Versions Compared

Key

  • This line was added.
  • This line was removed.
  • Formatting was changed.
Comment: Migrated to Confluence 4.0

...

Rule

Severity

Likelihood

Remediation Cost

Priority

Level

IDS03-J

medium

probable

medium

P8

L2

Related Guidelines

<ac:structured-macro ac:name="unmigrated-wiki-markup" ac:schema-version="1" ac:macro-id="2e0d180d-5376-4281-b86c-463006580580"><ac:plain-text-body><![CDATA[

[ISO/IEC TR 24772:2010http://www.aitcnet.org/isai/]

Injection [RST] ]]></ac:plain-text-body></ac:structured-macro>

MITRE CWE

CWE-144. Improper neutralization of line delimiters

 

CWE-150. Improper neutralization of escape, meta, or control sequences

Bibliography

<ac:structured-macro ac:name="unmigrated-wiki-markup" ac:schema-version="1" ac:macro-id="3c0a3908-a09f-4c66-941a-e33eb7500809"><ac:plain-text-body><! [CDATA[ [[API 2006

AA. References#API 06]]

] ]></ac:plain-text-body></ac:structured-macro><ac:structured-macro ac:name="unmigrated-wiki-markup" ac:schema-version="1" ac:macro-id="8a86c48f-8c17-483f-bb72-606cb9b77ef1"><ac:plain-text-body><![CDATA

[ [[OWASP 2008

AA. References#OWASP 08]]

]] ></ac:plain-text-body></ac:structured-macro>

<ac:structured-macro ac:name="unmigrated-wiki-markup" ac:schema-version="1" ac:macro-id="3ffebcb7-d5ef-4bb4-9904-449b9d88f817"><ac:plain-text-body><![CDATA[

[ [PCI DSS Standard

https://www.pcisecuritystandards.org/security_standards/pci_dss.shtml]]

] ]></ac:plain-text-body></ac:structured-macro>

...

IDS02-J. Canonicalize path names before validating them