ScyScan
  • 首页
  • 安全扫描
  • 病毒扫描程序
  • 链接扫描
  • 安全工具
    • SSL证书检查
    • Whois 查询
    • IP 查询
    • 一次性密钥
    • 更多
      • 网站检查
      • ATS 合规检测
      • ROBOT Attack 漏洞检测
      • HeartBleed 漏洞检测
      • CCS Injection 漏洞检测
  • 安全资讯
    • CVE 列表
    • 新闻列表
    • 警报列表
    • CWE 列表
    • CWE Top25 Software
    • English
    • 中文
首页/警报列表/警报详细/

90017—XSLT Injection

PUBLISHEDsecurity alertMedium
Active

Metadata

Alert ID:
90017
Risk:
Medium
Type:
Active
CWE:
CWE-91XML Injection (aka Blind XPath Injection)

摘要

Injection using XSL transformations may be possible, and may allow an attacker to read system information, read and write files, or execute arbitrary code.

解决方案

Sanitize and analyze every user input coming from any client-side.

参考

  • https://www.contextis.com/blog/xslt-server-side-injection-attacks
browse all alerts
相关工具:检查可疑链接 →运行更深入的网站漏洞扫描 →

ScyScan

全面的免费在线安全扫描和网络工具,保护您的数字资产。

安全工具

  • 安全扫描
  • 病毒扫描程序
  • 链接扫描
  • SSL证书检查
  • Whois 查询
  • IP 查询

帮助中心

  • 常见问题
  • 隐私政策
  • 服务条款
  • 意见反馈
  • 联系我们

资源

  • 下载
  • CVE 列表
  • CWE 列表
Follow Us:

© 2026 ScyScan. 保留所有权利。