|
Failure to Sanitize Invalid Characters in Identifiers in Web Pages Status: Draft Weakness ID: 86 (Weakness Variant)Description Summary The software does not strip out invalid characters in the middle of tag names, URI schemes, and other identifiers, which are still rendered by some web browsers that ignore the characters. Potential Mitigations see the vulnerability category "Cross-site scripting (XSS)" Observed Examples
Other Notes Commonly used characters include null, CRLF, and other non-standard whitespace. Relationships
Taxonomy Mappings
Applicable Platforms Languages All Time of Introduction ImplementationRelated Attack Patterns
Content History Submissions PLOVER. (Externally Mined) Modifications Eric Dalci. Cigital. 2008-07-01. (External) updated Time_of_Introduction CWE Content Team. MITRE. 2008-09-08. (Internal) updated Description, Name, Relationships, Other_Notes, Taxonomy_Mappings Previous Entry Names Invalid Characters in Identifiers (changed 2008-09-09) |
|
|
|||