CWE
Home > CWE List > VIEW LIST: CWE-629: Weaknesses in OWASP Top Ten (2007) (1.6)  

CWE-629: Weaknesses in OWASP Top Ten (2007)

 
Weaknesses in OWASP Top Ten (2007)
Definition in a New Window Definition in a New Window
View ID: 629 (View: Graph)Status: Draft
+ View Data

View Objective

CWE nodes in this view (graph) are associated with the OWASP Top Ten, as released in 2007.

+ View Metrics
CWEs in this viewTotal CWEs
Total38out of791
Views0out of22
Categories10out of106
Weaknesses25out of651
Compound_Elements3out of12
+ View Audience
StakeholderDescription
Developers

This view outlines the most important issues as identified by the OWASP Top Ten (2007 version), providing a good starting point for web application developers who want to code more securely.

Software Customers

This view outlines the most important issues as identified by the OWASP Top Ten (2007 version), providing customers with a way of asking their software developers to follow minimum expectations for secure code.

Educators

Since the OWASP Top Ten covers the most frequently encountered issues, this view can be used by educators as training material for students.

+ Relationships
NatureTypeIDNameView(s) this relationship pertains toView(s)
HasMemberCategoryCategory712OWASP Top Ten 2007 Category A1 - Cross Site Scripting (XSS)
Weaknesses in OWASP Top Ten (2007) (primary)629
HasMemberCategoryCategory713OWASP Top Ten 2007 Category A2 - Injection Flaws
Weaknesses in OWASP Top Ten (2007) (primary)629
HasMemberCategoryCategory714OWASP Top Ten 2007 Category A3 - Malicious File Execution
Weaknesses in OWASP Top Ten (2007) (primary)629
HasMemberCategoryCategory715OWASP Top Ten 2007 Category A4 - Insecure Direct Object Reference
Weaknesses in OWASP Top Ten (2007) (primary)629
HasMemberCategoryCategory716OWASP Top Ten 2007 Category A5 - Cross Site Request Forgery (CSRF)
Weaknesses in OWASP Top Ten (2007) (primary)629
HasMemberCategoryCategory717OWASP Top Ten 2007 Category A6 - Information Leakage and Improper Error Handling
Weaknesses in OWASP Top Ten (2007) (primary)629
HasMemberCategoryCategory718OWASP Top Ten 2007 Category A7 - Broken Authentication and Session Management
Weaknesses in OWASP Top Ten (2007) (primary)629
HasMemberCategoryCategory719OWASP Top Ten 2007 Category A8 - Insecure Cryptographic Storage
Weaknesses in OWASP Top Ten (2007) (primary)629
HasMemberCategoryCategory720OWASP Top Ten 2007 Category A9 - Insecure Communications
Weaknesses in OWASP Top Ten (2007) (primary)629
HasMemberCategoryCategory721OWASP Top Ten 2007 Category A10 - Failure to Restrict URL Access
Weaknesses in OWASP Top Ten (2007) (primary)629
MemberOfViewView699Development Concepts
Development Concepts (primary)699
+ Relationship Notes

The relationships in this view are a direct extraction of the CWE mappings that are in the 2007 OWASP document. CWE has changed since the release of that document.

+ References
"Top 10 2007". OWASP. 2007-05-18. <http://www.owasp.org/index.php/Top_10_2007>.
+ Content History
Modifications
Modification DateModifierOrganizationSource
2008-09-08CWE Content TeamMITREInternal
updated Description, Name, Relationships, References, Relationship Notes, View Audience, View Structure
Weakness BaseWeakness Base Access Control Bypass Through User-Controlled Key - (639)
Weakness BaseWeakness Base Authentication Bypass Using an Alternate Path or Channel - (288)
Compound Element: CompositeCompound Element: Composite Cross-Site Request Forgery (CSRF) - (352)
Weakness BaseWeakness Base Direct Request ('Forced Browsing') - (425)
Weakness ClassWeakness Class Discrepancy Information Leaks - (203)
Weakness BaseWeakness Base Error Message Information Leak - (209)
Weakness BaseWeakness Base External Control of Assumed-Immutable Web Parameter - (472)
Weakness BaseWeakness Base Failure to Encrypt Sensitive Data - (311)
Weakness BaseWeakness Base Failure to Preserve Web Page Structure ('Cross-site Scripting') - (79)
Weakness BaseWeakness Base Failure to Sanitize CRLF Sequences ('CRLF Injection') - (93)
Weakness BaseWeakness Base Failure to Sanitize Data into LDAP Queries ('LDAP Injection') - (90)
Weakness ClassWeakness Class Improper Access Control (Authorization) - (285)
Weakness ClassWeakness Class Improper Authentication - (287)
Compound Element: CompositeCompound Element: Composite Improper Control of Filename for Include/Require Statement in PHP Program ('PHP File Inclusion') - (98)
Weakness BaseWeakness Base Improper Sanitization of Directives in Dynamically Evaluated Code ('Eval Injection') - (95)
Weakness ClassWeakness Class Improper Sanitization of Special Elements used in a Command ('Command Injection') - (77)
Weakness BaseWeakness Base Improper Sanitization of Special Elements used in an OS Command ('OS Command Injection') - (78)
Weakness BaseWeakness Base Improper Sanitization of Special Elements used in an SQL Command ('SQL Injection') - (89)
Weakness ClassWeakness Class Inadequate Encryption Strength - (326)
Weakness ClassWeakness Class Information Leak (Information Disclosure) - (200)
Weakness VariantWeakness Variant Information Leak Through Debug Information - (215)
Weakness BaseWeakness Base Insufficiently Protected Credentials - (522)
Weakness BaseWeakness Base Missing Required Cryptographic Step - (325)
CategoryCategory OWASP Top Ten 2007 Category A1 - Cross Site Scripting (XSS) - (712)
CategoryCategory OWASP Top Ten 2007 Category A10 - Failure to Restrict URL Access - (721)
CategoryCategory OWASP Top Ten 2007 Category A2 - Injection Flaws - (713)
CategoryCategory OWASP Top Ten 2007 Category A3 - Malicious File Execution - (714)
CategoryCategory OWASP Top Ten 2007 Category A4 - Insecure Direct Object Reference - (715)
CategoryCategory OWASP Top Ten 2007 Category A5 - Cross Site Request Forgery (CSRF) - (716)
CategoryCategory OWASP Top Ten 2007 Category A6 - Information Leakage and Improper Error Handling - (717)
CategoryCategory OWASP Top Ten 2007 Category A7 - Broken Authentication and Session Management - (718)
CategoryCategory OWASP Top Ten 2007 Category A8 - Insecure Cryptographic Storage - (719)
CategoryCategory OWASP Top Ten 2007 Category A9 - Insecure Communications - (720)
Weakness ClassWeakness Class Path Traversal - (22)
Weakness VariantWeakness Variant Reflection Attack in an Authentication Protocol - (301)
Compound Element: CompositeCompound Element: Composite Unrestricted File Upload - (434)
Weakness BaseWeakness Base Use of Hard-coded Cryptographic Key - (321)
Weakness BaseWeakness Base XML Injection (aka Blind XPath Injection) - (91)
Page Last Updated: October 29, 2009