<?xml version="1.0"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
		<id>https://wiki.owasp.org/api.php?action=feedcontributions&amp;feedformat=atom&amp;user=Benjamin+Watson</id>
		<title>OWASP - User contributions [en]</title>
		<link rel="self" type="application/atom+xml" href="https://wiki.owasp.org/api.php?action=feedcontributions&amp;feedformat=atom&amp;user=Benjamin+Watson"/>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php/Special:Contributions/Benjamin_Watson"/>
		<updated>2026-04-24T00:18:47Z</updated>
		<subtitle>User contributions</subtitle>
		<generator>MediaWiki 1.27.2</generator>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=OWASP_Insecure_Web_Components_Project&amp;diff=182242</id>
		<title>OWASP Insecure Web Components Project</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=OWASP_Insecure_Web_Components_Project&amp;diff=182242"/>
				<updated>2014-09-12T18:00:17Z</updated>
		
		<summary type="html">&lt;p&gt;Benjamin Watson: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;=Main=&lt;br /&gt;
&lt;br /&gt;
&amp;lt;div style=&amp;quot;width:100%;height:160px;border:0,margin:0;overflow: hidden;&amp;quot;&amp;gt;[[File:OWASP_Project_Header.jpg|link=]]&amp;lt;/div&amp;gt;&lt;br /&gt;
&lt;br /&gt;
{| style=&amp;quot;padding: 0;margin:0;margin-top:10px;text-align:left;&amp;quot; |-&lt;br /&gt;
| valign=&amp;quot;top&amp;quot;  style=&amp;quot;border-right: 1px dotted gray;padding-right:25px;&amp;quot; |&lt;br /&gt;
&lt;br /&gt;
==OWASP Insecure Web Components Project==&lt;br /&gt;
&lt;br /&gt;
Helping to build and secure better web applications through the identification of insecure web components.&lt;br /&gt;
&lt;br /&gt;
==Introduction==&lt;br /&gt;
&lt;br /&gt;
The OWASP Insecure Web Components Project is a repository of identified vulnerable components in popular web application frameworks and languages.  The goal is to give developers and security professionals alike a centralized location where they can identify these vulnerable components when building and securing web applications.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
==Description==&lt;br /&gt;
&lt;br /&gt;
The focus of this project are the insecure components that make up popular web applications, and frameworks.  These can be everything from Struts 2 tags, to ASP.NET MVC Models.  We want to build a comprehensive list that can be used to help uncover issues in current implementations of web applications and aid in the secure architecture of them as well.&lt;br /&gt;
&lt;br /&gt;
==Component Categories==&lt;br /&gt;
&lt;br /&gt;
[https://www.owasp.org/index.php/OWASP_Insecure_Web_Components_Project/Struts2 Struts2]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
==Licensing==&lt;br /&gt;
OWASP Insecure Web Components Project is free to use. It is licensed under the http://creativecommons.org/licenses/by-sa/3.0/ Creative Commons Attribution-ShareAlike 3.0 license], so you can copy, distribute and transmit the work, and you can adapt it, and use it commercially, but all provided that you attribute the work and if you alter, transform, or build upon this work, you may distribute the resulting work only under the same or similar license to this one.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
| valign=&amp;quot;top&amp;quot;  style=&amp;quot;padding-left:25px;width:200px;border-right: 1px dotted gray;padding-right:25px;&amp;quot; |&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== Project Leader ==&lt;br /&gt;
&lt;br /&gt;
Benjamin Watson&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
| valign=&amp;quot;top&amp;quot;  style=&amp;quot;padding-left:25px;width:200px;&amp;quot; | &lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== News and Events ==&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
==Classifications==&lt;br /&gt;
&lt;br /&gt;
   {| width=&amp;quot;200&amp;quot; cellpadding=&amp;quot;2&amp;quot;&lt;br /&gt;
   |-&lt;br /&gt;
   | align=&amp;quot;center&amp;quot; valign=&amp;quot;top&amp;quot; width=&amp;quot;50%&amp;quot; rowspan=&amp;quot;2&amp;quot;| [[File:Owasp-incubator-trans-85.png|link=https://www.owasp.org/index.php/OWASP_Project_Stages#tab=Incubator_Projects]]&lt;br /&gt;
   | align=&amp;quot;center&amp;quot; valign=&amp;quot;top&amp;quot; width=&amp;quot;50%&amp;quot;| [[File:Owasp-builders-small.png|link=]]  &lt;br /&gt;
   |-&lt;br /&gt;
   | align=&amp;quot;center&amp;quot; valign=&amp;quot;top&amp;quot; width=&amp;quot;50%&amp;quot;| [[File:Owasp-defenders-small.png|link=]]&lt;br /&gt;
   |-&lt;br /&gt;
   | colspan=&amp;quot;2&amp;quot; align=&amp;quot;center&amp;quot;  | [[File:Cc-button-y-sa-small.png|link=http://creativecommons.org/licenses/by-sa/3.0/]]&lt;br /&gt;
   |-&lt;br /&gt;
   | colspan=&amp;quot;2&amp;quot; align=&amp;quot;center&amp;quot;  | [[File:Project_Type_Files_CODE.jpg|link=]]&lt;br /&gt;
   |}&lt;br /&gt;
&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=FAQs=&lt;br /&gt;
&lt;br /&gt;
; Q1&lt;br /&gt;
: A1&lt;br /&gt;
&lt;br /&gt;
; Q2&lt;br /&gt;
: A2&lt;br /&gt;
&lt;br /&gt;
= Acknowledgements =&lt;br /&gt;
==Volunteers==&lt;br /&gt;
XXX is developed by a worldwide team of volunteers. The primary contributors to date have been:&lt;br /&gt;
&lt;br /&gt;
* xxx&lt;br /&gt;
* xxx&lt;br /&gt;
&lt;br /&gt;
==Others==&lt;br /&gt;
* xxx&lt;br /&gt;
* xxx&lt;br /&gt;
&lt;br /&gt;
= Road Map and Getting Involved =&lt;br /&gt;
&lt;br /&gt;
As of 2014 our current priorities are identifying insecure components in J2EE applications and Java Web Application Frameworks.  This includes Struts, Spring, Wicket, Grails, and so forth.  We are looking at everything from API related components to configuration and environment.&lt;br /&gt;
&lt;br /&gt;
Involvement in the development and promotion of the OWASP Insecure Web Components Project is actively encouraged!&lt;br /&gt;
You do not have to be a security expert in order to contribute.&lt;br /&gt;
Some of the ways you can help:&lt;br /&gt;
&lt;br /&gt;
* Contact Tony UV&lt;br /&gt;
* Contact Benjamin Watson&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
=Project About=&lt;br /&gt;
{{:Projects/OWASP_Insecure_Web_Components_Project}}  &lt;br /&gt;
&lt;br /&gt;
__NOTOC__ &amp;lt;headertabs /&amp;gt; &lt;br /&gt;
&lt;br /&gt;
[[Category:OWASP Project]]  [[Category:OWASP_Builders]] [[Category:OWASP_Defenders]]  [[Category:OWASP_Document]]&lt;/div&gt;</summary>
		<author><name>Benjamin Watson</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=OWASP_Insecure_Web_Components_Project/Struts2&amp;diff=182058</id>
		<title>OWASP Insecure Web Components Project/Struts2</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=OWASP_Insecure_Web_Components_Project/Struts2&amp;diff=182058"/>
				<updated>2014-09-09T19:24:09Z</updated>
		
