Improper Sanitization of Script in Attributes of IMG Tags in a Web Page |
Weakness ID: 82 (Weakness Variant) | Status: Incomplete |
Description Summary
The web application does not filter or incorrectly filters scripting elements within attributes of HTML IMG tags, such as the src attribute.
Extended Description
Attackers can embed XSS exploits into the values for IMG attributes (e.g. SRC) that is streamed and then executed in a victim's browser. Note that when the page is loaded into a user's browsers, the exploit will automatically execute.
Reference | Description |
---|---|
CVE-2006-3211 | Stored XSS in a guestbook application using a javascript: URI in a bbcode img tag. |
CVE-2002-1649 | javascript URI scheme in IMG tag. |
CVE-2002-1803 | javascript URI scheme in IMG tag. |
CVE-2002-1804 | javascript URI scheme in IMG tag. |
CVE-2002-1805 | javascript URI scheme in IMG tag. |
CVE-2002-1806 | javascript URI scheme in IMG tag. |
CVE-2002-1807 | javascript URI scheme in IMG tag. |
CVE-2002-1808 | javascript URI scheme in IMG tag. |
Nature | Type | ID | Name | View(s) this relationship pertains to![]() |
---|---|---|---|---|
ChildOf | ![]() | 83 | Failure to Sanitize Script in Attributes in a Web Page | Development Concepts (primary)699 Research Concepts (primary)1000 |
Submissions | ||||
---|---|---|---|---|
Submission Date | Submitter | Organization | Source | |
PLOVER | Externally Mined | |||
Modifications | ||||
Modification Date | Modifier | Organization | Source | |
2008-07-01 | Eric Dalci | Cigital | External | |
updated Time of Introduction | ||||
2008-09-08 | CWE Content Team | MITRE | Internal | |
updated Relationships, Taxonomy Mappings | ||||
2008-10-14 | CWE Content Team | MITRE | Internal | |
updated Description | ||||
2009-05-27 | CWE Content Team | MITRE | Internal | |
updated Description, Name | ||||
2009-10-29 | CWE Content Team | MITRE | Internal | |
updated Relationships | ||||
2009-12-28 | CWE Content Team | MITRE | Internal | |
updated Observed Examples | ||||
Previous Entry Names | ||||
Change Date | Previous Entry Name | |||
2008-04-11 | Script in IMG Tags | |||
2009-05-27 | Failure to Sanitize Script in Attributes of IMG Tags in a Web Page | |||