Other nomination
Close encounters of the third kind (client-side JavaScript vulnerabilities)
IBM ran static taint analysis over JavaScript harvested by a deep crawl of 675 sites, the Fortune 500 plus 175 hand-picked ones, analysing fully rendered HTML and the DOM rather than raw source. 98 sites (14%) held DOM-based XSS or open redirects, 2,370 and 221 issues respectively, and 38% of the flaws came from third-party snippets.
Record
- Researcher
- Ory Segal, Omri Weisman, Adi Sharabani, Yair Amit and Lotem Guy
- Published by
- ibm.com
In the archive
Tags
This page is the archive's own catalogue record. The research is the work of Ory Segal, Omri Weisman, Adi Sharabani, Yair Amit and Lotem Guy, first published at the original source. Preserved copies are kept so the citation survives its host.