Slide 26
Slide 26 text
Summary of Main Vulnerability Types
• Interpreter and page injections
• Operating System, SQL, XML, deserialization, XSS, …
• Lack of validation
• trusting client side restrictions
• allowing session IDs and cookies to be reused
• not escaping and validating input data
• parameter values directly in pages and links
• Missing data protection
• Sensitive data exposure, deserialisation, configuration showing metadata, …
• Complexity
• Misconfiguration, deserialization, XXE, known vulnerabilities