Skip to main content

Websec Cybersecurity Blog

Expert insights, trends, research findings, and best practices from our security team to help you strengthen your organization's security posture.

Filtering by: Topic: PHP
(IN)secure session data in CodeIgniter
Blog July 4, 2013

(IN)secure session data in CodeIgniter

A security analysis of how web applications built on the CodeIgniter PHP framework handle user sessions, documenting the recurring implementation mistakes we see on assessments and what pentesters and developers should watch for.

Detecting and exploiting vulnerable PHP-CGI applications
Blog May 24, 2012

Detecting and exploiting vulnerable PHP-CGI applications

A critical vulnerability affecting PHP applications which use the CGI interprerter was published which allows attackers to view the source code and execute code remotely.