S4E just found a high top 10 tcp port service scan
high·Web Vulnerabilities·Updated Dec 16, 2023

window.name DOM XSS Scanner

Various research and studies identified that up to 50% of websites are vulnerable to DOM Based XSS vulnerability.

Est. Time~15 seconds
Scan TypeSingle Scan
Targetsurl, request
CostFree
0
Times Used
by S4E users
0
Assets Scanned
domains & IPs
0
Vulnerabilities Found
confirmed findings
References
Detail

DOM-based XSS vulnerabilities usually arise when JavaScript takes data from an attacker-controllable source, such as the URL, and passes it to a sink that supports dynamic code execution, such as eval() or innerHTML. This enables attackers to execute malicious JavaScript, which typically allows them to hijack other users' accounts.

An attacker can construct a link to send a victim to a vulnerable page with a payload in the query string and fragment portions of the URL. In certain circumstances, such as when targeting a 404 page or a website running PHP, the payload can also be placed in the path.

Solution Advice

Sanitize all parameters received as input from the user.

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.

Online window.name DOM XSS Scanner S4E