Cenzic Lists the Weak Spots in App Security

Opinion
May 24, 20072 mins

Security company Cenzic recently released their Q1 2007 Application Security Trend Report which is interesting and rather worrying reading. Here’s their summary:

Cenzic analyzed reported vulnerability information for the January 1, 2007 through March 31, 2007 time period. The analysis identified 1,561 unique vulnerabilities during the first quarter of 20076. Key findings are: * 67% of the vulnerabilities affected Web servers, Web applications and Web browsers. * Applications written in PHP comprise roughly 30% of all vulnerabilities. * Vulnerabilities within the PHP programming language versions 4 and 5,including wrappers, extensions, and bundled components comprised 3% of total vulnerabilities. * Roughly 63% of the Web application vulnerabilities can be accounted for by 4 vulnerability classes: file inclusion, SQL injection, cross-site scripting, and directory traversal. * Roughly 71% of the reported vulnerabilities are classified as easily or trivially exploitable. * Vulnerabilities in Web Server or Web Application Server technologies comprised around 7% of the total reported Web application vulnerabilities. * Remote file inclusion vulnerabilities in PHP comprise 17% of the reported Web application vulnerabilities and were reported in roughly equal proportion to SQL injection vulnerabilities. * 19% of all reported Web application vulnerabilities involved cross-site Scripting.

And when it comes to Web Applications:

1. Adobe Acrobat Reader Cross-Site Scripting and Code Execution 2. Google Desktop Cross-Site Scripting 3. IBM Websphere HTTP Response Splitting 4. Lotus Domino Web Access Cross-Site Scripting 5. PHP Nested Array Denial of Service 6. PHP Multiple Buffer Overflows and Denial of Service 7. IBM Rational ClearQuest Cross-Site Scripting 8. Sun Java Access Manager Multiple Vulnerabilities 9. Apache Tomcat Buffer Overflow via map_uri_to_worker() 10. BEA WebLogic Buffer Overflow and Multiple Vulnerabilities

Sigh.