Hosting generously provided by
www.mv.com





Pick Your Language


Cross-Site Scripting: Attackers' New Favorite Flaw
Posted 06/4/07 by Robert

"For years buffer overflow has been the favorite target of online attackers, but no more: Cross-site scripting is now the biggest culprit

That's the scoop from Mitre Corp., which later this week will release its latest findings about the flaws behind publicly-disclosed vulnerabilities.

The number two favorite flaw is SQL injection, says Robert Martin, lead for compatibility and outreach at Mitre, who first discussed the new data at yesterday's Cyber Security Executive Conference in New York. The number of buffer overflow flaws exploited dropped to number three in 2005 and number four so far this year, according to Mitre.

Martin says he was surprised to find that cross-site scripting has become the main flaw that attackers exploit in software. "We hadn't heard anything about this shift."

Mitre has recorded about 20,000 common vulnerability and exposures (CVE) -- the designation given to all publicly reported vulnerabilities -- with around 150 coming in per week. The statistics were based on samples of these CVEs, he says. " - Darkreading

Article Link: http://www.darkreading.com/document.asp?doc_id=103774
Link to this Story: Cross-Site Scripting: Attackers' New Favorite Flaw
Link: Have a Site Suggestion, Material Request, or News? Submit it!
News RSS Feed: Web Security news RSS Feed
Discuss this article    Find Related Stories



External Links:
Copyright 2000-2007 Cgisecurity.com.
Providing Web Security news since 2000.
Information contained on this website may not be copied without explicit permission.
Best Viewed with Netscape.
Website Security Web Application Security solid state drives ssd ebay ebay topdeals nslookup online buy macbook air not work safe software security


Popular Links By Subject

Sponsored Link (Advertise)


Subscribe to CGISecurity.com


The Web Security Mailing List

Contact us
Post News, get linkage!

Name

Email or Homepage:

Subject

Finish the word below: deadb33f

Body