21615 vulnerabilities classified as CWE-79 (在Web页面生成时对输入的转义处理不恰当(跨站脚本)). AI Chinese analysis included.
CWE-79 represents a critical input validation weakness where software fails to properly sanitize user-supplied data before rendering it in web pages. Attackers typically exploit this vulnerability by injecting malicious scripts, often JavaScript, into trusted websites. When other users view the compromised page, the embedded code executes in their browsers, allowing the attacker to steal session cookies, hijack accounts, or redirect victims to phishing sites. This breach of trust undermines user privacy and application integrity. To prevent such attacks, developers must implement robust input validation and output encoding strategies. By strictly filtering incoming data and ensuring that all dynamic content is properly escaped before being processed by the browser, developers can neutralize dangerous inputs and effectively mitigate the risk of cross-site scripting vulnerabilities.
$username = $_GET['username']; echo '<div class="header"> Welcome, ' . $username . '</div>';http://trustedSite.example.com/welcome.php?username=<Script Language="Javascript">alert("You've been attacked!");</Script><% String eid = request.getParameter("eid"); %> ... Employee ID: <%= eid %><% protected System.Web.UI.WebControls.TextBox Login; protected System.Web.UI.WebControls.Label EmployeeID; ... EmployeeID.Text = Login.Text; %> <p><asp:label id="EmployeeID" runat="server" /></p>| CVE ID | Title | CVSS | Severity | Published |
|---|---|---|---|---|
| CVE-2016-9130 | Revive Adserver 跨站脚本漏洞 — Revive Adserver All versions before 3.2.3 | 5.4 | - | 2017-03-28 |
| CVE-2016-9454 | Revive Adserver 跨站脚本漏洞 — Revive Adserver All versions before 3.2.3 | 5.4 | - | 2017-03-28 |
| CVE-2016-9457 | Revive Adserver 跨站脚本漏洞 — Revive Adserver All versions before 3.2.3 | 4.8 | - | 2017-03-28 |
| CVE-2016-9465 | Nextcloud Server和ownCloud Server 跨站脚本漏洞 — Nextcloud Server & ownCloud Server Nextcloud Server before 10.0.1 & ownCloud Server before 9.0.6 and 9.1.2 | 5.4 | - | 2017-03-28 |
| CVE-2016-9466 | ownCloud Server和Nextcloud Server 跨站脚本漏洞 — Nextcloud Server & ownCloud Server Nextcloud Server before 10.0.1 & ownCloud Server before 9.0.6 and 9.1.2 | 6.1 | - | 2017-03-28 |
| CVE-2016-9470 | Revive Adserver 安全漏洞 — Revive Adserver All versions before 3.2.5 and 4.0.0 | 8.8 | - | 2017-03-28 |
| CVE-2016-9472 | Revive Adserver 跨站脚本漏洞 — Revive Adserver All versions before 3.2.5 and 4.0.0 | 6.1 | - | 2017-03-28 |
| CVE-2017-2683 | Siemens RUGGEDCOM NMS 跨站脚本漏洞 — RUGGEDCOM NMS All versions < V2.1 (Windows and Linux) | 8.2 | - | 2017-02-27 |
| CVE-2014-5408 | Nordex NC2 Cross-site Scripting — Nordex Control 2 (NC2) SCADA | 6.1 | - | 2014-11-05 |
| CVE-2014-5411 | Schneider Electric SCADA Expert ClearSCADA Cross-site Scripting — ClearSCADA | 5.4 | - | 2014-09-18 |
| CVE-2014-5397 | Schneider Electric Wonderware Cross-site Scripting — Wonderware Information Server Portal | 6.1 | - | 2014-08-28 |
| CVE-2014-2370 | Omron NS Series HMI Improper Neutralization of Input During Web Page Generation — NS15 | 5.4 | - | 2014-07-24 |
| CVE-2011-2920 | Spacewalk: spacewalk: cross-site scripting vulnerability allows arbitrary web script execution. — Red Hat Enterprise Linux 6 | 5.5 | Medium | 2014-02-05 |
| CVE-2011-2927 | Spacewalk: spacewalk and red hat network satellite: cross-site scripting vulnerability via search forms — Red Hat Enterprise Linux 6 | 5.4 | Medium | 2014-02-05 |
| CVE-2011-3344 | Spacewalk: spacewalk: cross-site scripting via uri in lookup login/password form — Red Hat Enterprise Linux 6 | 5.4 | Medium | 2014-02-05 |
Vulnerabilities classified as CWE-79 (在Web页面生成时对输入的转义处理不恰当(跨站脚本)) represent 21615 CVEs. The CWE taxonomy describes the weakness; review individual CVEs for product-specific impact.