Web Hack List

Collected research

Close encounters of the third kind (client-side JavaScript vulnerabilities)

Close Encounters of the Third Kind: Client-Side JavaScript Vulnerabilities

IBM ran static taint analysis over JavaScript harvested by a deep crawl of 675 sites, the Fortune 500 plus 175 hand-picked ones, analysing fully rendered HTML and the DOM rather than raw source. 98 sites (14%) held DOM-based XSS or open redirects, 2,370 and 221 issues respectively, and 38% of the flaws came from third-party snippets.

Record

Document
Close Encounters of the Third Kind: Client-Side JavaScript Vulnerabilities
Researcher
Ory Segal, Omri Weisman, Adi Sharabani, Yair Amit and Lotem Guy
Published by
ibm.com
Topic
Browser

In the archive

Tags

This page is the archive's own catalogue record. The research is the work of Ory Segal, Omri Weisman, Adi Sharabani, Yair Amit and Lotem Guy, first published at the original source. Preserved copies are kept so the citation survives its host; this one was last captured on .