ScyScan
  • Home
  • Web Scanner
  • Virus Scanner
  • Link Checker
  • Tools
    • Web Scanner
    • Virus Scanner
    • Link Checker
    • SSL Checker
    • Whois
    • IP Lookup
    • More
      • SiteCheck
      • ATS detection
      • ROBOT Attack detection
      • HeartBleed detection
      • CCS Injection detection
      • Data encryption
  • Info
    • Blog
    • CVEs
    • News
    • Alerts
    • CWEs
    • CWE Top25 Software
    • English
    • δΈ­ζ–‡
Home/Alerts/Alert detail/

90017β€”XSLT Injection

PUBLISHEDsecurity alertMedium
Active

Metadata

Alert ID:
90017
Risk:
Medium
Type:
Active
CWE:
CWE-91XML Injection (aka Blind XPath Injection)

Summary

Injection using XSL transformations may be possible, and may allow an attacker to read system information, read and write files, or execute arbitrary code.

Solution

Sanitize and analyze every user input coming from any client-side.

References

  • https://www.contextis.com/blog/xslt-server-side-injection-attacks
browse all alerts

ScyScan

Comprehensive free online security scanning and network tools to protect your digital presence.

Security Tools

  • Web Scanner
  • Virus Scanner
  • Link Checker
  • SSL Checker
  • Whois
  • IP Lookup

Help Center

  • FAQ
  • Privacy Policy
  • Terms of Service
  • Feedback
  • Contact Us

Resources

  • Blog
  • Download
  • CVEs
  • CWEs
Follow Us:

Β© 2026 ScyScan. All rights reserved.