Products & Releases

New Report Finds Core Vulnerabilities Persist In Web Applications

Cenzic details prevalence of critical application layer vulnerabilities, such as Cross Site Scripting (XSS) and SQL Injection
Campbell, Calif. – April 12, 2012 – Cenzic Inc., the leading provider of application security intelligence to reduce security risks, today announced the release of the Cenzic Trends Report for 2011 through Q1 2012. The report details the continued threat of vulnerabilities within Web applications, mobile applications, and outlines specific vulnerabilities with cloud-based implications. The report reveals an alarming trend for security professionals, in the form of continued prevalence of critical application layer vulnerabilities, such as Cross Site Scripting (XSS) and SQL Injection. Though there are existing fixes for these well known vulnerabilities, these flaws continued to dominate with XSS climbing to a staggering 38 percent of total Web vulnerabilities, increasing slightly from the second half of 2010. SQL Injection accounted for 15 percent of the total number of Web vulnerabilities. “As businesses worry about the next big security threat, they fail to realize the threats that are right in front of them,” said John Weinschenk, CEO of Cenzic. “From an industry-wide perspective, the fact that the amount well known vulnerabilities continue to persist is a signal that education, diligence, and proper coding during the development phase are a necessity in today’s cyber world. Real change can only happen by adhering to these principles.”

The Trends Report also details the vulnerabilities related to cloud and mobile device usage, noting a total of 89 mobile vulnerabilities were made public in 2011, while out of a set of 1201 publically reported vulnerabilities 855 had cloud based security implications. As mobile devices continue to be used to access online cloud computing platforms, emerging hybrid vulnerabilities haved developed as well. “The growing demand for cloud applications and mobile devices that access them is creating a unique problem,” continued Weinschenk. “Each has its own set of security issues, but when used in tandem, they can produce hybrid vulnerabilities that compound threats and increase the complexity of secure coding. By exploiting vulnerabilities in a mobile application a hacker can open up an attack vector to a preexisting vulnerability on the cloud based application, and vice versa.”

Key findings of the Cenzic Trends Report include: Web vulnerabilities

· In the first two months of 2012, 59 percent of all reported security vulnerabilities were Web vulnerabilities

· In 2011, Cross Site Scripting (XSS) accounted for 38 percent of total Web vulnerabilities

Mobile vulnerabilities

· A total of 89 mobile vulnerabilities were made public in 2011 and so far in 2012 (Jan-Feb) 11 mobile vulnerabilities have been made public.

· Sensitive Information Disclosure (28 percent) and Session Authentication and Authorization (28 percent) make up the bulk of the vulnerabilities.

Cloud vulnerabilities

· In 2011, out of a set of 1201 publically reported vulnerabilities 855 had cloud based security implications

· Specific security vulnerabilities were found in cloud-based applications including EyeOS, OrangeHRM, The Parallels Plesk Panel, Oracle Fusion Middleware, Batavi E Commerce, deV!ls ClanPortal, and more. To download a PDF version of the full report, please visit

Important Links Cenzic Mobile Application Security Solution Cenzic Website Cenzic Twitter Cenzic Facebook Tweet this: Cenzic report reveals new stats on Web security, vulnerabilities

About Cenzic Cenzic provides the leading application security intelligence platform to continuously assess Cloud, Mobile and Web applications to reduce online security risk. Cenzic’s solutions scale from single applications to enterprise-level deployments with hybrid approaches that enable testing of applications at optimal levels. Cenzic helps brands of all sizes protect their reputation and manage security risk in the face of malicious attacks. Cenzic's solutions are used in all parts of the software development lifecycle, and most importantly in production, to protect against new threats even after the application has been deployed. Cenzic's application security intelligence platform is architected to handle web, cloud and mobile applications and is the first to provide risk reduction recommendations for business, application developers and specific applications. Today, Cenzic secures more than half a million online applications and trillions of dollars of commerce for Fortune 1000 companies, all major security companies, government agencies, universities and SMB companies.

Editors' Choice
Jai Vijayan, Contributing Writer, Dark Reading
Kelly Jackson Higgins 2, Editor-in-Chief, Dark Reading