4.6 SSI Injection
40
4.7 XPath Injection
41
5 Information Disclosure
44
5.1 Directory Indexing
44
5.2 Information Leakage
48
5.3 Path Traversal
51
5.4 Predictable Resource Location
53
6 Logical Attacks
54
6.1 Abuse of Functionality
55
6.2 Denial of Service
58
6.3 Insufficient Anti automation
59
6.4 Insufficient Process Validation
60
CONTACT                                                                                                           62
APPENDIX                                                                                                           63
1.1 HTTP Response Splitting
63
1.2 Web Server/Application Fingerprinting
69
LICENSE                                                                                                             86
3
Copyright 2004, Web Application Security Consortium. All rights reserved.




Unlimited Web Hosting




 
TotalRoute.net Business web hosting division of Vision Web Hosting Inc. All rights reserved.