OWASP's VulnXML Database
Ingo Struck writes "The
Open Web Application Security Project released the VulnXML db for early access to the public. VulnXML is a description of static known vulnerabilities. It provides all necessary information to let an execution engine automatically craft and launch appropriate HTTP, SOAP or WebDAV requests and analyse the response whether the attack had success. Besides it provides some human readable classification of the
described vulnerability. A tool to execute VulnXML records is currently being developed and will help developers to check their web applications against a suite of well-known vulnerabilities described in a portable format."
This story has been posted for 43 minutes, and only 20 or so comments? man, where is everybody?
This post was brought to you by the number 584811 and the characters / and .
Check out BXML for a binary encoding of XML to efficiently carry scientific/array-type data. Feedback appreciated.