PHP
Pages22
SQL injection
SQL injection
Command injection
Command injection
Reflected XSS
Reflected XSS
Stored XSS
Stored XSS
File inclusion path manipulation
File inclusion path manipulation
Path traversal
Path traversal
Unvalidated URL redirects
Unvalidated URL redirects
User-controlled authorization checks
User-controlled authorization checks
State changes without a CSRF token
State changes without a CSRF token
Predictable session tokens
Predictable session tokens
Session ID not regenerated after login
Session ID not regenerated after login
Predictable password reset tokens
Predictable password reset tokens
Hard-coded credentials
Hard-coded credentials
Weak password hashing
Weak password hashing
Weak cryptography
Weak cryptography
Hardcoded cryptographic key
Hardcoded cryptographic key
Insecure random-number generation
Insecure random-number generation
Weak Content Security Policy
Weak Content Security Policy
Error-information disclosure
Error-information disclosure
Unrestricted file upload
Unrestricted file upload
Unsafe deserialization
Object injection through untrusted PHP unserialize input
Server-side request forgery
Server-side request forgery