• Home
    • ABOUT US
      • VISION
        • SOCIAL NETWORK>
          • FACEBOOK SECURITY
            • TWITTER SECURITY
              • SECURITY BLOG
                • SECURITY PRESENTATION
                  • JOIN LINKEDIN
                    • Ethical Hacking Blog
                    • PEOPLE
                      • CLIENTS
                        • CREDENTIALS
                          • MEDIA
                          • AUDIT
                            • WEBSITE SECURITY AUDIT
                              • APPLICATION SECURITY AUDIT
                                • NETWORK SECURITY AUDIT
                                  • PHYSICAL SECURITY AUDIT
                                  • Compliance
                                    • ISO 27001 IEC 27002 COMPLIANCE
                                      • HIPAA COMPLIANCE
                                        • ISO 20000 COMPLIANCE
                                          • PCI/DSS
                                            • TL 9000
                                            • SERVICES
                                              • PENETRATION TESTING
                                                • MANAGED NETWORK SECURITY
                                                  • MANAGED WEBSITE & APPLICATION SECURITY
                                                    • CONSULTING
                                                      • EMERGENCY RESPONSE & FORENSICS
                                                      • PRODUCTS
                                                        • SECURITY MONITORING
                                                          • GATEWAY SECURITY
                                                            • FORT APPIN ANTI-VIRUS
                                                              • aENCRYPT ENCRYPTION SOFTWARE
                                                              • Industry Focus
                                                                • Aviation & Airlines
                                                                  • Telecom & ISP
                                                                    • Education Sector
                                                                      • BFSI/Banking/Insurance
                                                                        • IT / ITES / BPO
                                                                          • E-Commerce
                                                                            • Government & Defense
                                                                              • Health Care & Life Sciences
                                                                                • Infrastructure
                                                                                  • Manufacturing & Engineering
                                                                                    • Media
                                                                                      • Retail & FMCG
                                                                                        • Security Articles>
                                                                                          • NETWORK SECURITY MANAGEMENT
                                                                                            • Information security companies
                                                                                              • WEB APPLICATION SECURITY>
                                                                                                • Wireless Pen Testing
                                                                                                  • Web Authentication Server
                                                                                                    • Web Application Testing
                                                                                                      • Web App Vulnerability
                                                                                                        • Web Application Monitoring
                                                                                                          • Application Server Monitoring
                                                                                                            • Application Vulnerabilities
                                                                                                              • website security audit
                                                                                                                • Application Security Assessment
                                                                                                                  • Application Penetration Testing
                                                                                                                    • Juniper firewall india
                                                                                                                      • Managed security services
                                                                                                                        • Security consultancy service
                                                                                                                        • NETWORK SECURITY>
                                                                                                                          • TCP IP Stack
                                                                                                                            • E-mail Password Encryption
                                                                                                                              • Block Port Problem
                                                                                                                                • Secured E-mail Server Hosting
                                                                                                                                  • Infosec Phishing Protection
                                                                                                                                    • Information Security Policy
                                                                                                                                      • IT Security Management
                                                                                                                                        • Intrusion Prevention System
                                                                                                                                          • Intruder Detection System
                                                                                                                                            • Internet Security Firewalls
                                                                                                                                              • Identity Access Management
                                                                                                                                                • Security Event Log
                                                                                                                                                  • Cyberoam Firewall
                                                                                                                                                    • Network Security Software
                                                                                                                                                      • Antivirus Firewall Software
                                                                                                                                                        • Symantec Antivirus Corporate
                                                                                                                                                          • Sonicwall firewall
                                                                                                                                                            • Online antivirus
                                                                                                                                                              • Best antivirus 2012
                                                                                                                                                                • Hardware Firewall
                                                                                                                                                                  • Internet software security suites
                                                                                                                                                                  • Industry>
                                                                                                                                                                    • Bank Online Application Security
                                                                                                                                                                      • Healthcare Hipaa Compliance Security
                                                                                                                                                                        • Banking Financial Risk Management
                                                                                                                                                                        • CONSULTING AND AUDIT>
                                                                                                                                                                          • Security Risk Consultant
