The study aims to integrate OWASP Top 10 categories, controlled practical testing, and CVSS-based risk assessment into a single methodological sequence and to evaluate its practical effectiveness in identifying critical web application vulnerabilities.
The findings indicate that while the OWASP Top Ten serves as a strategic reference, the WSTG is superior as a primary technical auditing framework, which enhances audit consistency, precision, and efficiency in evaluating modern web environments.
It is concluded that web application security requires continuous assessment and proactive security practices throughout the software development lifecycle, and adopting OWASP guidelines and implementing effective security controls can significantly enhance the protection and resilience of modern web applications.
S. Banu, H. Shanmatha, Mehdi Gheisari et al.· BOHR International Journal o...· 0 citations
There are differing perceptions regarding framework usage. A key challenge in developing enterprise-scale Software as a Service (SaaS) applications is selecting the right backend web framework. This study addresses this challenge by applying the Simple Multi-Attribute Rating Technique (SMART) method. A total of 15 popu...
Sasa Ani Arnomo, Mhd Adi Setiawan Aritonang, Hendri Kremer et al.· JRST: Jurnal Riset Sains dan...· 0 citations
This study provides a transparent and traceable application of grey-box VAPT at the underreported faculty-subdomain level, linking reproducible technical findings with CVSS-based severity prioritization and practical cybersecurity governance implications.
Akbar, M. Pratama, A. Iskandar et al.· Journal of Embedded Systems,...· 0 citations
The e-commerce platform was declared sufficiently secure against direct penetration attacks on the database but remains vulnerable to end-user access manipulation, providing an objective overview of security in large-scale digital retail systems.
Sari Prabandari, Ahmad Fadilah Nur Fitrah, A. Zulfikar· IC-BESTS: International Conf...· 0 citations
HawkEye is introduced, a modular, web-based vulnerability auditing platform designed to streamline security analysis by integrating multiple scanning tools within a unified dashboard and illustrates how consolidated reporting improves vulnerability prioritization for development teams.
D. R. Patil, Varad Salgare, Devaj Arya et al.· International Journal for Re...· 0 citations
We use cookies to run the site and, with your consent, for analytics and to show ads.
See our Cookie Policy.