[ insider_reports_insider ] Vulnerability Of Web Applications Increases
Mike Sachoff Staff Writer
2009-11-10
Insider Reports RSS Feed
Web application security provider, Cenzic, has released its report detailing the most common types of Web application vulnerabilities for the first half of 2009.
 | | Vulnerability Of Web Applications Increases |  |
The report identified over 3,100 total vulnerabilities, which is a 10 percent increase in Web application vulnerabilities compared to the second half of 2008.
Popular vendors including Sun, IBM, and Apache continue to be among the top 10 most vulnerable Web applications named. The most common published exploits on commercial applications were SQL Injection and Cross Site Scripting (XSS) vulnerabilities, which account for 25 percent and 17 percent of all Web attacks, respectively.
Among Web browsers, Mozilla Firefox had the largest percentage of Web vulnerabilities, followed by Apple Safari, whose browser showed a vast increase in exploits, due to vulnerabilities reported in the Safari iPhone browser.
Key findings of the report include:
78 percent of the total reported vulnerabilities affected Web technologies, such as Web servers, applications, Web browsers, Plugins and ActiveX, which is a significant increase from last year.
Of Web browser vulnerabilities, Firefox had the largest percentage, at 44 percent. Safari vulnerabilities came in at 35 percent, significantly higher than even Internet Explorer.
Sun Java, PHP, and Apache continue to be among the Top 10 vendors having the most severe vulnerabilities for the first half of 2009.
"The fact that hackers can have direct access to your data using such common outlets is staggering," said Mandeep Khera, chief marketing officer at Cenzic.
"The worst part is that once they get in, it's a free for all. Nothing is safe because there is no such thing as a minor data breach. The average data breach can cost more than $500,000, which can also put a business' livelihood and reputation on the line.
About the Author:
Mike is a staff writer for WebProNews. Visit WebProNews for the latest ebusiness news.
More insider_reports_insider Articles
Insider Reports RSS Feed
|
|