		<summary type="html">&lt;p&gt;Benjamin Watson: /* CookieInterceptor (S2-022) */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;== CookieInterceptor (S2-022) ==&lt;br /&gt;
&lt;br /&gt;
=== Overview ===&lt;br /&gt;
&lt;br /&gt;
The excluded parameter pattern introduced in version 2.3.16.2 to block access to getClass() did not cover other cases, allowing the state manipulation of session, request, when &amp;quot; * &amp;quot; is used to configure cookiesName param.&lt;br /&gt;
&lt;br /&gt;
The CookieInterceptor is used to set values in the OGNL stack and action based on the cookie name and value.  If an asterisk is present in cookiesName parameter, it will be assumed that all cookie name are to be injected into the OGNL stack and corresponding action.  This applies to 'cookiesValue' as well.&lt;br /&gt;
&lt;br /&gt;
Example: &lt;br /&gt;
&lt;br /&gt;
 &amp;lt;nowiki&amp;gt;&lt;br /&gt;
    &lt;br /&gt;
    &amp;lt;action&amp;gt;   &lt;br /&gt;
         &amp;lt;interceptor-ref name=&amp;quot;cookie&amp;quot;&amp;gt;      &lt;br /&gt;
               &amp;lt;param name=&amp;quot;cookiesName&amp;quot;&amp;gt;cookie1, cookie2&amp;lt;/param&amp;gt;     &lt;br /&gt;
               &amp;lt;param name=&amp;quot;cookiesValue&amp;quot;&amp;gt;*&amp;lt;/param&amp;gt;   &lt;br /&gt;
         &amp;lt;interceptor-ref&amp;gt;&lt;br /&gt;
    &amp;lt;/action&amp;gt;&lt;br /&gt;
 &amp;lt;/nowiki&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Tampering with Struts2 Session Data ===&lt;br /&gt;
&lt;br /&gt;
This was reported here: http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-5057 - and has been fixed since Struts 2.3.4.  Yet conceptually this plays into understanding&lt;br /&gt;
the full issue at hand.&lt;br /&gt;
&lt;br /&gt;
If an action implements the interfaces Action or SessionAware it allows the auto-binding of data to the current session or request using the common implementation: &lt;br /&gt;
&lt;br /&gt;
Based on this post: http://codesecure.blogspot.ca/2011/12/struts-2-session-tampering-via.html - This allows manipulation such as: ?session.key=value.  If an object  has a setValue(String) method and is stored within the session using the key &amp;quot;data&amp;quot;; if one passed the following query string parameter &amp;quot;?session.data.value=authorized&amp;quot;; this would lead to the setting of that value.&lt;br /&gt;
&lt;br /&gt;
=== CVE-2014-0116 ===&lt;br /&gt;
&lt;br /&gt;
What was done to fix CVE-2014-0094 was not fully implemented for values such as session or request.  Please reference: http://securityintelligence.com/struts-vulnerabilities-analysis-parameters-cookie-interceptors-impact-exploitation/ - for the original analysis.&lt;br /&gt;
&lt;br /&gt;
With building an example vulnerable application, it is possible to modify session values in the same way above, i.e. &amp;quot;session.user.role=admin&amp;quot;, which when implementing SessionAware, sets the new value on the OGNL stack, and in the action.&lt;br /&gt;
&lt;br /&gt;
=== Remediation ===&lt;br /&gt;
&lt;br /&gt;
In Struts 2.3.16.3 the same exclude patterns were used in CookieInterceptor which are available in ParametersInterceptor. If you don't use CookieInterceptor you are safe. (S2-022)&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
References: &lt;br /&gt;
&lt;br /&gt;
* http://struts.apache.org/release/2.3.x/docs/s2-022.html&lt;br /&gt;
* http://securityintelligence.com/struts-vulnerabilities-analysis-parameters-cookie-interceptors-impact-exploitation/&lt;br /&gt;
* http://codesecure.blogspot.ca/2011/12/struts-2-session-tampering-via.html&lt;/div&gt;</summary>
		<author><name>Benjamin Watson</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=OWASP_Insecure_Web_Components_Project/Struts2&amp;diff=182057</id>
		<title>OWASP Insecure Web Components Project/Struts2</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=OWASP_Insecure_Web_Components_Project/Struts2&amp;diff=182057"/>
				<updated>2014-09-09T19:22:26Z</updated>
		
		<summary type="html">&lt;p&gt;Benjamin Watson: /* CookieInterceptor (S2-022) */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;== CookieInterceptor (S2-022) ==&lt;br /&gt;
&lt;br /&gt;
=== Overview ===&lt;br /&gt;
&lt;br /&gt;
The excluded parameter pattern introduced in version 2.3.16.2 to block access to getClass() did not cover other cases, allowing the state manipulation of session, request, when &amp;quot; * &amp;quot; is used to configure cookiesName param.&lt;br /&gt;
&lt;br /&gt;
The CookieInterceptor is used to set values in the OGNL stack and action based on the cookie name and value.  If an asterisk is present in cookiesName parameter, it will be assumed that all cookie name are to be injected into the OGNL stack and corresponding action.  This applies to 'cookiesValue' as well.&lt;br /&gt;
&lt;br /&gt;
Example: &lt;br /&gt;
&lt;br /&gt;
 &amp;lt;nowiki&amp;gt;&lt;br /&gt;
    &lt;br /&gt;
    &amp;lt;action&amp;gt;   &lt;br /&gt;
         &amp;lt;interceptor-ref name=&amp;quot;cookie&amp;quot;&amp;gt;      &lt;br /&gt;
               &amp;lt;param name=&amp;quot;cookiesName&amp;quot;&amp;gt;cookie1, cookie2&amp;lt;/param&amp;gt;     &lt;br /&gt;
               &amp;lt;param name=&amp;quot;cookiesValue&amp;quot;&amp;gt;*&amp;lt;/param&amp;gt;   &lt;br /&gt;
         &amp;lt;interceptor-ref&amp;gt;&lt;br /&gt;
    &amp;lt;/action&amp;gt;&lt;br /&gt;
 &amp;lt;/nowiki&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Tampering with Struts2 Session Data ===&lt;br /&gt;
&lt;br /&gt;
This was reported here: http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-5057 - and has been fixed since Struts 2.3.4.  Yet conceptually this plays into understanding&lt;br /&gt;
the full issue at hand.&lt;br /&gt;
&lt;br /&gt;
If an action implements the interfaces Action or SessionAware it allows the auto-binding of data to the current session or request using the common implementation: &lt;br /&gt;
&lt;br /&gt;
Based on this post: http://codesecure.blogspot.ca/2011/12/struts-2-session-tampering-via.html - This allows manipulation such as: ?session.key=value.  If an object  has a setValue(String) method and is stored within the session using the key &amp;quot;data&amp;quot;; if one passed the following query string parameter &amp;quot;?session.data.value=authorized&amp;quot;; this would lead to the setting of that value.&lt;br /&gt;
&lt;br /&gt;
=== CVE-2014-0116 ===&lt;br /&gt;
&lt;br /&gt;
What was done to fix CVE02014-0094 was not fully implemented for values such as session or request.  Please reference: http://securityintelligence.com/struts-vulnerabilities-analysis-parameters-cookie-interceptors-impact-exploitation/ - for the original analysis.&lt;br /&gt;
&lt;br /&gt;
With building an example vulnerable application, it is possible to modify session values in the same way above, i.e. &amp;quot;session.user.role=admin&amp;quot;, which when implementing SessionAware, sets the new value on the OGNL stack, and in the action.&lt;br /&gt;
&lt;br /&gt;
=== Remediation ===&lt;br /&gt;
&lt;br /&gt;
In Struts 2.3.16.3 the same exclude patterns were used in CookieInterceptor which are available in ParametersInterceptor. If you don't use CookieInterceptor you are safe. (S2-022)&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
References: &lt;br /&gt;
&lt;br /&gt;
* http://struts.apache.org/release/2.3.x/docs/s2-022.html&lt;br /&gt;
* http://securityintelligence.com/struts-vulnerabilities-analysis-parameters-cookie-interceptors-impact-exploitation/&lt;br /&gt;
* http://codesecure.blogspot.ca/2011/12/struts-2-session-tampering-via.html&lt;/div&gt;</summary>
		<author><name>Benjamin Watson</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=OWASP_Insecure_Web_Components_Project/Struts2&amp;diff=182056</id>
		<title>OWASP Insecure Web Components Project/Struts2</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=OWASP_Insecure_Web_Components_Project/Struts2&amp;diff=182056"/>
				<updated>2014-09-09T19:06:19Z</updated>
		
		<summary type="html">&lt;p&gt;Benjamin Watson: Created page with &amp;quot;== CookieInterceptor (S2-022) ==  === Overview ===  The excluded parameter pattern introduced in version 2.3.16.2 to block access to getClass() did not cover other cases, allo...&amp;quot;&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;== CookieInterceptor (S2-022) ==&lt;br /&gt;
&lt;br /&gt;
=== Overview ===&lt;br /&gt;
&lt;br /&gt;
The excluded parameter pattern introduced in version 2.3.16.2 to block access to getClass() did not cover other cases, allowing the state manipulation of session, request, when &amp;quot; * &amp;quot; is used to configure cookiesName param.&lt;br /&gt;
&lt;br /&gt;
The CookieInterceptor is used to set values in the OGNL stack and action based on the cookie name and value.  If an asterisk is present in cookiesName parameter, it will be assumed that all cookie name are to be injected into the OGNL stack and corresponding action.  This applies to 'cookiesValue' as well.&lt;br /&gt;
&lt;br /&gt;
Example: &lt;br /&gt;
&lt;br /&gt;
&amp;lt;nowiki&amp;gt;&lt;br /&gt;
&amp;lt;action ... &amp;gt;   &lt;br /&gt;
&amp;lt;interceptor-ref name=&amp;quot;cookie&amp;quot;&amp;gt;      &lt;br /&gt;
      &amp;lt;param name=&amp;quot;cookiesName&amp;quot;&amp;gt;cookie1, cookie2&amp;lt;/param&amp;gt;     &lt;br /&gt;
      &amp;lt;param name=&amp;quot;cookiesValue&amp;quot;&amp;gt;*&amp;lt;/param&amp;gt;   &lt;br /&gt;
&amp;lt;interceptor-ref&amp;gt;   ... &amp;lt;/action&amp;gt;&lt;br /&gt;
&amp;lt;/nowiki&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
References: &lt;br /&gt;
&lt;br /&gt;
http://struts.apache.org/release/2.3.x/docs/s2-022.html&lt;br /&gt;
http://securityintelligence.com/struts-vulnerabilities-analysis-parameters-cookie-interceptors-impact-exploitation/&lt;br /&gt;
http://codesecure.blogspot.ca/2011/12/struts-2-session-tampering-via.html&lt;/div&gt;</summary>
		<author><name>Benjamin Watson</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=OWASP_Insecure_Web_Components_Project&amp;diff=165430</id>
		<title>OWASP Insecure Web Components Project</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=OWASP_Insecure_Web_Components_Project&amp;diff=165430"/>
				<updated>2014-01-06T16:09:48Z</updated>
		
		<summary type="html">&lt;p&gt;Benjamin Watson: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;=Main=&lt;br /&gt;
&lt;br /&gt;
&amp;lt;div style=&amp;quot;width:100%;height:160px;border:0,margin:0;overflow: hidden;&amp;quot;&amp;gt;[[File:OWASP_Project_Header.jpg|link=]]&amp;lt;/div&amp;gt;&lt;br /&gt;
&lt;br /&gt;
{| style=&amp;quot;padding: 0;margin:0;margin-top:10px;text-align:left;&amp;quot; |-&lt;br /&gt;
| valign=&amp;quot;top&amp;quot;  style=&amp;quot;border-right: 1px dotted gray;padding-right:25px;&amp;quot; |&lt;br /&gt;
&lt;br /&gt;
==OWASP Insecure Web Components Project==&lt;br /&gt;
&lt;br /&gt;
Helping to build and secure better web applications through the identification of insecure web components.&lt;br /&gt;
&lt;br /&gt;
==Introduction==&lt;br /&gt;
&lt;br /&gt;
The OWASP Insecure Web Components Project is a repository of identified vulnerable components in popular web application frameworks and languages.  The goal is to give developers and security professionals alike a centralized location where they can identify these vulnerable components when building and securing web applications.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
==Description==&lt;br /&gt;
&lt;br /&gt;
The focus of this project are the insecure components that make up popular web applications, and frameworks.  These can be everything from Struts 2 tags, to ASP.NET MVC Models.  We want to build a comprehensive list that can be used to help uncover issues in current implementations of web applications and aid in the secure architecture of them as well.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
==Licensing==&lt;br /&gt;
OWASP Insecure Web Components Project is free to use. It is licensed under the http://creativecommons.org/licenses/by-sa/3.0/ Creative Commons Attribution-ShareAlike 3.0 license], so you can copy, distribute and transmit the work, and you can adapt it, and use it commercially, but all provided that you attribute the work and if you alter, transform, or build upon this work, you may distribute the resulting work only under the same or similar license to this one.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
| valign=&amp;quot;top&amp;quot;  style=&amp;quot;padding-left:25px;width:200px;border-right: 1px dotted gray;padding-right:25px;&amp;quot; |&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== Project Leader ==&lt;br /&gt;
&lt;br /&gt;
Benjamin Watson&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
| valign=&amp;quot;top&amp;quot;  style=&amp;quot;padding-left:25px;width:200px;&amp;quot; | &lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== News and Events ==&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
==Classifications==&lt;br /&gt;
&lt;br /&gt;
   {| width=&amp;quot;200&amp;quot; cellpadding=&amp;quot;2&amp;quot;&lt;br /&gt;
   |-&lt;br /&gt;
   | align=&amp;quot;center&amp;quot; valign=&amp;quot;top&amp;quot; width=&amp;quot;50%&amp;quot; rowspan=&amp;quot;2&amp;quot;| [[File:Owasp-incubator-trans-85.png|link=https://www.owasp.org/index.php/OWASP_Project_Stages#tab=Incubator_Projects]]&lt;br /&gt;
   | align=&amp;quot;center&amp;quot; valign=&amp;quot;top&amp;quot; width=&amp;quot;50%&amp;quot;| [[File:Owasp-builders-small.png|link=]]  &lt;br /&gt;
   |-&lt;br /&gt;
   | align=&amp;quot;center&amp;quot; valign=&amp;quot;top&amp;quot; width=&amp;quot;50%&amp;quot;| [[File:Owasp-defenders-small.png|link=]]&lt;br /&gt;
   |-&lt;br /&gt;
   | colspan=&amp;quot;2&amp;quot; align=&amp;quot;center&amp;quot;  | [[File:Cc-button-y-sa-small.png|link=http://creativecommons.org/licenses/by-sa/3.0/]]&lt;br /&gt;
   |-&lt;br /&gt;
   | colspan=&amp;quot;2&amp;quot; align=&amp;quot;center&amp;quot;  | [[File:Project_Type_Files_CODE.jpg|link=]]&lt;br /&gt;
   |}&lt;br /&gt;
&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=FAQs=&lt;br /&gt;
&lt;br /&gt;
; Q1&lt;br /&gt;
: A1&lt;br /&gt;
&lt;br /&gt;
; Q2&lt;br /&gt;
: A2&lt;br /&gt;
&lt;br /&gt;
= Acknowledgements =&lt;br /&gt;
==Volunteers==&lt;br /&gt;
XXX is developed by a worldwide team of volunteers. The primary contributors to date have been:&lt;br /&gt;
&lt;br /&gt;
* xxx&lt;br /&gt;
* xxx&lt;br /&gt;
&lt;br /&gt;
==Others==&lt;br /&gt;
* xxx&lt;br /&gt;
* xxx&lt;br /&gt;
&lt;br /&gt;
= Road Map and Getting Involved =&lt;br /&gt;
&lt;br /&gt;
As of 2014 our current priorities are identifying insecure components in J2EE applications and Java Web Application Frameworks.  This includes Struts, Spring, Wicket, Grails, and so forth.  We are looking at everything from API related components to configuration and environment.&lt;br /&gt;
&lt;br /&gt;
Involvement in the development and promotion of the OWASP Insecure Web Components Project is actively encouraged!&lt;br /&gt;
You do not have to be a security expert in order to contribute.&lt;br /&gt;
Some of the ways you can help:&lt;br /&gt;
&lt;br /&gt;
* Contact Tony UV&lt;br /&gt;
* Contact Benjamin Watson&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
=Project About=&lt;br /&gt;
{{:Projects/OWASP_Insecure_Web_Components_Project}}  &lt;br /&gt;
&lt;br /&gt;
__NOTOC__ &amp;lt;headertabs /&amp;gt; &lt;br /&gt;
&lt;br /&gt;
[[Category:OWASP Project]]  [[Category:OWASP_Builders]] [[Category:OWASP_Defenders]]  [[Category:OWASP_Document]]&lt;/div&gt;</summary>
		<author><name>Benjamin Watson</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=OWASP_Insecure_Web_Components_Project&amp;diff=165317</id>
		<title>OWASP Insecure Web Components Project</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=OWASP_Insecure_Web_Components_Project&amp;diff=165317"/>
				<updated>2014-01-03T17:02:55Z</updated>
		
