DATA VALIDATION & ENCODING (VE8)

Oana can bypass the centralized sanitization routines since they are not being used comprehensively

DATA VALIDATION & ENCODING
8

Oana can bypass the centralized sanitization routines since they are not being used comprehensively

OWASP SCP

15,169

OWASP ASVS

1.1.6,5.2.2,5.2.5

OWASP AppSensor

CAPEC

-

SAFECODE

2,17

How to play?

Sanitization may be used to strip some inputs or outputs of certain unwanted characters. It is not a substitute for data validation and encoding, but may be used in combination (e.g. to remove leading/trailing whitespace from keyboard input). If sanitization is part of the validation and encoding processes, ensure that no relevant input/output is excluded, or can be bypassed by submitting data through a different input stream (e.g. GET instead of POST) or using a different app (e.g. mobile vs. desktop).

NB: The key concept for this card is use of sanitization, and whether such routines are comprehensively applied.

Mappings

OWASP ASVS (4.0): 1.1.6 ,5.2.2 ,5.2.5

Capec: 28 ,31 ,152 ,160 ,468

OWASP SCP: 15,169

OWASP Appsensor:

Safecode: 2,17

ASVS (4.0) Cheatsheetseries Index

ASVS V1.1 - Secure Software Development Lifecycle Requirements

ASVS V5.2 - Sanitization and Sandboxing Requirements

No suitable mappings were found.

Attacks

SQL Injection

Cross-Site Scripting (XSS)

(Session) Data tampering

Privilege escalation

OWASP Cornucopia

  • OWASP Cornucopia is a mechanism in the form of a card game to assist software development teams identify security requirements in Agile, conventional and formal development processes. It is language, platform and technology-agnostic, and is free to use.
  • OWASP Cornucopia is licensed under the Creative Commons Attribution-ShareAlike 3.0 license, so you can copy, distribute and transmit the work, and you can adapt it, and use it commercially, but all provided that you attribute the work and if you alter, transform, or build upon this work, you may distribute the resulting work only under the same or similar licence to this one.
  • © 2012-2025 OWASP Foundation. The Open Worldwide Application Security Project (OWASP) is a nonprofit foundation that works to improve the security of software.