CWE
Home > CWE List > VIEW LIST: CWE-629: Weaknesses in OWASP Top Ten (Draft 9)   View the CWE List

VIEW LIST: CWE-629: Weaknesses in OWASP Top Ten (Draft 9)

Weaknesses in OWASP Top Ten
View ID
Status: Draft

629 (View)

ObjectiveCWE nodes in this view (slice) are associated with the OWASP Top Ten.
View Data
CWEs in this viewTotal CWEs
Total24out of695
Views0out of14
Categories0out of64
Weaknesses21out of605
Compound_Elements3out of12
Weakness VariantWeakness Variant Authentication Bypass by Alternate Path/Channel - (288)
Compound Element: Composite Cross-Site Request Forgery (CSRF) - (352)
Weakness BaseWeakness Base Direct Request ('Forced Browsing') - (425)
Weakness BaseWeakness Base External Control of Assumed-Immutable Web Parameter - (472)
Weakness BaseWeakness Base Failure to Encrypt Sensitive Data - (311)
Weakness BaseWeakness Base Failure to Sanitize CRLF Sequences (aka 'CRLF Injection') - (93)
Weakness ClassWeakness Class Failure to Sanitize Data into a Control Plane (aka 'Command Injection') - (77)
Weakness BaseWeakness Base Failure to Sanitize Data into an OS Command (aka 'OS Command Injection') - (78)
Weakness BaseWeakness Base Failure to Sanitize Data into LDAP Queries (aka 'LDAP Injection') - (90)
Weakness BaseWeakness Base Failure to Sanitize Data into SQL Queries (aka 'SQL Injection') - (89)
Weakness BaseWeakness Base Failure to Sanitize Directives in a Web Page (aka 'Cross-site scripting' (XSS)) - (79)
Weakness ClassWeakness Class Information Leak (Information Disclosure) - (200)
Weakness ClassWeakness Class Insufficient Authentication - (287)
Weakness BaseWeakness Base Insufficient Control of Directives in Dynamically Evaluated Code (aka 'Eval Injection') - (95)
Compound Element: Composite Insufficient Control of Filename for Include/Require Statement in PHP Program (aka 'PHP File Inclusion') - (98)
Weakness BaseWeakness Base Insufficiently Protected Credentials - (522)
Weakness BaseWeakness Base Missing or Inconsistent Access Control - (285)
Weakness BaseWeakness Base Missing Required Cryptographic Step - (325)
Weakness ClassWeakness Class Path Traversal - (22)
Weakness VariantWeakness Variant Reflection Attack in an Authentication Protocol - (301)
Compound Element: Composite Unrestricted File Upload - (434)
Weakness BaseWeakness Base Use of Hard-coded Cryptographic Key - (321)
Weakness ClassWeakness Class Weak Encryption - (326)
Weakness BaseWeakness Base XML Injection (aka Blind XPath Injection) - (91)
Page Last Updated: April 11, 2008