'; } else{ echo ''; } echo '
|
|||
Release Date:2025/9/15
Rule Name:Detect XSS Injection with '<body onload'
Severity:critical
CVE ID:
Descripiton:
|
Cross-site scripting(XSS) is a type of computer security vulnerability tipically found in Web application. XSS enables attackers to inject client-side scripts into Web pages viewed by other users. HTML events define the browser actions and the user actions. The 'onload' event is triggered immediately when the browser load the object successfully. Attackers can inject malicious code via '<body onload' to harm users. This rule detects '<body onload' in HTTP request. This rule supports to defend the A3: Injection of OWASP Top 10 - 2021.
Other reference:None
Solution:
|
Update vendor patches.