CWE-79 在Web页面生成时对输入的转义处理不恰当(跨站脚本) 类弱点 22106 条 CVE 漏洞汇总,含 AI 中文分析。
CWE-79 即跨站脚本攻击,属于输入验证类漏洞。攻击者通过在网页中注入恶意脚本,利用服务器未正确过滤用户输入的特性,使受害者在浏览器中执行非预期代码,从而窃取会话令牌或篡改页面内容。开发者应避免此类风险,需严格对用户输入进行白名单验证,并在输出到 HTML 时实施上下文相关的编码与转义,确保危险字符被正确中和。
$username = $_GET['username']; echo '<div class="header"> Welcome, ' . $username . '</div>';http://trustedSite.example.com/welcome.php?username=<Script Language="Javascript">alert("You've been attacked!");</Script><% String eid = request.getParameter("eid"); %> ... Employee ID: <%= eid %><% protected System.Web.UI.WebControls.TextBox Login; protected System.Web.UI.WebControls.Label EmployeeID; ... EmployeeID.Text = Login.Text; %> <p><asp:label id="EmployeeID" runat="server" /></p>| CVE ID | 标题 | CVSS | 风险等级 | Published |
|---|---|---|---|---|
| CVE-2018-16481 | html-page 跨站脚本漏洞 — html-pages | 6.1 | - | 2019-02-01 |
| CVE-2018-16484 | m-server 跨站脚本漏洞 — m-server | 5.4 | - | 2019-02-01 |
| CVE-2019-3911 | LabKey Server 跨站脚本漏洞 — LabKey Server Community Edition | 6.1 | - | 2019-01-30 |
| CVE-2018-18985 | TRIDIUM Niagara Enterprise Security、Niagara AX和Niagara 跨站脚本漏洞 — Tridium Niagara Enterprise Security 2.3u1, all versions prior to 2.3.118.6, Niagara AX 3.8u4, all versions prior to 3.8.401.1, Niagara 4.4u2, all versions prior to 4.4.93.40.2, and Niagara 4.6, all versions prior to 4.6.96.28.4 | 5.4 | - | 2019-01-29 |
| CVE-2019-1655 | Cisco WebEx Meetings Server 跨站脚本漏洞 — Cisco WebEx Meetings Server | 6.1 | - | 2019-01-24 |
| CVE-2019-1668 | Cisco SocialMiner 跨站脚本漏洞 — Cisco SocialMiner | 6.1 | - | 2019-01-24 |
| CVE-2019-1642 | Cisco Firepower Management Center Software 跨站脚本漏洞 — Cisco Firepower Management Center | 6.1 | - | 2019-01-23 |
| CVE-2019-1643 | Cisco Prime Infrastructure 跨站脚本漏洞 — Cisco Prime Infrastructure | 6.1 | - | 2019-01-23 |
| CVE-2018-15455 | Cisco Identity Services Engine 跨站脚本漏洞 — Cisco Identity Services Engine Software | 6.1 | - | 2019-01-23 |
| CVE-2018-15614 | Avaya IP Office one-x Portal组件跨站脚本漏洞 — IP Office | 5.4 | - | 2019-01-23 |
| CVE-2018-15440 | Cisco Identity Services Engine 跨站脚本漏洞 — Cisco Identity Services Engine Software | 6.1 | - | 2019-01-15 |
| CVE-2018-15463 | Cisco Identity Services Engine 跨站脚本漏洞 — Cisco Identity Services Engine Software | 6.1 | - | 2019-01-15 |
| CVE-2018-16887 | Katello 跨站脚本漏洞 — katello | 5.4 | - | 2019-01-13 |
| CVE-2018-15467 | Cisco TMS 跨站脚本漏洞 — Cisco TelePresence Management Suite (TMS) | 6.1 | - | 2019-01-11 |
| CVE-2018-15461 | Cisco Webex Business Suite MyWebex组件跨站脚本漏洞 — Cisco WebEx Meeting Center | 6.1 | - | 2019-01-10 |
| CVE-2018-15457 | Cisco PI 跨站脚本漏洞 — Cisco Prime Infrastructure | 6.1 | - | 2019-01-10 |
| CVE-2018-0482 | Cisco Prime NCS 跨站脚本漏洞 — Cisco Prime Network Control System | 4.8 | - | 2019-01-10 |
| CVE-2018-0483 | Cisco JCF 跨站脚本漏洞 — Cisco Jabber IM for Android | 5.4 | - | 2019-01-10 |
| CVE-2018-18997 | ABB GATE-E1和GATE-E2 跨站脚本漏洞 — ABB GATE-E1 and GATE-E2 | 7.2 | - | 2019-01-03 |
| CVE-2018-6333 | Nuclide 安全漏洞 — Nuclide | 10.0 | - | 2018-12-31 |
| CVE-2018-6341 | React 跨站脚本漏洞 — react-dom | 6.1 | - | 2018-12-31 |
| CVE-2018-8917 | Synology DiskStation Manager 跨站脚本漏洞 — DiskStation Manager (DSM) | 5.4 | - | 2018-12-24 |
| CVE-2018-8918 | Synology Router Manager 跨站脚本漏洞 — Synology Router Manager (SRM) | 5.4 | - | 2018-12-24 |
| CVE-2018-5411 | Pixars Tractor 跨站脚本漏洞 — Tractor | 5.4 | - | 2018-12-13 |
| CVE-2018-16861 | Foreman 跨站脚本漏洞 — foreman | 4.8 | - | 2018-12-07 |
| CVE-2018-18991 | iniNet SpiderControl SCADA WebServer 跨站脚本漏洞 — SCADA WebServer | 6.1 | - | 2018-12-04 |
| CVE-2018-0719 | QNAP Systems QNAP QTS 跨站脚本漏洞 — QTS | 5.5 | Medium | 2018-11-27 |
| CVE-2018-16471 | Rack 跨站脚本漏洞 — Rack | 6.1 | - | 2018-11-13 |
| CVE-2018-14655 | Red Hat Keycloak 跨站脚本漏洞 — keycloak | 5.4 | - | 2018-11-13 |
| CVE-2018-15451 | Cisco Prime Service Catalog 跨站脚本漏洞 — Cisco Prime Service Catalog | 5.4 | - | 2018-11-08 |
CWE-79(在Web页面生成时对输入的转义处理不恰当(跨站脚本)) 是常见的弱点类别,本平台收录该类弱点关联的 22106 条 CVE 漏洞。