		<summary type="html">&lt;p&gt;Benjamin Watson: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;=Main=&lt;br /&gt;
&lt;br /&gt;
&amp;lt;div style=&amp;quot;width:100%;height:160px;border:0,margin:0;overflow: hidden;&amp;quot;&amp;gt;[[File:OWASP_Project_Header.jpg|link=]]&amp;lt;/div&amp;gt;&lt;br /&gt;
&lt;br /&gt;
{| style=&amp;quot;padding: 0;margin:0;margin-top:10px;text-align:left;&amp;quot; |-&lt;br /&gt;
| valign=&amp;quot;top&amp;quot;  style=&amp;quot;border-right: 1px dotted gray;padding-right:25px;&amp;quot; |&lt;br /&gt;
&lt;br /&gt;
==OWASP Insecure Web Components Project==&lt;br /&gt;
&lt;br /&gt;
Helping to build and secure better web applications through the identification of insecure web components.&lt;br /&gt;
&lt;br /&gt;
==Introduction==&lt;br /&gt;
&lt;br /&gt;
The OWASP Insecure Web Components Project is a repository of identified vulnerable components in popular web application frameworks and languages.  The goal is to give developers and security professionals alike a centralized location where they can identify these vulnerable components when building and securing web applications.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
==Description==&lt;br /&gt;
&lt;br /&gt;
The focus of this project are the insecure components that make up popular web applications, and frameworks.  These can be everything from Struts 2 tags, to ASP.NET MVC Models.  We want to build a comprehensive list that can be used to help uncover issues in current implementations of web applications and aid in the secure architecture of them as well.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
==Licensing==&lt;br /&gt;
OWASP Insecure Web Components Project is free to use. It is licensed under the http://creativecommons.org/licenses/by-sa/3.0/ Creative Commons Attribution-ShareAlike 3.0 license], so you can copy, distribute and transmit the work, and you can adapt it, and use it commercially, but all provided that you attribute the work and if you alter, transform, or build upon this work, you may distribute the resulting work only under the same or similar license to this one.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
| valign=&amp;quot;top&amp;quot;  style=&amp;quot;padding-left:25px;width:200px;border-right: 1px dotted gray;padding-right:25px;&amp;quot; |&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== Project Leader ==&lt;br /&gt;
&lt;br /&gt;
Tony UV&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
| valign=&amp;quot;top&amp;quot;  style=&amp;quot;padding-left:25px;width:200px;&amp;quot; | &lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== News and Events ==&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
==Classifications==&lt;br /&gt;
&lt;br /&gt;
   {| width=&amp;quot;200&amp;quot; cellpadding=&amp;quot;2&amp;quot;&lt;br /&gt;
   |-&lt;br /&gt;
   | align=&amp;quot;center&amp;quot; valign=&amp;quot;top&amp;quot; width=&amp;quot;50%&amp;quot; rowspan=&amp;quot;2&amp;quot;| [[File:Owasp-incubator-trans-85.png|link=https://www.owasp.org/index.php/OWASP_Project_Stages#tab=Incubator_Projects]]&lt;br /&gt;
   | align=&amp;quot;center&amp;quot; valign=&amp;quot;top&amp;quot; width=&amp;quot;50%&amp;quot;| [[File:Owasp-builders-small.png|link=]]  &lt;br /&gt;
   |-&lt;br /&gt;
   | align=&amp;quot;center&amp;quot; valign=&amp;quot;top&amp;quot; width=&amp;quot;50%&amp;quot;| [[File:Owasp-defenders-small.png|link=]]&lt;br /&gt;
   |-&lt;br /&gt;
   | colspan=&amp;quot;2&amp;quot; align=&amp;quot;center&amp;quot;  | [[File:Cc-button-y-sa-small.png|link=http://creativecommons.org/licenses/by-sa/3.0/]]&lt;br /&gt;
   |-&lt;br /&gt;
   | colspan=&amp;quot;2&amp;quot; align=&amp;quot;center&amp;quot;  | [[File:Project_Type_Files_CODE.jpg|link=]]&lt;br /&gt;
   |}&lt;br /&gt;
&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=FAQs=&lt;br /&gt;
&lt;br /&gt;
; Q1&lt;br /&gt;
: A1&lt;br /&gt;
&lt;br /&gt;
; Q2&lt;br /&gt;
: A2&lt;br /&gt;
&lt;br /&gt;
= Acknowledgements =&lt;br /&gt;
==Volunteers==&lt;br /&gt;
XXX is developed by a worldwide team of volunteers. The primary contributors to date have been:&lt;br /&gt;
&lt;br /&gt;
* xxx&lt;br /&gt;
* xxx&lt;br /&gt;
&lt;br /&gt;
==Others==&lt;br /&gt;
* xxx&lt;br /&gt;
* xxx&lt;br /&gt;
&lt;br /&gt;
= Road Map and Getting Involved =&lt;br /&gt;
&lt;br /&gt;
As of 2014 our current priorities are identifying insecure components in J2EE applications and Java Web Application Frameworks.  This includes Struts, Spring, Wicket, Grails, and so forth.  We are looking at everything from API related components to configuration and environment.&lt;br /&gt;
&lt;br /&gt;
Involvement in the development and promotion of the OWASP Insecure Web Components Project is actively encouraged!&lt;br /&gt;
You do not have to be a security expert in order to contribute.&lt;br /&gt;
Some of the ways you can help:&lt;br /&gt;
&lt;br /&gt;
* Contact Tony UV&lt;br /&gt;
* Contact Benjamin Watson&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
=Project About=&lt;br /&gt;
{{:Projects/OWASP_Insecure_Web_Components_Project}}  &lt;br /&gt;
&lt;br /&gt;
__NOTOC__ &amp;lt;headertabs /&amp;gt; &lt;br /&gt;
&lt;br /&gt;
[[Category:OWASP Project]]  [[Category:OWASP_Builders]] [[Category:OWASP_Defenders]]  [[Category:OWASP_Document]]&lt;/div&gt;</summary>
		<author><name>Benjamin Watson</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=OWASP_Insecure_Web_Components_Project&amp;diff=165316</id>
		<title>OWASP Insecure Web Components Project</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=OWASP_Insecure_Web_Components_Project&amp;diff=165316"/>
				<updated>2014-01-03T17:02:04Z</updated>
		
		<summary type="html">&lt;p&gt;Benjamin Watson: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;=Main=&lt;br /&gt;
&lt;br /&gt;
&amp;lt;div style=&amp;quot;width:100%;height:160px;border:0,margin:0;overflow: hidden;&amp;quot;&amp;gt;[[File:OWASP_Project_Header.jpg|link=]]&amp;lt;/div&amp;gt;&lt;br /&gt;
&lt;br /&gt;
{| style=&amp;quot;padding: 0;margin:0;margin-top:10px;text-align:left;&amp;quot; |-&lt;br /&gt;
| valign=&amp;quot;top&amp;quot;  style=&amp;quot;border-right: 1px dotted gray;padding-right:25px;&amp;quot; |&lt;br /&gt;
&lt;br /&gt;
==OWASP Insecure Web Components Project==&lt;br /&gt;
&lt;br /&gt;
Helping to build and secure better web applications through the identification of insecure web components.&lt;br /&gt;
&lt;br /&gt;
==Introduction==&lt;br /&gt;
&lt;br /&gt;
The OWASP Insecure Web Components Project is a repository of identified vulnerable components in popular web application frameworks and languages.  The goal is to give developers and security professionals alike a centralized location where they can identify these vulnerable components when building and securing web applications.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
==Description==&lt;br /&gt;
&lt;br /&gt;
The focus of this project are the insecure components that make up popular web applications, and frameworks.  These can be everything from Struts 2 tags, to ASP.NET MVC Models.  We want to build a comprehensive list that can be used to help uncover issues in current implementations of web applications and aid in the secure architecture of them as well.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
==Licensing==&lt;br /&gt;
OWASP Insecure Web Components Project is free to use. It is licensed under the http://creativecommons.org/licenses/by-sa/3.0/ Creative Commons Attribution-ShareAlike 3.0 license], so you can copy, distribute and transmit the work, and you can adapt it, and use it commercially, but all provided that you attribute the work and if you alter, transform, or build upon this work, you may distribute the resulting work only under the same or similar license to this one.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
| valign=&amp;quot;top&amp;quot;  style=&amp;quot;padding-left:25px;width:200px;border-right: 1px dotted gray;padding-right:25px;&amp;quot; |&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== Project Leader ==&lt;br /&gt;
&lt;br /&gt;
Tony UV&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
| valign=&amp;quot;top&amp;quot;  style=&amp;quot;padding-left:25px;width:200px;&amp;quot; | &lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== News and Events ==&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
==Classifications==&lt;br /&gt;
&lt;br /&gt;
   {| width=&amp;quot;200&amp;quot; cellpadding=&amp;quot;2&amp;quot;&lt;br /&gt;
   |-&lt;br /&gt;
   | align=&amp;quot;center&amp;quot; valign=&amp;quot;top&amp;quot; width=&amp;quot;50%&amp;quot; rowspan=&amp;quot;2&amp;quot;| [[File:Owasp-incubator-trans-85.png|link=https://www.owasp.org/index.php/OWASP_Project_Stages#tab=Incubator_Projects]]&lt;br /&gt;
   | align=&amp;quot;center&amp;quot; valign=&amp;quot;top&amp;quot; width=&amp;quot;50%&amp;quot;| [[File:Owasp-builders-small.png|link=]]  &lt;br /&gt;
   |-&lt;br /&gt;
   | align=&amp;quot;center&amp;quot; valign=&amp;quot;top&amp;quot; width=&amp;quot;50%&amp;quot;| [[File:Owasp-defenders-small.png|link=]]&lt;br /&gt;
   |-&lt;br /&gt;
   | colspan=&amp;quot;2&amp;quot; align=&amp;quot;center&amp;quot;  | [[File:Cc-button-y-sa-small.png|link=http://creativecommons.org/licenses/by-sa/3.0/]]&lt;br /&gt;
   |-&lt;br /&gt;
   | colspan=&amp;quot;2&amp;quot; align=&amp;quot;center&amp;quot;  | [[File:Project_Type_Files_CODE.jpg|link=]]&lt;br /&gt;
   |}&lt;br /&gt;
&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=FAQs=&lt;br /&gt;
&lt;br /&gt;
; Q1&lt;br /&gt;
: A1&lt;br /&gt;
&lt;br /&gt;
; Q2&lt;br /&gt;
: A2&lt;br /&gt;
&lt;br /&gt;
= Acknowledgements =&lt;br /&gt;
==Volunteers==&lt;br /&gt;
XXX is developed by a worldwide team of volunteers. The primary contributors to date have been:&lt;br /&gt;
&lt;br /&gt;
* xxx&lt;br /&gt;
* xxx&lt;br /&gt;
&lt;br /&gt;
==Others==&lt;br /&gt;
* xxx&lt;br /&gt;
* xxx&lt;br /&gt;
&lt;br /&gt;
= Road Map and Getting Involved =&lt;br /&gt;
&lt;br /&gt;
As of 2014 our current priorities are identifying insecure components in J2EE applications and Java Web Application Frameworks.  This includes Struts, Spring, Wicket, Grails, and so forth.  We are looking at everything from API related components to configuration and environment.&lt;br /&gt;
&lt;br /&gt;
Involvement in the development and promotion of the OWASP Insecure Web Components Project is actively encouraged!&lt;br /&gt;
You do not have to be a security expert in order to contribute.&lt;br /&gt;
Some of the ways you can help:&lt;br /&gt;
Contact Tony UV&lt;br /&gt;
Contact Benjamin Watson&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
=Project About=&lt;br /&gt;
{{:Projects/OWASP_Insecure_Web_Components_Project}}  &lt;br /&gt;
&lt;br /&gt;
__NOTOC__ &amp;lt;headertabs /&amp;gt; &lt;br /&gt;
&lt;br /&gt;
[[Category:OWASP Project]]  [[Category:OWASP_Builders]] [[Category:OWASP_Defenders]]  [[Category:OWASP_Document]]&lt;/div&gt;</summary>
		<author><name>Benjamin Watson</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=OWASP_Insecure_Web_Components_Project&amp;diff=165315</id>
		<title>OWASP Insecure Web Components Project</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=OWASP_Insecure_Web_Components_Project&amp;diff=165315"/>
				<updated>2014-01-03T17:00:45Z</updated>
		
