Security for Web Languages
Marco Pistoia · 2008
1. Cross-site scripting (XSS) 2. Injection flaws 3. Malicious file executions 4. Insecure direct object reference 5. Cross site request forgery (CSRF) 6. Information leakage and improper error handling 7. Broken authentication and improper session management 8. Unsecure cryptographic storage 9. Unsecure communications 10. Failure to restrict URL accesses . it i ti . j ti l . li i il ti . i t j t . it t . ti l i li . t ti ti i i t . t i t . i ti . il t t i t