This site is the archived OWASP Foundation Wiki and is no longer accepting Account Requests.
To view the new OWASP Foundation website, please visit https://owasp.org

OWASP Insecure Web Components Project

From OWASP
Jump to: navigation, search
OWASP Inactive Banner.jpg

OWASP Insecure Web Components Project

Helping to build and secure better web applications through the identification of insecure web components.

Introduction

The OWASP Insecure Web Components Project is a repository of identified vulnerable components in popular web application frameworks and languages. The goal is to give developers and security professionals alike a centralized location where they can identify these vulnerable components when building and securing web applications.


Description

The focus of this project are the insecure components that make up popular web applications, and frameworks. These can be everything from Struts 2 tags, to ASP.NET MVC Models. We want to build a comprehensive list that can be used to help uncover issues in current implementations of web applications and aid in the secure architecture of them as well.

Component Categories

Struts2


Licensing

OWASP Insecure Web Components Project is free to use. It is licensed under the http://creativecommons.org/licenses/by-sa/3.0/ Creative Commons Attribution-ShareAlike 3.0 license], so you can copy, distribute and transmit the work, and you can adapt it, and use it commercially, but all provided that you attribute the work and if you alter, transform, or build upon this work, you may distribute the resulting work only under the same or similar license to this one.



Project Leader

Tony UcedaVelez "UV" Benjamin Watson


News and Events

Classifications

Owasp-incubator-trans-85.png Owasp-builders-small.png
Owasp-defenders-small.png
Cc-button-y-sa-small.png
Project Type Files CODE.jpg