		<summary type="html">&lt;p&gt;Benjamin Watson: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;=Main=&lt;br /&gt;
&lt;br /&gt;
&amp;lt;div style=&amp;quot;width:100%;height:160px;border:0,margin:0;overflow: hidden;&amp;quot;&amp;gt;[[File:OWASP_Project_Header.jpg|link=]]&amp;lt;/div&amp;gt;&lt;br /&gt;
&lt;br /&gt;
{| style=&amp;quot;padding: 0;margin:0;margin-top:10px;text-align:left;&amp;quot; |-&lt;br /&gt;
| valign=&amp;quot;top&amp;quot;  style=&amp;quot;border-right: 1px dotted gray;padding-right:25px;&amp;quot; |&lt;br /&gt;
&lt;br /&gt;
==OWASP Insecure Web Components Project==&lt;br /&gt;
&lt;br /&gt;
Helping to build and secure better web applications through the identification of insecure web components.&lt;br /&gt;
&lt;br /&gt;
==Introduction==&lt;br /&gt;
&lt;br /&gt;
The OWASP Insecure Web Components Project is a repository of identified vulnerable components in popular web application frameworks and languages.  The goal is to give developers and security professionals alike a centralized location where they can identify these vulnerable components when building and securing web applications.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
==Description==&lt;br /&gt;
&lt;br /&gt;
The focus of this project are the insecure components that make up popular web applications, and frameworks.  These can be everything from Struts 2 tags, to ASP.NET MVC Models.  We want to build a comprehensive list that can be used to help uncover issues in current implementations of web applications and aid in the secure architecture of them as well.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
==Licensing==&lt;br /&gt;
OWASP Insecure Web Components Project is free to use. It is licensed under the http://creativecommons.org/licenses/by-sa/3.0/ Creative Commons Attribution-ShareAlike 3.0 license], so you can copy, distribute and transmit the work, and you can adapt it, and use it commercially, but all provided that you attribute the work and if you alter, transform, or build upon this work, you may distribute the resulting work only under the same or similar license to this one.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
| valign=&amp;quot;top&amp;quot;  style=&amp;quot;padding-left:25px;width:200px;border-right: 1px dotted gray;padding-right:25px;&amp;quot; |&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== Project Leader ==&lt;br /&gt;
&lt;br /&gt;
Tony UV&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
| valign=&amp;quot;top&amp;quot;  style=&amp;quot;padding-left:25px;width:200px;&amp;quot; | &lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== News and Events ==&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
==Classifications==&lt;br /&gt;
&lt;br /&gt;
   {| width=&amp;quot;200&amp;quot; cellpadding=&amp;quot;2&amp;quot;&lt;br /&gt;
   |-&lt;br /&gt;
   | align=&amp;quot;center&amp;quot; valign=&amp;quot;top&amp;quot; width=&amp;quot;50%&amp;quot; rowspan=&amp;quot;2&amp;quot;| [[File:Owasp-incubator-trans-85.png|link=https://www.owasp.org/index.php/OWASP_Project_Stages#tab=Incubator_Projects]]&lt;br /&gt;
   | align=&amp;quot;center&amp;quot; valign=&amp;quot;top&amp;quot; width=&amp;quot;50%&amp;quot;| [[File:Owasp-builders-small.png|link=]]  &lt;br /&gt;
   |-&lt;br /&gt;
   | align=&amp;quot;center&amp;quot; valign=&amp;quot;top&amp;quot; width=&amp;quot;50%&amp;quot;| [[File:Owasp-defenders-small.png|link=]]&lt;br /&gt;
   |-&lt;br /&gt;
   | colspan=&amp;quot;2&amp;quot; align=&amp;quot;center&amp;quot;  | [[File:Cc-button-y-sa-small.png|link=http://creativecommons.org/licenses/by-sa/3.0/]]&lt;br /&gt;
   |-&lt;br /&gt;
   | colspan=&amp;quot;2&amp;quot; align=&amp;quot;center&amp;quot;  | [[File:Project_Type_Files_CODE.jpg|link=]]&lt;br /&gt;
   |}&lt;br /&gt;
&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=FAQs=&lt;br /&gt;
&lt;br /&gt;
; Q1&lt;br /&gt;
: A1&lt;br /&gt;
&lt;br /&gt;
; Q2&lt;br /&gt;
: A2&lt;br /&gt;
&lt;br /&gt;
= Acknowledgements =&lt;br /&gt;
==Volunteers==&lt;br /&gt;
XXX is developed by a worldwide team of volunteers. The primary contributors to date have been:&lt;br /&gt;
&lt;br /&gt;
* xxx&lt;br /&gt;
* xxx&lt;br /&gt;
&lt;br /&gt;
==Others==&lt;br /&gt;
* xxx&lt;br /&gt;
* xxx&lt;br /&gt;
&lt;br /&gt;
= Road Map and Getting Involved =&lt;br /&gt;
&lt;br /&gt;
As of 2014 our current priorities are identifying insecure components in J2EE applications and Java Web Application Frameworks.  This includes Struts, Spring, Wicket, Grails, and so forth.  We are looking at everything from API related components to configuration and environment.&lt;br /&gt;
&lt;br /&gt;
Involvement in the development and promotion of XXX is actively encouraged!&lt;br /&gt;
You do not have to be a security expert in order to contribute.&lt;br /&gt;
Some of the ways you can help:&lt;br /&gt;
* xxx&lt;br /&gt;
* xxx&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
=Project About=&lt;br /&gt;
{{:Projects/OWASP_Insecure_Web_Components_Project}}  &lt;br /&gt;
&lt;br /&gt;
__NOTOC__ &amp;lt;headertabs /&amp;gt; &lt;br /&gt;
&lt;br /&gt;
[[Category:OWASP Project]]  [[Category:OWASP_Builders]] [[Category:OWASP_Defenders]]  [[Category:OWASP_Document]]&lt;/div&gt;</summary>
		<author><name>Benjamin Watson</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=OWASP_Insecure_Web_Components_Project&amp;diff=165314</id>
		<title>OWASP Insecure Web Components Project</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=OWASP_Insecure_Web_Components_Project&amp;diff=165314"/>
				<updated>2014-01-03T16:56:31Z</updated>
		
