21615 vulnerabilities classified as CWE-79 (在Web页面生成时对输入的转义处理不恰当(跨站脚本)). AI Chinese analysis included.
CWE-79 represents a critical input validation weakness where software fails to properly sanitize user-supplied data before rendering it in web pages. Attackers typically exploit this vulnerability by injecting malicious scripts, often JavaScript, into trusted websites. When other users view the compromised page, the embedded code executes in their browsers, allowing the attacker to steal session cookies, hijack accounts, or redirect victims to phishing sites. This breach of trust undermines user privacy and application integrity. To prevent such attacks, developers must implement robust input validation and output encoding strategies. By strictly filtering incoming data and ensuring that all dynamic content is properly escaped before being processed by the browser, developers can neutralize dangerous inputs and effectively mitigate the risk of cross-site scripting vulnerabilities.
$username = $_GET['username']; echo '<div class="header"> Welcome, ' . $username . '</div>';http://trustedSite.example.com/welcome.php?username=<Script Language="Javascript">alert("You've been attacked!");</Script><% String eid = request.getParameter("eid"); %> ... Employee ID: <%= eid %><% protected System.Web.UI.WebControls.TextBox Login; protected System.Web.UI.WebControls.Label EmployeeID; ... EmployeeID.Text = Login.Text; %> <p><asp:label id="EmployeeID" runat="server" /></p>| CVE ID | Title | CVSS | Severity | Published |
|---|---|---|---|---|
| CVE-2017-12221 | Cisco Firepower Management Center 跨站脚本漏洞 — Cisco Firepower Management Center | 5.4 | - | 2017-09-07 |
| CVE-2017-6789 | Cisco Unified Intelligence Center 跨站脚本漏洞 — Cisco Unified Intelligence Center | 6.1 | - | 2017-09-07 |
| CVE-2015-3976 | GE Multilink Cross-site Scripting — Multilink ML800/1200/1600/2400 | 5.4 | - | 2017-08-28 |
| CVE-2017-9555 | Synology Photo Station 跨站脚本漏洞 — Synology Photo Station | 6.1 | - | 2017-08-24 |
| CVE-2017-7421 | Micro Focus Enterprise Developer和Enterprise Server 跨站请求伪造漏洞 — Micro Focus Enterprise Developer, Micro Focus Enterprise Server | 5.4 | - | 2017-08-21 |
| CVE-2017-7422 | Micro Focus Enterprise Developer和Enterprise Server 跨站脚本漏洞 — Micro Focus Enterprise Developer, Micro Focus Enterprise Server | 5.4 | - | 2017-08-21 |
| CVE-2017-9556 | Synology Video Station 跨站脚本漏洞 — Synology Video Station | 5.4 | - | 2017-08-11 |
| CVE-2017-6761 | Cisco Finesse 跨站脚本漏洞 — Cisco Finesse | 6.1 | - | 2017-08-07 |
| CVE-2017-6762 | Cisco Jabber Guest Server 跨站脚本漏洞 — Cisco Jabber Guest Server | 6.1 | - | 2017-08-07 |
| CVE-2017-6764 | Cisco Adaptive Security Appliance 跨站脚本漏洞 — Cisco Adaptive Security Appliance | 5.4 | - | 2017-08-07 |
| CVE-2015-9102 | Synology Photo Station 跨站脚本漏洞 — Photo Station | 5.4 | - | 2017-06-30 |
| CVE-2015-9103 | Synology Note Station 跨站脚本漏洞 — Note Station | 5.4 | - | 2017-06-30 |
| CVE-2015-9104 | Synology Audio Station 跨站脚本漏洞 — Audio Station | 5.4 | - | 2017-06-30 |
| CVE-2015-9105 | Synology Video Station 跨站脚本漏洞 — Video Station | 5.4 | - | 2017-06-30 |
| CVE-2017-6053 | Trihedral VTScada 跨站脚本漏洞 — Trihedral VTScada | 6.1 | - | 2017-06-21 |
| CVE-2015-9056 | Elasticsearch Kibana 跨站脚本漏洞 — Kibana | 6.1 | - | 2017-06-16 |
| CVE-2016-10366 | Elasticsearch Kibana 跨站脚本漏洞 — Kibana | 6.1 | - | 2017-06-16 |
| CVE-2017-8439 | Elasticsearch Kibana 跨站脚本漏洞 — Kibana | 6.1 | - | 2017-06-05 |
| CVE-2017-8440 | Elasticsearch Kibana 跨站脚本漏洞 — Kibana | 6.1 | - | 2017-06-05 |
| CVE-2017-6654 | Cisco Unified Communications Manager 跨站脚本漏洞 — Cisco Unified Communications Manager | 6.1 | - | 2017-05-22 |
| CVE-2017-0890 | Nextcloud Server 搜索模块跨站脚本漏洞 — Nextcloud Server | 5.4 | - | 2017-05-08 |
| CVE-2017-0891 | Nextcloud Server 跨站脚本漏洞 — Nextcloud Server | 6.1 | - | 2017-05-08 |
| CVE-2017-0893 | Nextcloud Server JavaScript库跨站脚本漏洞 — Nextcloud Server | 6.1 | - | 2017-05-08 |
| CVE-2017-6029 | Certec EDV GmbH atvise scada 跨站脚本漏洞 — Certec EDV GmbH atvise scada | 5.4 | - | 2017-05-06 |
| CVE-2017-6611 | Cisco Prime Infrastructure 跨站脚本漏洞 — Cisco Prime Infrastructure | 6.1 | - | 2017-04-20 |
| CVE-2017-6618 | Cisco Integrated Management Controller 输入验证漏洞 — Cisco Integrated Management Controller | 5.4 | - | 2017-04-20 |
| CVE-2017-2687 | Siemens RUGGEDCOM ROX I 安全漏洞 — RUGGEDCOM ROX I All versions | 6.1 | - | 2017-03-29 |
| CVE-2017-6864 | Siemens RUGGEDCOM ROX I 安全漏洞 — RUGGEDCOM ROX I All versions | 5.4 | - | 2017-03-29 |
| CVE-2016-9126 | Revive Adserver 跨站脚本漏洞 — Revive Adserver All versions before 3.2.3 | 5.4 | - | 2017-03-28 |
| CVE-2016-9128 | Revive Adserver 跨站脚本漏洞 — Revive Adserver All versions before 3.2.3 | 6.1 | - | 2017-03-28 |
Vulnerabilities classified as CWE-79 (在Web页面生成时对输入的转义处理不恰当(跨站脚本)) represent 21615 CVEs. The CWE taxonomy describes the weakness; review individual CVEs for product-specific impact.