EasyAudit International EasyAudit International
Pages Menu
  • Agreements
  • Frequently Asked Questions
  • Blog

Missing Function Level Access Control (A7)

Home » Missing Function Level Access Control (A7)

Applications do not always protect application functions properly. Sometimes, function level protection is managed via configuration, and the system is misconfigured. Sometimes, developers must include the proper code checks, and they forget.
Detecting such flaws is easy. The hardest part is identifying which pages (URLs) or functions exist to attack.

Technical Specifications

  • Technical specifications
  • WASC TC v2.0 Classes Coverage
  • WASC TC v1.0 Classes Coverage
  • OWASP Top Ten 2013 Coverage
  • OWASP Top Ten 2010 Coverage
  • OWASP Top Ten 2007 Coverage
  • OWASP Top Ten 2004 Coverage
  • 2011 CWE/SANS Top 25 Coverage
  • 2010 CWE/SANS Top 25 Coverage
  • 2009 CWE/SANS Top 25 Coverage
  • The Health Insurance Portability and Accountability Act (HIPAA)
  • Payment Card Industry Data Security Standard (PCI DSS)
  • NIST Special Publication 800-53
  • Sarbanes-Oxley Act (SOX)
  • DISA Security Technical Implementation Guide (STIG)
  • ISO/IEC 27001:2005 Coverage
  • ISO/IEC 27001:2013 Coverage

OWASP Top 10 2013 Contents

  • OWASP Top Ten 2013
  • Injection
  • Broken Authentication and Session Management
  • Cross-Site Scripting, XSS
  • Insecure Direct Object References
  • Security Misconfiguration
  • Sensitive Data Exposure
  • Missing Function Level Access Control
  • Cross-Site Request Forgery, CSRF
  • Using Components with Known Vulnerabilities
  • Unvalidated Redirects and Forwards

  • Providers Agreement
  • Organizations Agreement
  • Resellers
  • Partners

Learn More

  • Blog
  • White Papers
  • Training
  • Newsletter
  • Technical specifications
  • Press Kit

Products

  • EasyAudit WEB
  • EasyAudit WEB Full-Time
  • EasyAudit NET
  • EasyAudit NET Full-Time
  • EasyAudit AEO
  • EasyAudit AEO Full-Time

ISGroup SRL

Tel (+39) 045 4853232
Mail [email protected]

Via San Giusto, 7
37121 Verona VR, ITALY
CF e P.IVA 04164220230
REA VR-397513

EasyAudit

  • EasyAudit International (English)
  • EasyAudit Italiano (Italian)
  • EasyAudit Español (Spanish)
  • EasyAudit Deutsch (German)
  • EasyAudit Français (French)
  • EasyAudit 中国的 (Chinese)

Enterprise Services

  • ISGroup International (English)
  • ISGroup Italiano (Italian)
  • ISGroup Deutsch (German)
  • ISGroup Français (French)
  • ISGroup русский (Russian)
  • ISGroup 中国的 (Chinese)

Social

Twitter Google Plus Facebook Linkedin Skype RSS

Do you like EasyAudit? Show your appreciation!
Follow @isgroupsrl Tweet

Copyright © 2026 ISGroup SRL - All rights reserved