Versions Compared

Key

  • This line was added.
  • This line was removed.
  • Formatting was changed.

...

Rule

Severity

Likelihood

Remediation Cost

Priority

Level

IDS06-J

high

probable

medium

P12

L1

Related

...

Guidelines

Examples of related vulnerabilities include:

...

...

Search for vulnerabilities resulting from the violation of this rule on the CERT website.

Bibliography

...

...

<ac:structured-macro ac:name="unmigrated-wiki-markup" ac:schema-version="1" ac:macro-id="367eef04-5de5-4c39-842c-a74ccde926f7"><ac:plain-text-body><![CDATA[

[[MITRE 2009

AA. Bibliography#MITRE 09]]

[CWE ID 78

http://cwe.mitre.org/data/definitions/78.html]

...

"Improper

...

Neutralization

...

of

...

Special

...

Elements

...

used

...

in

...

an

...

OS

...

Command

...

('OS

...

Command

...

Injection')

...

"

]]></ac:plain-text-body></ac:structured-macro>

Search for vulnerabilities resulting from the violation of this rule on the CERT website.

Bibliography

<ac:structured-macro ac:name="unmigrated-wiki-markup" ac:schema-version="1" ac:macro-id="ea32443a-6b1f-4bc3-91f6-46ab1ccb7c6b"><ac:plain-text-body><![CDATA[

[[Chess 2007

AA. Bibliography#Chess 07]]

Chapter 5: Handling Input, "Command Injection"]]></ac:plain-text-body></ac:structured-macro>

<ac:structured-macro ac:name="unmigrated-wiki-markup" ac:schema-version="1" ac:macro-id="f00208a1-a3a3-4888-b604-9a28168daea1"><ac:plain-text-body><![CDATA[

[[OWASP 2005

AA. Bibliography#OWASP 05]]

[Reviewing Code for OS Injection

http://www.owasp.org/index.php/Reviewing_Code_for_OS_Injection

...

]

]]></ac:plain-text-body></ac:structured-macro>

<ac:structured-macro ac:name="unmigrated-wiki-markup" ac:schema-version="1" ac:macro-id="370efff0-73a1-4fe1-9987-173ea5637a2b"><ac:plain-text-body><![CDATA[

[[Permissions

...

2008

...

AA.

...

Bibliography#Permissions

...

08]

...

]

...

[Permissions

...

in

...

the Java™ SE 6 Development Kit (JDK)

...

http://java.sun.com/javase/6/docs/technotes/guides/security/permissions.html],

...

Sun

...

Microsystems,

...

Inc.

...

(2008)

]]></ac:plain-text-body></ac:structured-macro>

...

IDS05-J. Do not log unsanitized user input            IDS13-J. Do not assume every character in a string is the same size