Vulnerability Intelligence and Management by Cybersecurity Help s.r.o.



Incomplete Blacklist to Cross-Site Scripting

Constant variations of web browsers and pages can't be properly followed and recorded by the blacklist that leads to its incompleteness. Using of such blacklist for preventing XSS attacks can't provide a proper protection of the system.
The weakness allows attackers to compromise system's confideniality, integrity and availability that may result in unathorized code or command execution.