Release Notes
Release Notes
v2.2
****
New bugs:
v2.1
****
New bugs:
v2.0
****
New bugs:
- BEAST/CRIME/BREACH Attacks
- Buffer Overflow (Local)
- Buffer Overflow (Remote)
- Denial-of-Service (Large Chunk Size)
- Denial-of-Service (SSL-Exhaustion)
- Local Privilege Escalation (sendpage)
- phpMyAdmin BBCode Tag XSS
- SQLiteManager PHP Code Injection
- SQLiteManager XSS
- SSL 2.0 Deprecated Protocol
Modifications:
New features:
v1.9+
*****
Modifications:
- Blog entries per user ('Show all' and 'Delete' entry options)
- bWAPP reset functionality only available for users with admin privileges
New features:
v1.9
****
New bugs:
New features:
Modifications:
v1.8
****
New bugs:
- Insecure FTP
- Insecure WebDAV
- PHP CGI Remote Code Execution
- Server-Side Includes Injection
New features:
Bug fixes:
v1.7
****
New bugs:
New features:
Modifications:
v1.6
****
New features:
Modifications:
- Addition of an insecure jQuery script
v1.5
****
New features:
Bug fixes:
Modifications:
v1.4
****
New features:
- LDAP Injection
- Client-Side Validation (Password)
- PHP Eval Function
- Remote and Local File Inclusion
- Unsecure files: phpinfo.php, config.inc, test.php
- Integration with bee-box (Ubuntu OS)
Bug fixes:
Modifications:
Number of bugs: 47
New features:
Bug fixes:
- HTML5 issues
Modifications
v1.2
****
New features:
Bug fixes:
Modifications
- Name change: Session Management - Cookie Security >> Session Management - Cookies
(HTTPOnly)
- Name change: Cross-Site Scripting - Stored >> Cross-Site Scripting - Stored
(Blog)
v1.1
****
New features:
Bug fixes:
v1.01
*****
New features:
- none
Bug fixes:
v1.0
*****
v0.15
*****
- Layout
- Code optimization
- New 'Info' page
v0.14
*****
- Layout
- Code optimization
v0.13
*****
- Code optimization
- Modifications:
- XSS & HTML Injection Stored
- No 'HTML entities check' in the SQL insert statement
- 'HTML entities check' in the HTML output
- New:
- Authorization Testing - Restrict Device Access
Upcoming bugs
/////////////
- JSON
- AJAX
- Web Services