CWE-79 - CERT CVE

CWE-79 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

The software does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.

CAPEC ID Naziv
CAPEC-209 XSS Using MIME Type Mismatch
CAPEC-588 DOM-Based XSS
CAPEC-591 Reflected XSS
CAPEC-592 Stored XSS
CAPEC-63 Cross-Site Scripting (XSS)
CAPEC-85 AJAX Fingerprinting