Common Security Problems in the Code of Dynamic Web Applications
Sverre H. Huseby · 2005
The majority of occurring software security holes in web applications may be sorted into just two categories: Failure to deal with metacharacters, and authorization problems due to giving too much trust in input. This article gives several examples from both categories, and then adds some from other categories as well.