Title :
Security in Open Source Web Content Management Systems
Author :
Meike, Michael ; Sametinger, Johannes ; Wiesauer, Andreas
Author_Institution :
Trusted Bytes, Austria
Abstract :
Typically, users of Web content management systems lack expert knowledge of the technology itself, let alone the security issues therein. Complicating the matter, WCMS vulnerabilities are attractive targets for potential attackers. A security analysis of two popular, open-source WCMSs exposed significant security holes, despite the obvious efforts of their developer communities. These vulnerabilities leave the applications and their nonexpert users open to exploitation.
Keywords :
Web sites; content management; public domain software; security of data; Web content management system; open source WCMS; security analysis; Content management; Data security; Employment; HTML; Information security; Internet; Permission; Publishing; Web server; XML; Internet application; electronic commerce; open source software; security;
Journal_Title :
Security & Privacy, IEEE
DOI :
10.1109/MSP.2009.104