FYI…

- http://www.securityfocus.com/news/11413
2006-09-15
"…A draft report on the latest numbers from the vulnerability database found that 4,375 security issues had so far been cataloged in the first nine months of 2006, just shy of the 4,538 issues documented last year. The data shows that web flaws have continued their meteoric rise since 2005, capturing the top-three spots on the list of most common vulnerabilities. Buffer overflows, a perennial favorite, fell to the No. 4 slot… The jump in web-based vulnerabilities is fueled by the simplicity of exploiting many of the most common web vulnerabilities, the enormous number of web applications freely available, and the difficulty in eradicating cross-site scripting flaws. Moreover, while many of the vulnerabilities are easy to test for and find, independent security researchers are less likely to probe another group's website to find the flaws, because doing so violates computer intrusion statutes…Cross-site scripting is considered by many security researchers to be a less-than-hackerly technique used by script kiddies, phishers and spammers to fool trusting users. The technique is a key method for injecting malicious code into a victim's web session. Cross-site scripting allows a malicious website to inject code into the context of another website; a user that believes they are interacting with a popular social networking site, for example, might instead be loading a script in from some other malicious site…"

:ph34r: