CWE-86 - CERT CVE

CWE-86 - Improper Neutralization of Invalid Characters in Identifiers in Web Pages

The software does not neutralize or incorrectly neutralizes invalid characters or byte sequences in the middle of tag names, URI schemes, and other identifiers.

CAPEC ID Naziv
CAPEC-247 XSS Using Invalid Characters
CAPEC-73 User-Controlled Filename
CAPEC-85 AJAX Fingerprinting