Mechanisms exist to ensure all input handled by a web application is validated and/or sanitized.
Does the organization ensure all input handled by a web application is validated and/or sanitized?