ITPRO

Printed from www.itpro.co.uk

Register to receive our regular email newsletter at http://www.itpro.co.uk/reg/register.

The newsletter contains links to our latest IT news, product reviews, features and how-to guides, plus special offers and competitions.

Skip to navigation

    One in four business web apps has a 'high-risk' flaw

Many business applications such as websites, webmail or wikis are vulnerable to attack.

By Asavin Wattanajantra, 8 Sep 2009 at 15:40

One in four business web applications have at least one high-risk security issue, according to a report.

Analysing the web applications on behalf of its public and private sector clients around the world, NTA Monitor found that 27 per cent of all those tested had a high-risk issue, comparing to 17 per cent the previous year.

NTA looked at a wide range of industry sectors, and saw that the biggest change came with its charity and not-for-profit clients, where the average number of vulnerabilities for each web app more than tripled since last year to 15 per cent.

The sector with the highest number of high-risk vulnerabilities - those that could allow an attacker to gain network access - was services, which had an average of two high-risk flaws per test.

The most secure industry sectors were utilities and legal, as they were the only ones to have no high-level risks.

NTA found that the most common attacks against web application flaws were SQL injection, cross-site scripting and cross-request forgery.

SQL injection was the only one of these that was in the top three high-risk attacks from last year’s report.

Roy Hills, technical director at NTA Monitor, said that user-supplied data needed to be cleaned before it was returned to the browser or stored in the database.

“This reduces the threat of SQL injection, which is a consistently prevalent high-risk throughout 2008 and 2009," he said in a statement.

“SQL injection enables attackers to modify the database queries initiated from an application so users can delete, create or update database records.”

Email to a friend

Print this page

< Previous   Security : News Next >

Be the first to comment on this article

You need to Login or Register to comment.

    You may also like...

 Sponsored Links

advertisement

    You may also like...

advertisement

    Register for IT PRO

You'll get exclusive member benefits including free whitepapers, downloads, Webinars and weekly newsletters full of the latest IT PRO news, reviews, insight and expertise.

Sponsored Links
Advertisement