Web Hack List

Other nomination

Close encounters of the third kind (client-side JavaScript vulnerabilities)

IBM ran static taint analysis over JavaScript harvested by a deep crawl of 675 sites, the Fortune 500 plus 175 hand-picked ones, analysing fully rendered HTML and the DOM rather than raw source. 98 sites (14%) held DOM-based XSS or open redirects, 2,370 and 221 issues respectively, and 38% of the flaws came from third-party snippets.

Record

Researcher
Ory Segal, Omri Weisman, Adi Sharabani, Yair Amit and Lotem Guy
Published by
ibm.com

In the archive

Tags

This page is the archive's own catalogue record. The research is the work of Ory Segal, Omri Weisman, Adi Sharabani, Yair Amit and Lotem Guy, first published at the original source. Preserved copies are kept so the citation survives its host.