                                                                                                                                                                            • Enterprise IT Security
                                                                                                                                                                              • Corporate Risk Management
                                                                                                                                                                                • Audit ISO 9001
                                                                                                                                                                                  • ISO 27001 Compliance
                                                                                                                                                                                    • Auditor Wireless Security
                                                                                                                                                                                      • PCI Compliance Credit Card
                                                                                                                                                                                        • Network Security Scanner Scan
                                                                                                                                                                                          • Risk Assesment Management
                                                                                                                                                                                            • ISO 20000 IT Service
                                                                                                                                                                                              • ISO 27001
                                                                                                                                                                                                • TL 9000 telecom
                                                                                                                                                                                                • Data security>
                                                                                                                                                                                                  • XSS Cross-Site Attack
                                                                                                                                                                                                    • SQL Injection Database
                                                                                                                                                                                                      • Database File Encryption
                                                                                                                                                                                                        • VPN HTTPS System
                                                                                                                                                                                                          • IP Spoofing Data Privacy
                                                                                                                                                                                                            • Man In Middle Attack
                                                                                                                                                                                                              • Data Loss Prevention
                                                                                                                                                                                                                • Data Protection Act
                                                                                                                                                                                                                • Appliance>
                                                                                                                                                                                                                  • Voip Voice Encryption
                                                                                                                                                                                                                    • IDS IPS UTM Appliance
                                                                                                                                                                                                                      • Load Balancer Bandwidth Manager
                                                                                                                                                                                                                        • Managed Firewall Services
                                                                                                                                                                                                                          • Cisco Mars Pix
                                                                                                                                                                                                                            • Firewall Web Server
                                                                                                                                                                                                                              • Firewall For Windows Server
                                                                                                                                                                                                                          • SECURITY GROUP
                                                                                                                                                                                                                            • Fort Appin Authorized consultant>
                                                                                                                                                                                                                              • Security-Consulting-Hyderabad-Himayath Nagar
                                                                                                                                                                                                                                • Security-Consulting-Hyderabad-Secunderabad
                                                                                                                                                                                                                                  • Security-Consulting-Rajasthan-Kota
                                                                                                                                                                                                                                    • Security-Consulting-Hyderabad-Ameerpet
                                                                                                                                                                                                                                      • Security-Consulting-Bangalore-JP Nagar
                                                                                                                                                                                                                                        • Security-Consulting-Hyderabad-Dilsukhnagar
                                                                                                                                                                                                                                          • Security-Consulting-Bangalore-Sahakarnagar
                                                                                                                                                                                                                                          • STUDENT TRAINING
                                                                                                                                                                                                                                            • SECURITY FRANCHISE
                                                                                                                                                                                                                                              • CORPORATE SECURITY>
                                                                                                                                                                                                                                                • FORT APPIN ANTIVIRUS
                                                                                                                                                                                                                                                • CYBER INVESTIGATION>
                                                                                                                                                                                                                                                  • INVESTIGATION FRANCHISE

