CWE-84: Improper Neutralization of Encoded URI Schemes in a Web Page

VariantDraft

The web application improperly neutralizes user-controlled input for executable script disguised with URI encodings.

View on MITRE
Back to CWE Lookup

Technical Details

Structure
Simple

Applicable To

Languages
Not Language-Specific
Platforms

Learn More