|
Articles
|
|
 |
Absolute Path Traversal
Absolute Path Traversal
Description
If a product expects a filename as input it is possible that it can construct an absolute path such as...
|
|
06 May, 2008
Views: 770
|
|
 |
Spyware
Spyware
Description
The spyware is a program that captures statistic information from user´s computer and sends it over internet without...
|
|
06 May, 2008
Views: 328
|
|
 |
Setting Manipulation
Setting Manipulation
Description
This attack aims to modify application settings in order to cause data misleading or advantages on user behalf....
|
|
06 May, 2008
Views: 1257
|
|
 |
Repudiation Attack
Repudiation Attack
Description
Repudiation is the act of refuse authoring of something that happened. A repudiation attack happens when an...
|
|
06 May, 2008
Views: 84803
|
|
 |
Relative Path Traversal
Relative Path Traversal
This attack is a variant of Path Traversal and can be exploited when the application accepts the use of relative traversal...
|
|
06 May, 2008
Views: 1336
|
|
 |
Forced browsing
Forced browsing
Description
Forced browsing is an attack that’s aim to enumerate and access resources that are not referenced by the...
|
|
06 May, 2008
Views: 1813
|
|
 |
Double Encoding
Double Encoding
Description
This attack technique consists of encode user request parameters twice in hexadecimal format in order to bypass...
|
|
06 May, 2008
Views: 459
|
|
 |
Direct Dynamic Code Evaluation ('Eval Injection')
Direct Dynamic Code Evaluation ('Eval Injection')
Description
This attack consists in a script does not properly validate user inputs in the page...
|
|
06 May, 2008
Views: 542
|
|
 |
Custom Special Character Injection
Custom Special Character Injection
Description
The software does not properly filter or quote special characters or reserved words that are used...
|
|
06 May, 2008
Views: 351
|
|
 |
Comment Element
Comment Element
Description
Comments injected into an application through input can be used to compromise a system. as data is parsed, an...
|
|
06 May, 2008
Views: 310
|
|