                                                                                                                                                                                                                                                _Application Vulnerability

                                                                                                                                                                                                                                                A Web application vulnerability is a security weakness in a website or its environment. Vulnerabilities usually occur when there is a site development or implementation flaw.

                                                                                                                                                                                                                                                Depending on the type of flaw, malicious users might exploit vulnerabilities, which could change the website, collect visitor's personal information, steal visitor's browser data `or perform other harmful actions to the site or visitors.

                                                                                                                                                                                                                                                Vulnerabilities can be difficult for Web developers to locate because, in many cases, they do not affect the intended use of the application. Plus, there are hundreds of "known" vulnerabilities and new ones are discovered daily.

                                                                                                                                                                                                                                                For example: If a log-in page submits credentials in "clear text," the log-in information is sent to the server unencrypted. Visitors can log in and might not notice any issue.

                                                                                                                                                                                                                                                Attackers who discover the "clear text" vulnerability might try to intercept another visitor's log-in information and exploit it.

                                                                                                                                                                                                                                                You can resolve this issue by adding an SSL certificate to the website which encrypts transactions between visitors and the site.

                                                                                                                                                                                                                                                To avoid vulnerabilities regularly evaluate your site and its environment for flaws. Also, use a daily vulnerability scanner, such as Website Protection Site Scanner, to detect issues.

                                                                                                                                                                                                                                                Hackers today have an ever increasing list of weaknesses in the web application structure at their disposal, which they can exploit to accomplish a wide variety of malicious tasks.

                                                                                                                                                                                                                                                New flaws in web application security measures are constantly being researched both by hackers and by security professionals. Most of these flaws affect all dynamic web applications whilst others are dependent on specific application technologies. In both cases, one may observe how the evolution and refinement of web technologies also brings about new exploits which compromise sensitive databases, provide access to theoretically secure networks, and pose a threat to the daily operation of online businesses.


                                                                                                                                                                                                                                                Web Application Vulnerabilities

                                                                                                                                                                                                                                                • Backup files Security Vulnerability
                                                                                                                                                                                                                                                • Blind SQL/XPath injection Security Vulnerability
                                                                                                                                                                                                                                                • Code execution Security Vulnerability
                                                                                                                                                                                                                                                • Common files Security Vulnerability
                                                                                                                                                                                                                                                • Cookie manipulation Security Vulnerability
                                                                                                                                                                                                                                                • CRLF injection/HTTP response splitting Security Vulnerability
                                                                                                                                                                                                                                                • Cross Site Scripting Security Vulnerability
                                                                                                                                                                                                                                                • Cross Site Scripting in path Security Vulnerability
                                                                                                                                                                                                                                                • Cross Site Scripting in URI Security Vulnerability
                                                                                                                                                                                                                                                • DELETE Method Enabled Security Vulnerability
                                                                                                                                                                                                                                                • Directories with executable permission enabled Security Vulnerability
                                                                                                                                                                                                                                                • Directories with write permissions enabled Security Vulnerability
                                                                                                                                                                                                                                                • Directory Listing Security Vulnerability
                                                                                                                                                                                                                                                • Directory Traversal Security Vulnerability
                                                                                                                                                                                                                                                • Email address found Security Vulnerability
                                                                                                                                                                                                                                                • File inclusion Security Vulnerability
                                                                                                                                                                                                                                                • Full path disclosure Security Vulnerability
                                                                                                                                                                                                                                                • Possible sensitive files Security Vulnerability
                                                                                                                                                                                                                                                • PUT Method Enabled Security Vulnerability
                                                                                                                                                                                                                                                • Script source code disclosure Security Vulnerability
                                                                                                                                                                                                                                                • Sensitive data not encrypted Security Vulnerability
                                                                                                                                                                                                                                                • Source code disclosure Security Vulnerability
                                                                                                                                                                                                                                                • SQL injection Security Vulnerability
                                                                                                                                                                                                                                                • TRACE method is enabled Security Vulnerability
                                                                                                                                                                                                                                                • TRACK method is enabled Security Vulnerability
                                                                                                                                                                                                                                                • Trojan shell script Security Vulnerability
                                                                                                                                                                                                                                                • URL redirection Security Vulnerability
                                                                                                                                                                                                                                                • XFS vulnerability Security Vulnerability
                                                                                                                                                                                                                                                • XPath Injection vulnerability Security Vulnerability


                                                                                                                                                                                                                                                Article source: http://help.godaddy.com/article/4486?isc=&locale=en
                                                                                                                                                                                                                                                Article source: http://www.acunetix.com/vulnerabilities/