Packages and Modern Security

Packages and Modern Security

They didn’t need to know as much about SQL Injection or XSS or CSRF or null-byte injection or any of the other various ways web applications could be attacked. I use WordPress as an example of a larger movement towards prepackaged, large, customizable web applications as a basis for a website. They took advantage of the wide distribution of this prepackaged software and used these exploits to attack large numbers of applications, many databases and servers, that all had the same bug.

Source: pragmacoders.com