		<summary type="html">&lt;p&gt;Benjamin Watson: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;=Main=&lt;br /&gt;
&lt;br /&gt;
&amp;lt;div style=&amp;quot;width:100%;height:160px;border:0,margin:0;overflow: hidden;&amp;quot;&amp;gt;[[File:OWASP_Project_Header.jpg|link=]]&amp;lt;/div&amp;gt;&lt;br /&gt;
&lt;br /&gt;
{| style=&amp;quot;padding: 0;margin:0;margin-top:10px;text-align:left;&amp;quot; |-&lt;br /&gt;
| valign=&amp;quot;top&amp;quot;  style=&amp;quot;border-right: 1px dotted gray;padding-right:25px;&amp;quot; |&lt;br /&gt;
&lt;br /&gt;
==OWASP Insecure Web Components Project==&lt;br /&gt;
&lt;br /&gt;
The OWASP Insecure Web Components Project&lt;br /&gt;
&lt;br /&gt;
==Introduction==&lt;br /&gt;
&lt;br /&gt;
The OWASP Insecure Web Components Project is a repository of identified vulnerable components in popular web application frameworks and languages.  The goal is to give developers and security professionals alike a centralized location where they can identify these vulnerable components when building and securing web applications.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
==Description==&lt;br /&gt;
&lt;br /&gt;
The focus of this project are the insecure components that make up popular web applications, and frameworks.  These can be everything from Struts 2 tags, to ASP.NET MVC Models.  We want to build a comprehensive list that can be used to help uncover issues in current implementations of web applications and aid in the secure architecture of them as well.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
==Licensing==&lt;br /&gt;
OWASP Insecure Web Components Project is free to use. It is licensed under the http://creativecommons.org/licenses/by-sa/3.0/ Creative Commons Attribution-ShareAlike 3.0 license], so you can copy, distribute and transmit the work, and you can adapt it, and use it commercially, but all provided that you attribute the work and if you alter, transform, or build upon this work, you may distribute the resulting work only under the same or similar license to this one.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
| valign=&amp;quot;top&amp;quot;  style=&amp;quot;padding-left:25px;width:200px;border-right: 1px dotted gray;padding-right:25px;&amp;quot; |&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== Project Leader ==&lt;br /&gt;
&lt;br /&gt;
Project leader's name&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== Related Projects ==&lt;br /&gt;
&lt;br /&gt;
* [[OWASP_CISO_Survey]]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
| valign=&amp;quot;top&amp;quot;  style=&amp;quot;padding-left:25px;width:200px;&amp;quot; | &lt;br /&gt;
&lt;br /&gt;
== Quick Download ==&lt;br /&gt;
&lt;br /&gt;
* Link to page/download&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== News and Events ==&lt;br /&gt;
* [20 Nov 2013] News 2&lt;br /&gt;
* [30 Sep 2013] News 1&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== In Print ==&lt;br /&gt;
This project can be purchased as a print on demand book from Lulu.com&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
==Classifications==&lt;br /&gt;
&lt;br /&gt;
   {| width=&amp;quot;200&amp;quot; cellpadding=&amp;quot;2&amp;quot;&lt;br /&gt;
   |-&lt;br /&gt;
   | align=&amp;quot;center&amp;quot; valign=&amp;quot;top&amp;quot; width=&amp;quot;50%&amp;quot; rowspan=&amp;quot;2&amp;quot;| [[File:Owasp-incubator-trans-85.png|link=https://www.owasp.org/index.php/OWASP_Project_Stages#tab=Incubator_Projects]]&lt;br /&gt;
   | align=&amp;quot;center&amp;quot; valign=&amp;quot;top&amp;quot; width=&amp;quot;50%&amp;quot;| [[File:Owasp-builders-small.png|link=]]  &lt;br /&gt;
   |-&lt;br /&gt;
   | align=&amp;quot;center&amp;quot; valign=&amp;quot;top&amp;quot; width=&amp;quot;50%&amp;quot;| [[File:Owasp-defenders-small.png|link=]]&lt;br /&gt;
   |-&lt;br /&gt;
   | colspan=&amp;quot;2&amp;quot; align=&amp;quot;center&amp;quot;  | [[File:Cc-button-y-sa-small.png|link=http://creativecommons.org/licenses/by-sa/3.0/]]&lt;br /&gt;
   |-&lt;br /&gt;
   | colspan=&amp;quot;2&amp;quot; align=&amp;quot;center&amp;quot;  | [[File:Project_Type_Files_CODE.jpg|link=]]&lt;br /&gt;
   |}&lt;br /&gt;
&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=FAQs=&lt;br /&gt;
&lt;br /&gt;
; Q1&lt;br /&gt;
: A1&lt;br /&gt;
&lt;br /&gt;
; Q2&lt;br /&gt;
: A2&lt;br /&gt;
&lt;br /&gt;
= Acknowledgements =&lt;br /&gt;
==Volunteers==&lt;br /&gt;
XXX is developed by a worldwide team of volunteers. The primary contributors to date have been:&lt;br /&gt;
&lt;br /&gt;
* xxx&lt;br /&gt;
* xxx&lt;br /&gt;
&lt;br /&gt;
==Others==&lt;br /&gt;
* xxx&lt;br /&gt;
* xxx&lt;br /&gt;
&lt;br /&gt;
= Road Map and Getting Involved =&lt;br /&gt;
&lt;br /&gt;
As of 2014 our current priorities are identifying insecure components in J2EE applications and Java Web Application Frameworks.  This includes Struts, Spring, Wicket, Grails, and so forth.  We are looking at everything from API related components to configuration and environment.&lt;br /&gt;
&lt;br /&gt;
Involvement in the development and promotion of XXX is actively encouraged!&lt;br /&gt;
You do not have to be a security expert in order to contribute.&lt;br /&gt;
Some of the ways you can help:&lt;br /&gt;
* xxx&lt;br /&gt;
* xxx&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
=Project About=&lt;br /&gt;
{{:Projects/OWASP_Insecure_Web_Components_Project}}  &lt;br /&gt;
&lt;br /&gt;
__NOTOC__ &amp;lt;headertabs /&amp;gt; &lt;br /&gt;
&lt;br /&gt;
[[Category:OWASP Project]]  [[Category:OWASP_Builders]] [[Category:OWASP_Defenders]]  [[Category:OWASP_Document]]&lt;/div&gt;</summary>
		<author><name>Benjamin Watson</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=OWASP_Insecure_Web_Components_Project&amp;diff=165313</id>
		<title>OWASP Insecure Web Components Project</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=OWASP_Insecure_Web_Components_Project&amp;diff=165313"/>
				<updated>2014-01-03T16:55:27Z</updated>
		
		<summary type="html">&lt;p&gt;Benjamin Watson: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;=Main=&lt;br /&gt;
&lt;br /&gt;
&amp;lt;div style=&amp;quot;width:100%;height:160px;border:0,margin:0;overflow: hidden;&amp;quot;&amp;gt;[[File:OWASP_Project_Header.jpg|link=]]&amp;lt;/div&amp;gt;&lt;br /&gt;
&lt;br /&gt;
{| style=&amp;quot;padding: 0;margin:0;margin-top:10px;text-align:left;&amp;quot; |-&lt;br /&gt;
| valign=&amp;quot;top&amp;quot;  style=&amp;quot;border-right: 1px dotted gray;padding-right:25px;&amp;quot; |&lt;br /&gt;
&lt;br /&gt;
==OWASP Insecure Web Components Project==&lt;br /&gt;
&lt;br /&gt;
The OWASP Insecure Web Components Project&lt;br /&gt;
&lt;br /&gt;
==Introduction==&lt;br /&gt;
&lt;br /&gt;
The OWASP Insecure Web Components Project is a repository of identified vulnerable components in popular web application frameworks and languages.  The goal is to give developers and security professionals alike a centralized location where they can identify these vulnerable components when building and securing web applications.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
==Description==&lt;br /&gt;
&lt;br /&gt;
The focus of this project are the insecure components that make up popular web applications, and frameworks.  These can be everything from Struts 2 tags, to ASP.NET MVC Models.  We want to build a comprehensive list that can be used to help uncover issues in current implementations of web applications and aid in the secure architecture of them as well.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
==Licensing==&lt;br /&gt;
OWASP XXX is free to use. It is licensed under the http://creativecommons.org/licenses/by-sa/3.0/ Creative Commons Attribution-ShareAlike 3.0 license], so you can copy, distribute and transmit the work, and you can adapt it, and use it commercially, but all provided that you attribute the work and if you alter, transform, or build upon this work, you may distribute the resulting work only under the same or similar license to this one.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
| valign=&amp;quot;top&amp;quot;  style=&amp;quot;padding-left:25px;width:200px;border-right: 1px dotted gray;padding-right:25px;&amp;quot; |&lt;br /&gt;
&lt;br /&gt;
== What is XXX? ==&lt;br /&gt;
&lt;br /&gt;
OWASP XXX  provides:&lt;br /&gt;
&lt;br /&gt;
* xxx&lt;br /&gt;
* xxx&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== Presentation ==&lt;br /&gt;
&lt;br /&gt;
Link to presentation&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== Project Leader ==&lt;br /&gt;
&lt;br /&gt;
Project leader's name&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== Related Projects ==&lt;br /&gt;
&lt;br /&gt;
* [[OWASP_CISO_Survey]]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
| valign=&amp;quot;top&amp;quot;  style=&amp;quot;padding-left:25px;width:200px;&amp;quot; | &lt;br /&gt;
&lt;br /&gt;
== Quick Download ==&lt;br /&gt;
&lt;br /&gt;
* Link to page/download&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== News and Events ==&lt;br /&gt;
* [20 Nov 2013] News 2&lt;br /&gt;
* [30 Sep 2013] News 1&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== In Print ==&lt;br /&gt;
This project can be purchased as a print on demand book from Lulu.com&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
==Classifications==&lt;br /&gt;
&lt;br /&gt;
   {| width=&amp;quot;200&amp;quot; cellpadding=&amp;quot;2&amp;quot;&lt;br /&gt;
   |-&lt;br /&gt;
   | align=&amp;quot;center&amp;quot; valign=&amp;quot;top&amp;quot; width=&amp;quot;50%&amp;quot; rowspan=&amp;quot;2&amp;quot;| [[File:Owasp-incubator-trans-85.png|link=https://www.owasp.org/index.php/OWASP_Project_Stages#tab=Incubator_Projects]]&lt;br /&gt;
   | align=&amp;quot;center&amp;quot; valign=&amp;quot;top&amp;quot; width=&amp;quot;50%&amp;quot;| [[File:Owasp-builders-small.png|link=]]  &lt;br /&gt;
   |-&lt;br /&gt;
   | align=&amp;quot;center&amp;quot; valign=&amp;quot;top&amp;quot; width=&amp;quot;50%&amp;quot;| [[File:Owasp-defenders-small.png|link=]]&lt;br /&gt;
   |-&lt;br /&gt;
   | colspan=&amp;quot;2&amp;quot; align=&amp;quot;center&amp;quot;  | [[File:Cc-button-y-sa-small.png|link=http://creativecommons.org/licenses/by-sa/3.0/]]&lt;br /&gt;
   |-&lt;br /&gt;
   | colspan=&amp;quot;2&amp;quot; align=&amp;quot;center&amp;quot;  | [[File:Project_Type_Files_CODE.jpg|link=]]&lt;br /&gt;
   |}&lt;br /&gt;
&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=FAQs=&lt;br /&gt;
&lt;br /&gt;
; Q1&lt;br /&gt;
: A1&lt;br /&gt;
&lt;br /&gt;
; Q2&lt;br /&gt;
: A2&lt;br /&gt;
&lt;br /&gt;
= Acknowledgements =&lt;br /&gt;
==Volunteers==&lt;br /&gt;
XXX is developed by a worldwide team of volunteers. The primary contributors to date have been:&lt;br /&gt;
&lt;br /&gt;
* xxx&lt;br /&gt;
* xxx&lt;br /&gt;
&lt;br /&gt;
==Others==&lt;br /&gt;
* xxx&lt;br /&gt;
* xxx&lt;br /&gt;
&lt;br /&gt;
= Road Map and Getting Involved =&lt;br /&gt;
&lt;br /&gt;
As of 2014 our current priorities are identifying insecure components in J2EE applications and Java Web Application Frameworks.  This includes Struts, Spring, Wicket, Grails, and so forth.  We are looking at everything from API related components to configuration and environment.&lt;br /&gt;
&lt;br /&gt;
Involvement in the development and promotion of XXX is actively encouraged!&lt;br /&gt;
You do not have to be a security expert in order to contribute.&lt;br /&gt;
Some of the ways you can help:&lt;br /&gt;
* xxx&lt;br /&gt;
* xxx&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
=Project About=&lt;br /&gt;
{{:Projects/OWASP_Insecure_Web_Components_Project}}  &lt;br /&gt;
&lt;br /&gt;
__NOTOC__ &amp;lt;headertabs /&amp;gt; &lt;br /&gt;
&lt;br /&gt;
[[Category:OWASP Project]]  [[Category:OWASP_Builders]] [[Category:OWASP_Defenders]]  [[Category:OWASP_Document]]&lt;/div&gt;</summary>
		<author><name>Benjamin Watson</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=OWASP_Insecure_Web_Components_Project&amp;diff=165311</id>
		<title>OWASP Insecure Web Components Project</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=OWASP_Insecure_Web_Components_Project&amp;diff=165311"/>
				<updated>2014-01-03T16:48:33Z</updated>
		
