With the advent of World Wide Web, information sharing through internet increased drastically. So web applications security is today’s most significant battlefield between attackers and resources of web service. It is likely to remain so for the foreseeable future. By considering recent attacks it has been found that major attacks in Web Applications have been carried out even system having authentication mechanisms. Malicious users getting access into systems, reasons may be anything but getting third party access into systems shell violet organization policies. Authenticating an object means confirming its provenance to service, whereas authenticating a person often consists of verifying their identity. Depends on application authentication scheme will implement one or more authentication factors. In computer security, authentication is the process of attempting to verify the digital identity of user to server for getting service, in this process server don’t knows who requesting service, irrespective of identification if server provides service then possibility to getting access by unauthorized users. Mainly these vulnerable authentication applications lead to security risks.

