2015
DOI: 10.1016/j.infsof.2014.07.010
|View full text |Cite
|
Sign up to set email alerts
|

Current state of research on cross-site scripting (XSS) – A systematic literature review

Abstract: Context: Cross-site scripting (XSS) is a security vulnerability that affects web applications. It occurs due to improper or lack of sanitization of user inputs. The security vulnerability caused many problems for users and server applications. Objective: To conduct a systematic literature review on the studies done on XSS vulnerabilities and attacks. Method: We followed the standard guidelines for systematic literature review as documented by Barbara Kitchenham and reviewed a total of 115 studies related to cr… Show more

Help me understand this report

Search citation statements

Order By: Relevance

Paper Sections

Select...
3
1

Citation Types

0
62
0
3

Year Published

2016
2016
2022
2022

Publication Types

Select...
7
3

Relationship

0
10

Authors

Journals

citations
Cited by 115 publications
(65 citation statements)
references
References 96 publications
0
62
0
3
Order By: Relevance
“…These types of attacks may cause severe breaches in security such as Account Hijacking and Cookie/Session theft. [12] State that Cross-site scripting (XSS) is a "security vulnerability that affects web applications. It occurs due to improper or lack of sanitization of user inputs.…”
Section: Cross-site Scriptingmentioning
confidence: 99%
“…These types of attacks may cause severe breaches in security such as Account Hijacking and Cookie/Session theft. [12] State that Cross-site scripting (XSS) is a "security vulnerability that affects web applications. It occurs due to improper or lack of sanitization of user inputs.…”
Section: Cross-site Scriptingmentioning
confidence: 99%
“…Otro trabajo [11], realizó enfoque sistemático para establecer una base de datos sustancial y completa de la literatura de última generación centrada en la detección de ataques. Finalmente, en la artículo [12] se lleva a cabo una revisión sistemática de la literatura sobre vulnerabilidades y ataques XSS hechas en trabajos afines.…”
Section: Introductionunclassified
“…When visiting the webpage containing the injected script, a user runs the script on his/her browser and becomes a victim of XSS attack. For instance, if a user profile on SNSs is infected by XSS, the profiles of the user's friends and other connected user profiles can be easily infected by this attack [4]. A typical XSS attack method is shown in Fig.…”
Section: Introductionmentioning
confidence: 99%