This site is the archived OWASP Foundation Wiki and is no longer accepting Account Requests.
To view the new OWASP Foundation website, please visit https://owasp.org
Sample form
From OWASP
Revision as of 22:03, 2 September 2008 by EoinKeary (talk | contribs) (New page: <!-- →Font Definitions: @font-face {font-family:"Microsoft Sans Serif"; panose-1:2 11 6 4 2 2 2 2 2 4;} →Style Definitions: p.MsoNormal, li.MsoNormal, div.MsoNormal {margin:...)
Review /Engagement reference: |
|||
Package/Component/Class Name |
|||
|
|||
Finding description |
Location(S) |
Severity |
Recommendation |
No input validation of the HTTPRequest object.getID() function.
Lack of input validation may make the application vulnerable to many types of injection |
com.inc.dostuff.java Lines 20, 55,106
com.inc.main.java Lines 34, 99 |
Critical ▪
Required □
Recommended □
Informational □
|
It is critical that this be addressed prior to deployment to production |