CWE-79 在Web页面生成时对输入的转义处理不恰当(跨站脚本) 类弱点 22106 条 CVE 漏洞汇总,含 AI 中文分析。
CWE-79 即跨站脚本攻击,属于输入验证类漏洞。攻击者通过在网页中注入恶意脚本,利用服务器未正确过滤用户输入的特性,使受害者在浏览器中执行非预期代码,从而窃取会话令牌或篡改页面内容。开发者应避免此类风险,需严格对用户输入进行白名单验证,并在输出到 HTML 时实施上下文相关的编码与转义,确保危险字符被正确中和。
$username = $_GET['username']; echo '<div class="header"> Welcome, ' . $username . '</div>';http://trustedSite.example.com/welcome.php?username=<Script Language="Javascript">alert("You've been attacked!");</Script><% String eid = request.getParameter("eid"); %> ... Employee ID: <%= eid %><% protected System.Web.UI.WebControls.TextBox Login; protected System.Web.UI.WebControls.Label EmployeeID; ... EmployeeID.Text = Login.Text; %> <p><asp:label id="EmployeeID" runat="server" /></p>| CVE ID | 标题 | CVSS | 风险等级 | Published |
|---|---|---|---|---|
| CVE-2018-6590 | CA API Developer Portal 跨站脚本漏洞 — CA API Developer Portal | 6.1 | - | 2018-08-03 |
| CVE-2018-0406 | Cisco Web Security Appliance 跨站脚本漏洞 — Cisco Web Security Appliance unknown | 6.1 | - | 2018-08-01 |
| CVE-2018-0407 | Cisco Small Business 300 Series(Sx300)Managed Switches 跨站脚本漏洞 — Cisco Small Business 300 Series Managed Switches unknown | 5.4 | - | 2018-08-01 |
| CVE-2018-0408 | Cisco Small Business 300 Series(Sx300)Managed Switches 跨站脚本漏洞 — Cisco Small Business 300 Series Managed Switches unknown | 5.4 | - | 2018-08-01 |
| CVE-2018-0411 | Cisco Unified Communications Manager 跨站脚本漏洞 — Cisco Unified Communications Manager unknown | 6.1 | - | 2018-08-01 |
| CVE-2016-8608 | Red Hat JBoss BRMS和BPM Suite 跨站脚本漏洞 — BRMS | 5.4 | - | 2018-08-01 |
| CVE-2016-8639 | Foreman 跨站脚本漏洞 — foreman | 5.4 | - | 2018-08-01 |
| CVE-2016-8634 | Foreman 跨站脚本漏洞 — foreman | 5.4 | - | 2018-08-01 |
| CVE-2016-8613 | Foreman 跨站脚本漏洞 — foreman | 6.1 | - | 2018-07-31 |
| CVE-2018-10609 | Martem GW6和GWM 跨站脚本漏洞 — TELEM-GW6/GWM | 6.1 | - | 2018-07-31 |
| CVE-2018-3773 | metascrape npm模块跨站脚本漏洞 — metascraper | 6.1 | - | 2018-07-30 |
| CVE-2017-7514 | Red Hat Satellite 跨站脚本漏洞 — Red Hat Satellite | 5.4 | - | 2018-07-30 |
| CVE-2017-7463 | Red Hat JBoss BRMS和BPM Suite 跨站脚本漏洞 — business-central | 6.1 | - | 2018-07-27 |
| CVE-2017-15125 | Red Hat CloudForms 跨站脚本漏洞 — cloudforms | 5.4 | - | 2018-07-27 |
| CVE-2017-12175 | Red Hat Satellite 跨站脚本漏洞 — Satellite | 5.4 | - | 2018-07-26 |
| CVE-2017-7538 | Red Hat Satellite 跨站脚本漏洞 — Satellite | 5.4 | - | 2018-07-26 |
| CVE-2017-7535 | Foreman 跨站脚本漏洞 — foreman | 5.4 | - | 2018-07-26 |
| CVE-2018-3771 | statics-server 跨站脚本漏洞 — statics-server | 6.1 | - | 2018-07-20 |
| CVE-2018-0390 | Cisco Webex 跨站脚本漏洞 — Cisco Webex unknown | 6.1 | - | 2018-07-18 |
| CVE-2018-0396 | Cisco Unified Communications Manager IM and Presence Service Software 跨站脚本漏洞 — Cisco Unified Communications Manager IM And Presence Service unknown | 5.4 | - | 2018-07-18 |
| CVE-2018-0400 | Cisco Unified Contact Center Express 跨站脚本漏洞 — Cisco Unified Contact Center Express unknown | 6.1 | - | 2018-07-18 |
| CVE-2018-0401 | Cisco Unified Contact Center Express 跨站脚本漏洞 — Cisco Unified Contact Center Express unknown | 6.1 | - | 2018-07-18 |
| CVE-2018-0402 | Cisco Unified Contact Center Express 跨站请求伪造漏洞 — Cisco Unified Contact Center Express unknown | 8.8 | - | 2018-07-18 |
| CVE-2018-0403 | Cisco Unified Contact Center Express 信息泄露漏洞 — Cisco Unified Contact Center Express unknown | 9.1 | - | 2018-07-18 |
| CVE-2018-0366 | Cisco Web Security Appliance 跨站脚本漏洞 — Cisco Web Security Appliance unknown | 6.1 | - | 2018-07-16 |
| CVE-2018-11450 | Siemens PLM Software TEAMCENTER 跨站脚本漏洞 — Siemens PLM Software TEAMCENTER | 6.1 | - | 2018-07-09 |
| CVE-2018-3763 | Nextcloud Calendar 跨站脚本漏洞 — Nextcloud Calendar application | 4.8 | - | 2018-07-05 |
| CVE-2018-3764 | Nextcloud Contacts 跨站脚本漏洞 — Nextcloud Contacts application | 4.8 | - | 2018-07-05 |
| CVE-2018-3769 | ruby-grape ruby gem 跨站脚本漏洞 — ruby-grape ruby gem | 6.1 | - | 2018-07-05 |
| CVE-2018-8928 | Synology CardDAV Server Address Book Editor 跨站脚本漏洞 — CardDAV Server | 5.4 | - | 2018-07-05 |
CWE-79(在Web页面生成时对输入的转义处理不恰当(跨站脚本)) 是常见的弱点类别,本平台收录该类弱点关联的 22106 条 CVE 漏洞。