This site uses cookies. By continuing to browse this site you are agreeing to our use of cookies. Find out more.X

OWASP Top 10 released for 2013

Share this article:

The Open Web Application Security Project (OWASP) has released its well-referenced Top 10 risks list facing developers.

For another year, ‘injection', which includes vulnerabilities such as SQL injection, was rated as the top application security risk. It was followed by ‘broken authentication and session management', which can lead to password, key and session compromises. Coming in third was ‘cross-site scripting', a flaw that lets attackers inject data-stealing code into a website not under their control.

In 2012, injection also held the top spot. This year, broken authentication and session management and cross-site scripting switched positions on the list.

According to OWASP, which had been seeking feedback for this year's list for several months, the rankings are meant to "raise awareness about application security by identifying some of the most critical risks facing organisations".

The OWASP Top 10 project, first unveiled in 2003, is often referenced by standards groups and US government agencies. 

However, some security experts caution that the list should not be viewed as a "prescriptive" guide for securing software because it is too broad. As proof, they point to the fact that the list hasn't seen very much movement since it was first released.

Share this article:

SC webcasts on demand

This is how to secure data in the cloud


Exclusive video webcast & Q&A sponsored by Vormetric


As enterprises look to take advantage of the cloud, they need to understand the importance of safeguarding their confidential and sensitive data in cloud environments. With the appropriate security safeguards, such as fine-grained access policies, a move to the cloud is as, or more, secure than an on-premise data storage.


View the webcast here to find out more

More in News

'Sophisticated' Chinese hackers launched attacks against 43,000 computer systems

'Sophisticated' Chinese hackers launched attacks against 43,000 computer ...

A new report reveals that a Chinese cyber-espionage group is closely affiliated with government and carried out attacks against the likes of Fortune 500 companies and government agencies.

Hackers smuggle out stolen data disguised as videos

Hackers smuggle out stolen data disguised as videos

Around a dozen organisations, including at least one financial sector company, have been hit by a new form of hacking where attackers hide stolen corporate data inside video files that ...

White House breached: Russian hackers suspected

White House breached: Russian hackers suspected

Russian hackers are allegedly behind a breach at the US President's office, while Russia's BlackEnergy malware has been used to attack US SCADA system suppliers.