XSS Archives - 7ASecurity Blog https://7asecurity.com/blog/ 7ASecurity Blog With Cybersecurity Tips and Tools Fri, 17 Jul 2026 07:18:32 +0000 en-US hourly 1 https://7asecurity.com/blog/contents/uploads/2019/06/favicon.ico XSS Archives - 7ASecurity Blog https://7asecurity.com/blog/ 32 32 Don't Let jQuery 3.5.1 Vulnerabilities Panic Your Risk Team https://7asecurity.com/blog/2026/07/jquery-3-5-1-vulnerabilities/ Fri, 17 Jul 2026 07:18:30 +0000 Searches for jQuery 3.5.1 vulnerabilities often mix up older jQuery XSS issues with scanner noise. The major 2020 DOM manipulation flaws, CVE-2020-11022 and CVE-2020-11023, affected versions before 3.5.0. jQuery 3.5.1 followed 3.5.0 and kept those fixes while addressing a regression. Teams should still check loaded versions, old bundled copies, plugins, unsafe DOM insertion, and output …

The post Don't Let jQuery 3.5.1 Vulnerabilities Panic Your Risk Team appeared first on 7ASecurity Blog.

]]>
XXE Exposed Webinar Recording and Slides https://7asecurity.com/blog/2014/07/xxe-exposed-webinar-recording/ https://7asecurity.com/blog/2014/07/xxe-exposed-webinar-recording/#respond Fri, 25 Jul 2014 19:50:00 +0000 In case someone is interested, I had the pleasure of giving a Webinar for eLearnSecurity on Tuesday this week: Webinar Title: "XXE Exposed" Summary: Brief coverage of Web Service Types, SQLi and XSS against Web Services to then talk about XXE and XEE attacks and mitigation.Heavily inspired on the "Practical Web Defense" (PWD) style of pwnage + …

The post XXE Exposed Webinar Recording and Slides appeared first on 7ASecurity Blog.

]]>
https://7asecurity.com/blog/2014/07/xxe-exposed-webinar-recording/feed/ 0
Embedding untrusted HTML XSS+ challenge https://7asecurity.com/blog/2012/01/embedding-untrusted-html-xss-challenge/ https://7asecurity.com/blog/2012/01/embedding-untrusted-html-xss-challenge/#comments Thu, 26 Jan 2012 13:24:00 +0000 Where this came from - skip to the end for the challenge if you do not care 🙂 During the OWTF workshop at BSides Vienna the interaction with the audience was great. For the purpose of this blog post the conversation on embedding HTML input from an untrusted source developed as follows: - Olaf first asked …

The post Embedding untrusted HTML XSS+ challenge appeared first on 7ASecurity Blog.

]]>
https://7asecurity.com/blog/2012/01/embedding-untrusted-html-xss-challenge/feed/ 2