Invention Grant
- Patent Title: Systems and methods for analysis of cross-site scripting vulnerabilities
-
Application No.: US14519511Application Date: 2014-10-21
-
Publication No.: US10223533B2Publication Date: 2019-03-05
- Inventor: Isaac M. Dawson
- Applicant: Veracode, Inc.
- Applicant Address: US MA Burlington
- Assignee: Veracode, Inc.
- Current Assignee: Veracode, Inc.
- Current Assignee Address: US MA Burlington
- Agency: Gilliam IP
- Main IPC: G06F21/57
- IPC: G06F21/57 ; G06F17/30 ; H04L29/06

Abstract:
A system for detecting XSS vulnerabilities includes determining the context in which a probe supplied as an input to a webpage or an application exists in a script associated with the webpage or application. A payload is generated based on, at least in part, the context such that during execution of the script, an executable code fragment in the payload can escape out of the context in which the probe exists and into a the global context of the script. The payload may include additional characters that prevent the payload from causing errors in the execution of the script.
Public/Granted literature
- US20160110547A1 SYSTEMS AND METHODS FOR ANALYSIS OF CROSS-SITE SCRIPTING VULNERABILITIES Public/Granted day:2016-04-21
Information query