IT Trenches

Sep 8 2008   4:49PM GMT

Did you see this? – 2007 Web Application Security Statistics Project

Troy Tate Profile: Troy Tate

The Web Application Security Consortium (WASC) is pleased to announce the WASC Web Application Security Statistics Project 2007. This initiative is a collaborative industry wide effort to pool together sanitized website vulnerability data and to gain a better understanding about the web application vulnerability landscape.



1. Identify the prevalence and probability of different vulnerability classes 2. Compare testing methodologies against what types of vulnerabilities they are likely to identify.


The statistics was compiled from web application security assessment projects which were made by the following companies in 2007 (in alphabetic



– Booz Allen Hamilton

– BT

– Cenzic with Hailstorm and ClickToSecure


– HP Application Security Center with WebInspect

– Positive Technologies with MaxPatrol

– Veracode with Veracode Security Review

– WhiteHat Security with WhiteHat Sentinel


The overall statistics includes analysis results of 32,717 sites and 69,476 vulnerabilities of different degrees of severity. The detailed information can be found here:

 Comment on this Post

There was an error processing your information. Please try again later.
Thanks. We'll let you know when a new response is added.
Send me notifications when other members comment.

Forgot Password

No problem! Submit your e-mail address below. We'll send you an e-mail containing your password.

Your password has been sent to:

Share this item with your network: