Towards an Understanding of Web Application Security Threats and Incidents

Gerhard Steinke, Emanuel Țundrea, Kenmoro Kelly · Journal of Information Privacy and Security · 2011

This paper examines a variety of sources that provide web application security vulnerabilities and incident data. In particular, the research tracks the impact of SQL Injection, Cross-Site Scripting and Cross-Site Request Forgery vulnerabilities. A comparison of vulnerability data versus attacks that have actually resulted in data compromises is studied to determine how the type of vulnerabilities relate to actual methods used to steal data. The paper concludes with recommendations for more secure web applications.

Read the paper · More papers on PaperTik