4.6 SSI Injection
40
4.7 XPath Injection
41
5 Information Disclosure
44
5.1 Directory Indexing
44
5.2 Information Leakage
48
5.3 Path Traversal
51
5.4 Predictable Resource Location
53
6 Logical Attacks
54
6.1 Abuse of Functionality
55
6.2 Denial of Service
58
6.3 Insufficient Anti automation
59
6.4 Insufficient Process Validation
60
CONTACT 62
APPENDIX 63
1.1 HTTP Response Splitting
63
1.2 Web Server/Application Fingerprinting
69
LICENSE 86
3
Copyright 2004, Web Application Security Consortium. All rights reserved.