Code execution Security Vulnerability

Description

Code injection vulnerabilities occur where the output or content served from a web application can be manipulated in such a way that it triggers server-side code execution. In some poorly written web applications that allow users to modify server-side files (such as by posting to a message board or guestbook), it is sometimes possible to inject code in the scripting language of the web application itself.

Impact
A malicious user may execute arbitrary system commands with the permissions of the web server.

References
Security Focus - Penetration Testing for Web Applications (Part Two)
OWASP PHP Top 5

Acunetix Web Application Security Blog

Latest Article

Web Server Security and Database Server Security

Latest Whitepaper

Why File Upload Forms are a major security threat

Testimonials

“The issues detected were of major impact; if hackers would have found the security holes, they could have hacked an entire Joomla! Site.”

Robin Muilvijk
Quality & Testing Team, Joomla!