		<summary type="html">&lt;p&gt;Benjamin Watson: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;=Main=&lt;br /&gt;
&lt;br /&gt;
&amp;lt;div style=&amp;quot;width:100%;height:160px;border:0,margin:0;overflow: hidden;&amp;quot;&amp;gt;[[File:OWASP_Project_Header.jpg|link=]]&amp;lt;/div&amp;gt;&lt;br /&gt;
&lt;br /&gt;
{| style=&amp;quot;padding: 0;margin:0;margin-top:10px;text-align:left;&amp;quot; |-&lt;br /&gt;
| valign=&amp;quot;top&amp;quot;  style=&amp;quot;border-right: 1px dotted gray;padding-right:25px;&amp;quot; |&lt;br /&gt;
&lt;br /&gt;
==OWASP Insecure Web Components Project==&lt;br /&gt;
&lt;br /&gt;
The OWASP Insecure Web Components Project&lt;br /&gt;
&lt;br /&gt;
==Introduction==&lt;br /&gt;
&lt;br /&gt;
The OWASP Insecure Web Components Project is a repository of identified vulnerable components in popular web application frameworks and languages.  The goal is to give developers and security professionals alike a centralized location where they can identify these vulnerable components when building and securing web applications.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
==Description==&lt;br /&gt;
&lt;br /&gt;
The focus of this project are the insecure components that make up popular web applications, and frameworks.  These can be everything from Struts 2 tags, to ASP.NET MVC Models.  We want to build a comprehensive list that can be used to help uncover issues in current implementations of web applications and aid in the secure architecture of them as well.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
==Licensing==&lt;br /&gt;
OWASP XXX is free to use. It is licensed under the http://creativecommons.org/licenses/by-sa/3.0/ Creative Commons Attribution-ShareAlike 3.0 license], so you can copy, distribute and transmit the work, and you can adapt it, and use it commercially, but all provided that you attribute the work and if you alter, transform, or build upon this work, you may distribute the resulting work only under the same or similar license to this one.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
| valign=&amp;quot;top&amp;quot;  style=&amp;quot;padding-left:25px;width:200px;border-right: 1px dotted gray;padding-right:25px;&amp;quot; |&lt;br /&gt;
&lt;br /&gt;
== What is XXX? ==&lt;br /&gt;
&lt;br /&gt;
OWASP XXX  provides:&lt;br /&gt;
&lt;br /&gt;
* xxx&lt;br /&gt;
* xxx&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== Presentation ==&lt;br /&gt;
&lt;br /&gt;
Link to presentation&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== Project Leader ==&lt;br /&gt;
&lt;br /&gt;
Project leader's name&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== Related Projects ==&lt;br /&gt;
&lt;br /&gt;
* [[OWASP_CISO_Survey]]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
| valign=&amp;quot;top&amp;quot;  style=&amp;quot;padding-left:25px;width:200px;&amp;quot; | &lt;br /&gt;
&lt;br /&gt;
== Quick Download ==&lt;br /&gt;
&lt;br /&gt;
* Link to page/download&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== News and Events ==&lt;br /&gt;
* [20 Nov 2013] News 2&lt;br /&gt;
* [30 Sep 2013] News 1&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== In Print ==&lt;br /&gt;
This project can be purchased as a print on demand book from Lulu.com&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
==Classifications==&lt;br /&gt;
&lt;br /&gt;
   {| width=&amp;quot;200&amp;quot; cellpadding=&amp;quot;2&amp;quot;&lt;br /&gt;
   |-&lt;br /&gt;
   | align=&amp;quot;center&amp;quot; valign=&amp;quot;top&amp;quot; width=&amp;quot;50%&amp;quot; rowspan=&amp;quot;2&amp;quot;| [[File:Owasp-incubator-trans-85.png|link=https://www.owasp.org/index.php/OWASP_Project_Stages#tab=Incubator_Projects]]&lt;br /&gt;
   | align=&amp;quot;center&amp;quot; valign=&amp;quot;top&amp;quot; width=&amp;quot;50%&amp;quot;| [[File:Owasp-builders-small.png|link=]]  &lt;br /&gt;
   |-&lt;br /&gt;
   | align=&amp;quot;center&amp;quot; valign=&amp;quot;top&amp;quot; width=&amp;quot;50%&amp;quot;| [[File:Owasp-defenders-small.png|link=]]&lt;br /&gt;
   |-&lt;br /&gt;
   | colspan=&amp;quot;2&amp;quot; align=&amp;quot;center&amp;quot;  | [[File:Cc-button-y-sa-small.png|link=http://creativecommons.org/licenses/by-sa/3.0/]]&lt;br /&gt;
   |-&lt;br /&gt;
   | colspan=&amp;quot;2&amp;quot; align=&amp;quot;center&amp;quot;  | [[File:Project_Type_Files_CODE.jpg|link=]]&lt;br /&gt;
   |}&lt;br /&gt;
&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=FAQs=&lt;br /&gt;
&lt;br /&gt;
; Q1&lt;br /&gt;
: A1&lt;br /&gt;
&lt;br /&gt;
; Q2&lt;br /&gt;
: A2&lt;br /&gt;
&lt;br /&gt;
= Acknowledgements =&lt;br /&gt;
==Volunteers==&lt;br /&gt;
XXX is developed by a worldwide team of volunteers. The primary contributors to date have been:&lt;br /&gt;
&lt;br /&gt;
* xxx&lt;br /&gt;
* xxx&lt;br /&gt;
&lt;br /&gt;
==Others==&lt;br /&gt;
* xxx&lt;br /&gt;
* xxx&lt;br /&gt;
&lt;br /&gt;
= Road Map and Getting Involved =&lt;br /&gt;
As of XXX, the priorities are:&lt;br /&gt;
* xxx&lt;br /&gt;
* xxx&lt;br /&gt;
* xxx&lt;br /&gt;
&lt;br /&gt;
Involvement in the development and promotion of XXX is actively encouraged!&lt;br /&gt;
You do not have to be a security expert in order to contribute.&lt;br /&gt;
Some of the ways you can help:&lt;br /&gt;
* xxx&lt;br /&gt;
* xxx&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
=Project About=&lt;br /&gt;
{{:Projects/OWASP_Insecure_Web_Components_Project}}  &lt;br /&gt;
&lt;br /&gt;
__NOTOC__ &amp;lt;headertabs /&amp;gt; &lt;br /&gt;
&lt;br /&gt;
[[Category:OWASP Project]]  [[Category:OWASP_Builders]] [[Category:OWASP_Defenders]]  [[Category:OWASP_Document]]&lt;/div&gt;</summary>
		<author><name>Benjamin Watson</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=Projects/OWASP_Insecure_Web_Components_Project&amp;diff=165310</id>
		<title>Projects/OWASP Insecure Web Components Project</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=Projects/OWASP_Insecure_Web_Components_Project&amp;diff=165310"/>
				<updated>2014-01-03T16:40:24Z</updated>
		
		<summary type="html">&lt;p&gt;Benjamin Watson: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;{{Template:Project About&lt;br /&gt;
| project_name =OWASP Insecure Web Components Project&lt;br /&gt;
| project_description =The focus of this project are the insecure components that make up popular web applications, and frameworks.  These can be everything from Struts 2 tags, to ASP.NET MVC Models.  We want to build a comprehensive list that can be used to help uncover issues in current implementations of web applications and aid in the secure architecture of them as well.&lt;br /&gt;
| project_license =Creative Commons Attribution ShareAlike 3.0 License  (best for documentation projects)&lt;br /&gt;
| leader_name1 =Tony UV&lt;br /&gt;
| leader_email1 =tonyuv@owasp.org&lt;br /&gt;
| leader_name2 =Benjamin Watson&lt;br /&gt;
| leader_email2 =rotlogix@gmail.com&lt;br /&gt;
| mailing_list_name = https://lists.owasp.org/mailman/listinfo/owasp_insecure_web_components_project&lt;br /&gt;
| project_road_map = https://www.owasp.org/index.php/Projects/OWASP_Insecure_Web_Components_Project/Roadmap&lt;br /&gt;
}}&lt;/div&gt;</summary>
		<author><name>Benjamin Watson</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=Projects/OWASP_Insecure_Web_Components_Project&amp;diff=165309</id>
		<title>Projects/OWASP Insecure Web Components Project</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=Projects/OWASP_Insecure_Web_Components_Project&amp;diff=165309"/>
				<updated>2014-01-03T16:39:24Z</updated>
		
		<summary type="html">&lt;p&gt;Benjamin Watson: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;{{Template:Project About&lt;br /&gt;
| project_name =OWASP Insecure Web Components Project&lt;br /&gt;
| project_description =The focus of this project are the insecure components that make up popular web applications, and frameworks.  These can be everything from Struts 2 tags, to ASP.NET MVC Models.  We want to build a comprehensive list that can be used to help uncover issues in current implementations of web applications and aid in the secure architecture of them as well.&lt;br /&gt;
| project_license =Creative Commons Attribution ShareAlike 3.0 License  (best for documentation projects)&lt;br /&gt;
| leader_name1 =Tony UV&lt;br /&gt;
| leader_email1 =tonyuv@owasp.org&lt;br /&gt;
| mailing_list_name = https://lists.owasp.org/mailman/listinfo/owasp_insecure_web_components_project&lt;br /&gt;
| project_road_map = https://www.owasp.org/index.php/Projects/OWASP_Insecure_Web_Components_Project/Roadmap&lt;br /&gt;
}}&lt;/div&gt;</summary>
		<author><name>Benjamin Watson</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=Projects/OWASP_Insecure_Web_Components_Project&amp;diff=165308</id>
		<title>Projects/OWASP Insecure Web Components Project</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=Projects/OWASP_Insecure_Web_Components_Project&amp;diff=165308"/>
				<updated>2014-01-03T16:37:34Z</updated>
		
		<summary type="html">&lt;p&gt;Benjamin Watson: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;{{Template:Project About&lt;br /&gt;
| project_name =OWASP Insecure Web Components Project&lt;br /&gt;
| project_description =The focus of this project are the insecure components that make up &lt;br /&gt;
  popular web applications, and frameworks.  These can be everything from&lt;br /&gt;
  Struts 2 tags, to ASP.NET MVC Models. We want to build a comprehensive &lt;br /&gt;
  list that can be used to help uncover issues in current implementations &lt;br /&gt;
  of web applications and aid in the secure architecture of them as well.&lt;br /&gt;
| project_license =Creative Commons Attribution ShareAlike 3.0 License  (best for documentation projects)&lt;br /&gt;
| leader_name1 =Tony UV&lt;br /&gt;
| leader_email1 =tonyuv@owasp.org&lt;br /&gt;
| mailing_list_name = https://lists.owasp.org/mailman/listinfo/owasp_insecure_web_components_project&lt;br /&gt;
| project_road_map = https://www.owasp.org/index.php/Projects/OWASP_Insecure_Web_Components_Project/Roadmap&lt;br /&gt;
}}&lt;/div&gt;</summary>
		<author><name>Benjamin Watson</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=Projects/OWASP_Insecure_Web_Components_Project&amp;diff=165307</id>
		<title>Projects/OWASP Insecure Web Components Project</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=Projects/OWASP_Insecure_Web_Components_Project&amp;diff=165307"/>
				<updated>2014-01-03T16:36:22Z</updated>
		
		<summary type="html">&lt;p&gt;Benjamin Watson: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;{{Template:Project About&lt;br /&gt;
| project_name =OWASP Insecure Web Components Project&lt;br /&gt;
| project_description =The focus of this project are the insecure components that make up &lt;br /&gt;
popular web applications, and frameworks.  These can be everything from&lt;br /&gt;
Struts 2 tags, to ASP.NET MVC Models. We want to build a comprehensive &lt;br /&gt;
list that can be used to help uncover issues in current implementations &lt;br /&gt;
of web applications and aid in the secure architecture of them as well.&lt;br /&gt;
| project_license =Creative Commons Attribution ShareAlike 3.0 License  (best for documentation projects)&lt;br /&gt;
| leader_name1 =Tony UV&lt;br /&gt;
| leader_email1 =tonyuv@owasp.org&lt;br /&gt;
| mailing_list_name = https://lists.owasp.org/mailman/listinfo/owasp_insecure_web_components_project&lt;br /&gt;
| project_road_map = https://www.owasp.org/index.php/Projects/OWASP_Insecure_Web_Components_Project/Roadmap&lt;br /&gt;
}}&lt;/div&gt;</summary>
		<author><name>Benjamin Watson</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=Projects/OWASP_Insecure_Web_Components_Project&amp;diff=165306</id>
		<title>Projects/OWASP Insecure Web Components Project</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=Projects/OWASP_Insecure_Web_Components_Project&amp;diff=165306"/>
				<updated>2014-01-03T16:35:57Z</updated>
		
		<summary type="html">&lt;p&gt;Benjamin Watson: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;{{Template:Project About&lt;br /&gt;
| project_name =OWASP Insecure Web Components Project&lt;br /&gt;
| project_description =&amp;quot;The focus of this project are the insecure components that make up &lt;br /&gt;
popular web applications, and frameworks.  These can be everything from&lt;br /&gt;
Struts 2 tags, to ASP.NET MVC Models. We want to build a comprehensive &lt;br /&gt;
list that can be used to help uncover issues in current implementations &lt;br /&gt;
of web applications and aid in the secure architecture of them as well.&lt;br /&gt;
| project_license =Creative Commons Attribution ShareAlike 3.0 License  (best for documentation projects)&lt;br /&gt;
| leader_name1 =Tony UV&lt;br /&gt;
| leader_email1 =tonyuv@owasp.org&lt;br /&gt;
| mailing_list_name = https://lists.owasp.org/mailman/listinfo/owasp_insecure_web_components_project&lt;br /&gt;
| project_road_map = https://www.owasp.org/index.php/Projects/OWASP_Insecure_Web_Components_Project/Roadmap&lt;br /&gt;
}}&lt;/div&gt;</summary>
		<author><name>Benjamin Watson</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=Projects/OWASP_Insecure_Web_Components_Project&amp;diff=165305</id>
		<title>Projects/OWASP Insecure Web Components Project</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=Projects/OWASP_Insecure_Web_Components_Project&amp;diff=165305"/>
				<updated>2014-01-03T16:35:20Z</updated>
		
		<summary type="html">&lt;p&gt;Benjamin Watson: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;{{Template:Project About&lt;br /&gt;
| project_name =OWASP Insecure Web Components Project&lt;br /&gt;
| project_description =The focus of this project are the insecure components that make up &lt;br /&gt;
popular web applications, and frameworks.  These can be everything from&lt;br /&gt;
Struts 2 tags, to ASP.NET MVC Models. We want to build a comprehensive &lt;br /&gt;
list that can be used to help uncover issues in current implementations &lt;br /&gt;
of web applications and aid in the secure architecture of them as well.&lt;br /&gt;
| project_license =Creative Commons Attribution ShareAlike 3.0 License  (best for documentation projects)&lt;br /&gt;
| leader_name1 =Tony UV&lt;br /&gt;
| leader_email1 =tonyuv@owasp.org&lt;br /&gt;
| mailing_list_name = https://lists.owasp.org/mailman/listinfo/owasp_insecure_web_components_project&lt;br /&gt;
| project_road_map = https://www.owasp.org/index.php/Projects/OWASP_Insecure_Web_Components_Project/Roadmap&lt;br /&gt;
}}&lt;/div&gt;</summary>
		<author><name>Benjamin Watson</name></author>	</entry>

	</feed>