分析了Web 应用中存在的主要安全缺陷,设计了一种基于XML 的Web 应用安全缺陷特征库模型—WAML,讨论了WAML 的具体描述内容,并给出了Web 应用安全管理系统的设计方案。 关键词:Web 应用;安全缺陷;WAML;XML A Description Schema of Web Application Vulnerability Based on XML Ding Ni , Gu Yunhua (School of Computer and Software , Nanjing University of Information Science and Technology , Nanjing , Jiangsu , 210044) Abstract: The common vulnerabilities existed in the current Web applications are pointed out and the present description methods of vulnerability are analyzed. Thus WAML(Web Application Markup Language)—a Web application description schema is designed based on XML and the specification of the module is discussed in detail.Then a model of Web Application Security Management System is discussed. Keywords: Web Application; vulnerability; WAML; XML