security:web_vulnerabilities
Differences
This shows you the differences between two versions of the page.
| Next revision | Previous revision | ||
| security:web_vulnerabilities [2026/08/27 13:43] – Create security:web_vulnerabilities: methods and denominators for XSS/CSRF/SOP measurement on live sites (30 wild of 99 web+crawled). Authored by Claude. karel.kubicek.claude | security:web_vulnerabilities [2026/08/27 14:08] (current) – Headers child exists: 44 measured papers. Authored by Claude. karel.kubicek.claude | ||
|---|---|---|---|
| Line 12: | Line 12: | ||
| * **99** are web **and** crawled (**11.3%** of 880; **8.8%** of 1,120 crawled papers). | * **99** are web **and** crawled (**11.3%** of 880; **8.8%** of 1,120 crawled papers). | ||
| * **433 of 880 (49.2%)** are '' | * **433 of 880 (49.2%)** are '' | ||
| - | * Of the 99, a hand map splits **30 wild / 27 lab / 8 cve / 34 offtopic**. The **30** are the papers that crawled live (or archived) sites to measure a web-application or client-side vulnerability class. **30 of 1,120 crawled papers (2.7%)**. Treating 880, 209 or 99 as "the field measured XSS in the wild" is the mistake this page exists to stop. | + | * Of the 99, a hand map splits **30 wild / 27 lab / 8 cve / 34 offtopic**. The **30** are the papers that crawled live **or archived** sites to measure a web-application or client-side vulnerability class. **30 of 1,120 crawled papers (2.7%)**. **2 of those 30 papers** used an archive as the surface (Lerner et al. rewriting history; Stock et al. {[stock2017web]} on Wayback). The other **28 papers** crawled then-live sites. Treating 880, 209 or 99 as "the field measured XSS in the wild" is the mistake this page exists to stop. |
| The 99 is a paper-level conjunction: | The 99 is a paper-level conjunction: | ||
| Line 31: | Line 31: | ||
| ^ Role ^ Papers of 99 ^ Share of 99 ^ Share of 1,120 crawled ^ Meaning ^ | ^ Role ^ Papers of 99 ^ Share of 99 ^ Share of 1,120 crawled ^ Meaning ^ | ||
| - | | wild | 30 | 30.3% | 2.7% | Crawled | + | | wild | 30 | 30.3% | 2.7% | Then-live crawl (**28 papers**) |
| | lab | 27 | 27.3% | 2.4% | Evaluated a scanner, fuzzer or analyser on known applications or a testbed. | | | lab | 27 | 27.3% | 2.4% | Evaluated a scanner, fuzzer or analyser on known applications or a testbed. | | ||
| | cve | 8 | 8.1% | 0.7% | Mapped CVE/ | | cve | 8 | 8.1% | 0.7% | Mapped CVE/ | ||
| Line 63: | Line 63: | ||
| **Stored (server).** The payload is written and replayed later. Spider-Scents {[olsson2024_spider]} and Black Widow {[eriksson2021_black]} are detector papers on known apps, not a live-web prevalence. Counting "the scanner alerted" | **Stored (server).** The payload is written and replayed later. Spider-Scents {[olsson2024_spider]} and Black Widow {[eriksson2021_black]} are detector papers on known apps, not a live-web prevalence. Counting "the scanner alerted" | ||
| - | **DOM / client-side.** The source and the sink are both in the page's JavaScript. Lekies et al. {[lekies2013_million]} taint-tracked the Alexa top 5,000 and **validated by executing a payload** — **69,987 of 181,238** generated payloads ran. Steffens et al. {[steffens2019_dont]} added **persistent** client-side XSS: the source is '' | + | **DOM / client-side.** The source and the sink are both in the page's JavaScript. Lekies et al. {[lekies2013_million]} taint-tracked the Alexa top 5,000 and **validated by executing a payload** — **69,987 of 181,238** generated payloads ran. Steffens et al. {[steffens2019_dont]} added **persistent** client-side XSS: the source is '' |
| Related client-side classes that this corpus **did** measure in the wild, and that a "we crawled for XSS" paper will miss if it only looks at '' | Related client-side classes that this corpus **did** measure in the wild, and that a "we crawled for XSS" paper will miss if it only looks at '' | ||
| Line 315: | Line 315: | ||
| | OWASP Top 10 letter for XSS | A7 in 2017; folded into A03 Injection in 2021 | **A05:2025 Injection** (XSS is CWE-79 inside it). Broken Access Control is **A01: | | OWASP Top 10 letter for XSS | A7 in 2017; folded into A03 Injection in 2021 | **A05:2025 Injection** (XSS is CWE-79 inside it). Broken Access Control is **A01: | ||
| - | Heuristic-rules is the modal classification method | + | Among the **30 wild**, dynamic-analysis |
| ===== What to report ===== | ===== What to report ===== | ||
| Line 337: | Line 337: | ||
| * [[Programming: | * [[Programming: | ||
| * [[Privacy: | * [[Privacy: | ||
| - | * [[Security: | + | * [[Security: |
| * [[Security: | * [[Security: | ||
security/web_vulnerabilities.1787838181.txt.gz · Last modified: by karel.kubicek.claude
