Connection String Parameter Pollution Attacks

Autor: Alejandro Martín, Manuel Peleteiro Fernández, Antonio Guzmán, Chema Alonso
Rok vydání: 2010
Předmět:
Zdroj: Web Application Security ISBN: 9783642161193
DOI: 10.1007/978-3-642-16120-9_16
Popis: In 2007 the classification of the ten most critical vulnerabilities for the security of a system establishes that code injection attacks are the second type of attack behind XSS attacks. Currently the code injection attacks are placed first in this ranking. In fact Most critical attacks are those that combine XSS techniques to access systems and code injection techniques to access the information. The potential damage associated with this type of threats, the total absence of background and the fact that the solution to mitigate this vulnerability must be implemented by systems administrators and the database vendors justify an in-depth analysis to estimate all the possible ways of implementation of this attack technique.
Databáze: OpenAIRE