SQL Injection

[Release] New modules

Security never stands still, which is why we update our service on a regular basis to help you keep up with the latest vulnerabilities. Here are a few of the modules included in this week’s release.

 

OWASP TOP 10: Injection

The first one on the list is Injection. This type of finding is more like a category, and includes all kinds of vulnerabilities where an application sends untrusted data to an interpreter. It is often found in database queries, but other examples are OS commands, XML parsers or when user input is sent as program arguments.

What is an SQL Injection and how do you fix it?

SQL injection flaws are very critical. A remote attacker will gain access to the underlying database. In the worst case scenario it allows the attacker to read, write and delete content in the database. This blog post explain what it is and how you fix it.

New vulnerability findings: Joomla, JBoss, Jenkins and others!

During the past month, a great deal has happened in the web security landscape, and we have added a ton of new findings to the service. Some of these findings come from other security companies’ public disclosures, whilst others are the results of internal audits of responsible disclosure programs.

SQL Injection in 1 min!

A clever attacker can with ease gather all the intelligence he/she needs in order to conduct a full fledged exploit to reveal all the usernames (emails) and passwords of your website.