81
CISA: Most exploited vulnerabilities should have been eradicated decades ago
(www.theregister.com)
An umbrella community for all things cybersecurity / infosec. News, research, questions, are all welcome!
Enjoy!
Looking into the mentioned unforgivable vulnerabilities and stubborn weaknesses published by CISA:
Unforgivable Vulnerabilities (PDF)
"A"characters in:<script>tags, especially in the:'in the:"id"or other identifier fieldinclude($_GET['dir'] . "/config.inc");"../.."or"/a/b/c"inGETorSENDcommands of frequently-used file sharing functionality (e.g., aGETin a web/FTP server, or a send-file command in a chat client)"authenticated=1"cookie/form field"help"(Windows)malloc()/calloc()Stubborn Weaknesses
| CWE-ID | Description | 2023 Rank | |
|
|
| | CWE-787 | Out-of-bounds Write | 1 | | CWE-79 | Improper Neutralization of Input During Web Page Generation (‘Cross-site Scripting’) | 2 | | CWE-89 | Improper Neutralization of Special Elements used in an SQL Command (‘SQL Injection’) | 3 | | CWE-416 | Use After Free | 4 | | CWE-78 | Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') | 5 | | CWE-20 | Improper Input Validation | 6 | | CWE-125 | Out-of-bounds Read | 7 | | CWE-22 | Improper Limitation of a Pathname to a Restricted Directory (‘Path Traversal’) | 8 | | CWE-352 | Cross-Site Request Forgery (CSRF) | 9 | | CWE-476 | NULL Pointer Dereference | 12 | | CWE-287 | Improper Authentication | 13 | | CWE-190 | Integer Overflow or Wraparound | 14 | | CWE-502 | Deserialization of Untrusted Data | 15 | | CWE-119 | Improper Restriction of Operations within Bounds of a Memory Buffer | 17 | | CWE-798 | Use of Hard-coded Credentials | 18 |