Collected research
Close encounters of the third kind (client-side JavaScript vulnerabilities)
Close Encounters of the Third Kind: Client-Side JavaScript Vulnerabilities
IBM ran static taint analysis over JavaScript harvested by a deep crawl of 675 sites, the Fortune 500 plus 175 hand-picked ones, analysing fully rendered HTML and the DOM rather than raw source. 98 sites (14%) held DOM-based XSS or open redirects, 2,370 and 221 issues respectively, and 38% of the flaws came from third-party snippets.
Record
- Document
- Close Encounters of the Third Kind: Client-Side JavaScript Vulnerabilities
- Researcher
- Ory Segal, Omri Weisman, Adi Sharabani, Yair Amit and Lotem Guy
- Published by
- ibm.com
- Topic
- Browser
In the archive
Tags
This page is the archive's own catalogue record. The research is the work of Ory Segal, Omri Weisman, Adi Sharabani, Yair Amit and Lotem Guy, first published at the original source. Preserved copies are kept so the citation survives its host; this one was last captured on .