'; } else{ echo ''; } echo '
|
|
|||
Release Date:2025/9/15
Rule Name:Detect XSS Probing Evasion via Unicode Value
Severity:high
CVE ID:
| Descripiton:
|
Cross-site scripting(XSS) is a type of computer security vulnerability tipically found in Web application. XSS enables attackers to inject client-side scripts into Web pages viewed by other users. The keyword 'xss' is usually used by attackers to detect XSS vulneribility of the website. Attackers can bypass 'xss' detection by using javascript function 'fromcharcode' and its Unicode value. This rule detects the Unicode value of 'xss' in HTTP request. This rule supports to defend the A3: Injection of OWASP Top 10 - 2021.
Other reference:None
| Solution:
|
Update vendor patches.