CWE-84: Improper Neutralization of Encoded URI Schemes in a Web Page
VariantDraft
The web application improperly neutralizes user-controlled input for executable script disguised with URI encodings.
View on MITREBack to CWE Lookup
Technical Details
- Structure
- Simple
Applicable To
Not Language-Specific