Slide 15
Slide 15 text
Classification: Public 17
Typical Requierments ...
... that are often not accounted for:
“If user input is concatenated into data structures
such as SQL, HTML, JavaScript, JSON, XML, CSV,
LDAP filters, SMTP, XPATH, etc., there has to be
context-sensitive output encoding according to the
target format, or the concatenation has to be
avoided altogether.”
SBA Research gGmbH, 2019