Improper Input Validation | |